BugTraq
rpc sdbot Aug 13 2003 05:04PM
Daniel Otis-Vigil (dvigil moosoft com)
This sdbot variant has been spreading around Undernet and is a combination
of the msblast worm, sdbot and spybot. It installs as a service and
triggers WFP which I think was a mistake. Termination of the process
causes an immediate reboot.

Samples are available here: http://www.moosoft.com/thecleaner/rcpsdbot.zip
password is: infected

Daniel Otis-Vigil
MooSoft Development LLC
http://www.moosoft.com/thecleaner

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus