Sophos

W32/Sdbot-AAZ

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Chat programs
Affected operating systems Windows
Characteristics
  • Drops more malware
Protection available since 19 July 2005 20:48:19 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Sdbot-AAZ is a network worm with backdoor Trojan functionality for the Windows platform.

The backdoor component of W32/Sdbot-AAZ joins a predetermined IRC channel and awaits further commands from remote attackers.

The worm spreads through network shares and can be instructed to send itself through the AOL Instant Messenger (AIM) application. W32/Sdbot-AAZ is a network worm with backdoor Trojan functionality for the Windows platform.

When run, W32/Sdbot-AAZ copies itself to the Windows system folder as xmconfig.exe and sets the following registry entries in order to run each time a user logs on:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
stratas
"xmconfig.exe"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
stratas
"xmconfig.exe"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
stratas
"xmconfig.exe"

The worm then drops the file msdirectx.sys to the Windows system folder and then loads the file as a system driver. Sophos's anti-virus products detect msdirectx.sys as Troj/NtRootK-F.

The backdoor component of W32/Sdbot-AAZ joins a predetermined IRC channel and awaits further commands from remote attackers.

The worm spreads through network shares and can be instructed to send itself through the AOL Instant Messenger (AIM) application.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer