TrojanInfo.com
GTBot IRC DDos Trojan Information

GT Bot Name Here

Interview with Lockdown | Main Page | Trojan List | NoHack | SwatIt | Submit a Trojan

Bot description here

Dropper File
File Name Dropper Size Discovered Date Here

Files and Folders Dropped
File/Folder File Size Description

Before you make any changes to the registry, it is recommended that you first make a back up

Registry Keys Added
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

Registry Keys Changed
HKEY_CLASSES_ROOT\ChatFile\DefaultIcon "(Default)"
Old data: "C:\MIRC\MIRC.EXE"
New data: "C:\\TEMP.EXE"

HKEY_CLASSES_ROOT\ChatFile\Shell\open\command "(Default)"
Old data: "C:\MIRC\MIRC.EXE" -noconnect
New data: "C:\\TEMP.EXE" -noconnect

HKEY_CLASSES_ROOT\irc\DefaultIcon "(Default)"
Old data: "C:\MIRC\MIRC.EXE"
New data: "C:\\TEMP.EXE"

HKEY_CLASSES_ROOT\irc\Shell\open\command "(Default)"
Old data: "C:\MIRC\MIRC.EXE" -noconnect
New data: "C:\\TEMP.EXE" -noconnect

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mIRC "UninstallString"
Old data: "C:\MIRC\MIRC.EXE" -uninstall
New data: "C:\\TEMP.EXE" -uninstall

Back to Links
Back to Top of GT Bot Information Page
Submit New bots to golcor@trojaninfo.com