Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Yet another IM worm: WORM_SDBOT.CWG

    Dec23
    10:40 am (UTC-7)   |    by


    This worm may propagate through the following techniques:



    • AOL Instant Messenger (needs a remote-user-intervention)
    • Internet Relay Chat
    • Microsoft Vulnerabilities (MS04-007& MS05-039)
    This malware uses anti-debugging technique. It uses the IsDebuggerPresent API and also it detects VMWare. The IsDebuggerPresent API checks if the malware is being debugged. For the VMWare, it checks the registry entry if the VMWare tools is installed.

    Most of its strings are encrypted using its own encryption table. One noticeable string on its body, upon decryption, is “[Reptile - 0.33]“.

    So if you are not sure if the link being sent to you on Instant Messenger(et. al., AOL, Yahoo, MSN), DO NOT click the link.

    For complete technical analysis and removal instructions, please see the links below:
    WORM_SDBOT.CWG Technical Details
    WORM_SDBOT.CWG Removal Instructions





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice