Sophos

W32/Dabber-D

Aliases
  • Backdoor.Win32.IRCBot.acd
  • Win32/IRCBot.WO
  • W32/Sdbot.AAOV
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 4 October 2007 19:02:01 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information


W32/Dabber-D is a worm for the Windows platform.

W32/Dabber-D includes functionality to access the internet and communicate with a remote server via HTTP. W32/Dabber-D is a worm for the Windows platform.

W32/Dabber-D includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Dabber-D copies itself to <System>\msnfix.exe and creates the following files:

<User>\auto.txt
<System>\libinets.dll
<System>\libweb.dll

The files libinets.dll and libweb.dll are detected as Mal/Generic-A.

The files libinets.dll and libweb.dll are registered as COM objects, creating registry entries under:

HKCR\CLSID\{442B222A-0112-48B8-A8EF-1409332F9B8F}
HKCR\CLSID\{CCB13A8A-BBA4-4603-9012-996E69602713}

The following registry entries are created to run code exported by libinets.dll and libweb.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
printers
{CCB13A8A-BBA4-4603-9012-996E69602713}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
version
{442B222A-0112-48B8-A8EF-1409332F9B8F

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer