Virus:BDS/Iroffer.1213.A
Date discovered:05/09/2005
Type:Trojan
In the wild:No
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low
Static file:Yes
File size:5.632 Bytes
MD5 checksum:ec3c36da016c7bf5e9b3345e5f49c296

 General Method of propagation:
   • No own spreading routine


Aliases:
   •  Symantec: Trojan.Delsha.B
   •  Mcafee: Delshare.a.
   •  Kaspersky: Backdoor.Win32.Iroffer.1213.a
   •  TrendMicro: BKDR_IROFFER12.A
   •  F-Secure: W32/Iroffer.A
   •  Sophos: Troj/DelShare-B
   •  Grisoft: BackDoor.Iroffer.A
   •  Eset: Win32/Iroffer.1213
   •  Bitdefender: Backdoor.Iroffer.C


Platforms / OS:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003

 Miscellaneous Windows Messenger Service:
It can send a message using Windows Messenger Service. The message is the following:
   • System secured


Network shares:
The following network shares will be deleted:
   • IPC$
   • ADMIN$
   • C$
   • D$


 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with the following runtime packer:
   • UPX

Description inserted by Iulia Diaconescu on Wednesday, September 7, 2005
Description updated by Iulia Diaconescu on Monday, September 19, 2005

Back . . . .