Sophos

W32/Sdbot-JX

Aliases
  • Backdoor.Agobot.jx
  • IRC-Slinbot
  • W32.Randex.gen
  • BKDR_AGOBOT.JX
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from June 2004 (3.82)
Protection available since 19 April 2004 13:57:44 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-JX is an IRC backdoor Trojan and network worm.

W32/Sdbot-JX is capable of spreading to computers on the local network protected by weak passwords.

When first run W32/Sdbot-JX copies itself to the Windows system folder as peere32.exe and creates the following registry entries so that peere32.exe is run automatically on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Peer Manager = peere32.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Peer Manager = peere32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Peer Manager = peere32.exe

The harmless file pene.g is created in the Windows system folder.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer