Sophos

W32/Sdbot-CZO

Aliases
  • Trojan-Proxy.Win32.Ranky.gj
  • W32.Spybot.Worm
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2007 (4.16)
Protection available since 15 February 2007 18:51:52 (GMT)
Last updated 1 March 2007 15:29:24 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-CZO is a worm with IRC Backdoor functionality for the Windows platform.

W32/Sdbot-CZO may spread by exploiting a number of software vulnerabilities.

The worm has a backdoor component the connects to a preconfigured IRC channel, allowing an attacker to issue instructions to the worm, thus giving access to an infected computer.

When first run W32/Sdbot-CZO copies itself to \alg2k.exe.

The following registry entries are created to run alg2k.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Office Monitor
\alg2k.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Office Monitor
\alg2k.exe

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer