Main Menu
Home
Bookmark
Contact Us



 
SDBot.ConfigurationLoader Worm Information

Name: SDBot.ConfigurationLoader
Category: Worm
Alias: - Alias: W32/Chainsaw.worm
Advice: Remove
Risk: Severe Risk Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine.
Description: SDBot is the name of a family of remote access tools, also known as backdoors or worms, used by hackers to control a machine without the owner's knowledge.

SDBot.ConfigurationLoader copies itself to the Windows system folder as DEZI.EXE and creates the following entries in the registry to run itself on system startup:

HKLMSoftwareMicrosoftWindowsCurrentVersionRunConfiguration Loader = dezi.exe

HKLMSoftwareMicrosoftWindowsCurrentVersionRunServicesConfiguration Loader = dezi.exe

HKCUSoftwareMicrosoftWindowsCurrentVersionRunConfiguration Loader = dezi.exe

SDBot.ConfigurationLoader spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user.

Signatures: process: dezi.exe: MD5 Hash: ... process: dezi.exe: MD5 Hash: bd5e8fab36330f3d13e... process: scvhost.exe: MD5 Hash: d36793c09716a70e4ed..
Type: Worm - A worm is program that propagates by attacking other computers and copying itself to them. Worms may replace files, but do not insert themselves into files (as viruses do).



Top Worm Visited Pages:
Wukill.mstray - Alias: Win32/HLLW.Wukill - 294 visits
Rbot - Alias: Backdoor.Rbot.Gen - 276 visits
SDBot - Alias: Wootbot.gen, Wootbot, Donk, spybot, Agobot - 229 visits
Trojan.Downloader.winstall - 182 visits
Worm.Brit.e - Alias: VBS/Chick.e@M virus - 89 visits
Worm.P2P.SpyBot.gen - 56 visits
Gaobot - 44 visits
Win32/Darby.O - 42 visits
Worm.Trilissa.e - 42 visits
JS.Lame - Alias: HTML.Lame - 40 visits

Random Worm Pages:
Worm.Mimail.h
Wootbot.forboo - Alias: Win32/Wootbot.worm
Virus.Deloder - Alias: W32/Deloder.worm, Worm.Win32.Deloder.a
Dwarf 4 You Worm - Alias: I-Worm.Hybris.b, W32/Hybris.gen@MM, W32/Hybris.worm.B
Net-Worm.Max-Stats.Maslan
Mawanella Worm - Alias: I-Worm.Mawanella
Virus.Zhangpo.a@MM - Alias: I-Worm.Zhangpo
Worm.Ioanna.b
Worm.Dawn
Worm.Chainsaw - Alias: W32/Chainsaw.worm


 


© 2006-2008 spyware32.com - Privacy Policy