P2P Worm Identified

From software to hardware, breakthough to disaster, it all belongs here!

Moderator: CricketMX Forum Moderators

Post Reply
User avatar
p2p-sharing-rules
Moderator
Moderator
Posts: 8462
Joined: Mon Mar 29, 2004 6:55 pm
Location: Canada

A new worm is catching the attention of computer security agencies. W32/Inject-H spreads via peer-to-peer networks, acting as a backdoor Internet Relay Chat (IRC) to exploit Windows-based computers.

Running continuously in the background, the worm/trojan becomes a server that allows remote access and control over the computer via IRC.

Sophossays W32/Inject-H installs itself in the registry and advises P2P file sharers to download its virus identity (IDE) file.

IRC is a common protocol used in many file-sharing applications like Napster.
securitypronews

Description from Sophos
This section helps you to understand how it behaves
W32/Inject-H is a worm and IRC backdoor Trojan for the Windows platform.

W32/Inject-H spreads via file sharing on Peer-to-peer networks.

W32/Inject-H runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels
User avatar
p2p-sharing-rules
Moderator
Moderator
Posts: 8462
Joined: Mon Mar 29, 2004 6:55 pm
Location: Canada

Peer-To-Peer Trojan Worm Attacks Enterprises
Thursday, 30 March 2006 11:54 EST

Security experts at MicroWorld Technologies inform that Trojan.Win32.Inject.t or W32/Inject-H is a new peer-to peer worm with IRC backdoor Trojan capacities. Inject.t can run in the background of a computer by working as a Server that allows a hacker to control the system via IRC channels.

Exploiting Windows vulnerabilities, this worm will proliferate in networks. First it copies itself into a shared folder on the local machine. From there, the P2P network takes over to contact other computers in the network and helps them download and execute the infected file.
it-observer.com
Post Reply