Sophos

W32/Sdbot-ADD

Aliases
  • Backdoor.Win32.Aimbot.aj
  • Downloader-VF
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 15 September 2005 06:07:29 (GMT)
Last updated 31 October 2005 23:01:18 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-ADD is a worm for the Windows platform.

W32/Sdbot-ADD runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When first run W32/Sdbot-ADD copies itself to <System>\lockx.exe and creates the following files:

<CurrentFolder>\msdirectx.sys or <System>\msdirectx.sys
\xz.bat

The file msdirectx.sys is detected as Troj/NtRootK-F. The file xz.bat is harmless and can safely be deleted.

The following registry entries are created to run lockx.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
stratas
lockx.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
stratas
lockx.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
stratas
lockx.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer