Sophos

W32/Spybot-NX

Aliases
  • Backdoor.Win32.Rizo.a
  • WORM_SPYBOT.XZ
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2007 (4.20)
Protection available since 29 June 2007 20:53:49 (GMT)
Detected by All Sophos products

Action

More Information

W32/Spybot-NX is a worm for the Windows platform with IRC backdoor functionality.

W32/Spybot-NX is a worm for the Windows platform with IRC backdoor functionality.

W32/Spybot-NX installs as ajsha5.exe in the <System> folder. The following Registry entries are added to run at startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
(default)
ajsha5.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
(default)
ajsha5.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
(default)
ajsha5.exe

Once running, W32/Spybot-NX attempts to connect to a remote server (port 3921) to receive remote commands.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer