Sophos

W32/Dogbot-A

Aliases
  • W32/Zotob.D
  • WORM_ZOTOB.D
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Protection available since 17 August 2005 00:35:15 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Dogbot-A is a network worm with backdoor Trojan functionality for the Windows platform.

When run, W32/Dogbot-A creates the folder <System>\wbev\ and copies itself to the new folder using the filename windrg32.exe. The following registry entries are created in order to run the worm copy each time a user logs on:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinDrg32
<System>\wbev\windrg32.exe

W32/Dogbot-A spreads using a variety of techniques including the exploitation of operating system vulnerabilities such as LSASS (MS04-011) and PnP(MS05-039).

The backdoor component connects to an IRC server and joins a predetermined channel where it then awaits commands from attackers.

W32/Dogbot-A may attempt to download and execute additional files.

W32/Dogbot-A attempts to disable and remove several adware related applications.

Patches for the operating system vulnerabilities exploited by W32/Dogbot-A can be obtained from Microsoft at:

MS04-011
MS05-039

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer