Threat Information for "BackDoor.IRC.Sdbot.755"

Removal Top

StopSign will automatically remove this infection with a paid membership.

Summary Top
  • Name: BackDoor.IRC.Sdbot.755
  • Aliases:
  • Date Discovered: 2006-09-22
  • Protection Added: 2006-09-27
Description Top
-- Ease of Removal

1: Consistent file contents
2: Consistently named
3: Creates new registry entries with consistent data

-- Damage/Intrusion/Annoyance

1: Displays deceptive error messages
2: Changes browser home page

-- Propagation/Saturation

1: Infects through Internet Relay Chat (IRC)
2: Spreads through Peer-2-Peer software
Technical Details Top
  • Added Directory/File:
    FilePath: %SYSTEMDIR%\msi32info.exe
  • Added Registry Key:
    Key: HKLM\Software\ProductName
  • Added Registry Data:
    Key: HKLM\%CURRENTVERSIONREG%\RunServices Value: [RANDOM VALUE] Data: msi32info.exe
  • Added Registry Data:
    Key: HKCU\%CURRENTVERSIONREG%\RunServices Value: [RANDOM VALUE] Data: msi32info.exe