|
|
SDBot.NvCplScan Worm Information
| Name: |
SDBot.NvCplScan |
| Category: |
Worm |
| Alias: |
- Alias: WORM_RBOT.BTN |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
SDBot is the name of a family of remote access tools, also known as backdoors or worms, used by hackers to control a machine without the owner's knowledge.
This memory-resident worm propagates through network shares and Internet Relay Chat (IRC). It attempts to access network shares by dropping a copy of itself as the file NVSC32.EXE and using a list of common user names and weak passwords. It also tries to connect to an Internet Relay Chat (IRC) server and joins a channel to wait for remote commands. It allows a malicious user to perform its backdoor capabilities; thus, compromising system security. It performs Denial of Service (DoS) attacks and steal CD keys of certain game applications.
|
| Signatures:
|
process: nvsc32.exe: MD5 Hash: 9e2805e7019e7a69d5f...
process: nvsc32.exe: MD5 Hash: 89a41f28f4ce56b57ac...
process: nvsc32.exe: MD5 Hash: ...
process: nvsc32.exe: MD5 Hash: 7c42cb516479b256257...
process: msc32.exe: MD5 Hash: 827f185387bb448dd0d...
process: winasp.exe: MD5 Hash: 1d6af3dd704ae645c48...
process: winasp.exe: MD5 Hash: 272156b32d39dce7108...
process: nvsc32.exe: MD5 Hash: 816f3f30c2bf3011043...
process: nvsc32.exe: MD5 Hash: f11b38a9ba3628352d8...
process: nvsc32.exe: MD5 Hash: 6a3eb12cfd3c4c1ae25...
process: nvsc32.exe: MD5 Hash: ae923a5335886c1914c...
process: kav32.exe: MD5 Hash: 54dbb50dfcde36d4170...
process: kav32.exe: MD5 Hash: 936d0084c6054344895.. |
| Type: |
Worm - A worm is program that propagates by attacking other computers and copying itself to them. Worms may replace files, but do not insert themselves into files (as viruses do). |
Top Worm Visited Pages:
Wukill.mstray - Alias: Win32/HLLW.Wukill - 294 visits
Rbot - Alias: Backdoor.Rbot.Gen - 276 visits
SDBot - Alias: Wootbot.gen, Wootbot, Donk, spybot, Agobot - 229 visits
Trojan.Downloader.winstall - 182 visits
Worm.Brit.e - Alias: VBS/Chick.e@M virus - 89 visits
Worm.P2P.SpyBot.gen - 56 visits
Gaobot - 44 visits
Win32/Darby.O - 42 visits
Worm.Trilissa.e - 42 visits
JS.Lame - Alias: HTML.Lame - 40 visits
Random Worm Pages:
Annoying Worm - Alias: I-Worm.Newpic.a, W32/Choke, W32/Choke.C
IRC.Worm.Milbug.b
Worm.P2P.Bonet.b
Worm.Brit.b - Alias: VBS/Chick.b@M virus
SdBot.svchost
Worm.Borzella - Alias: W32/Porkis@MM
IRC.Worm.Radex
Rbot.msgfix - Alias: Backdoor:Win32/Rbot
IRC.Worm.Dragon.B - Alias: Elspy.worm.a
RBot.xmconfig - Alias: WORM_RBOT.BTN
|
|