Threat behavior
Backdoor:Win32/Sdbot.ZA is a backdoor Trojan that allows an attacker to take control of an infected computer. When a computer is infected, the Trojan connects to an Internet Relay Chat (IRC) server and joins a channel in order to receive commands from the controlling attacker. This malware can also spread via network shares with weak passwords, and by exploiting a known vulnerability in the RPCSS Service (addressed in Microsoft Security Bulletin
MS03-039).
Installation
When executed, Sdbot.ZA copies itself to <System>\scvideo.exe and makes the following registry modifications to ensure that this file is executed at each Windows start:
Adds value: "Microsoft Update Manager"
With data: "scvideo.exe"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adds value: "Microsoft Update Manager"
With data: "scvideo.exe"
To subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Note: <System> is a variable location and refers to the location of the affected machine's System directory. The default location of the Windows System directory is C:\Windows\System32 (Windows XP, Vista); C:\Winnt\System32 (Windows NT/2000), C:\Windows\System (Windows 95/98/ME).
It also drops the file “oreans32.sys”. This is a legitimate file associated with the Themida software protection system from Oreans Technologies.
Spreads Via…
Network Shares
Sdbot.ZA attempts to spread to accessible network shares using a simple dictionary attack. It carries the following list of username and passwords:
Abdulrazak access accounting accounts Ackerman Adams Addison Adelstein Adibe adm admin administrador administrat administrateur administrator admins Adorno Ahlers Alavi Alcorn Alda Aleks Allison Alongi Altavilla Altenberger Altenhofen Amaral Amatangelo Ameer Amsden Anand Andel Ando Andrelus Andron Anfinrud Ansley Anthony Antos Arbia Arduini Arellano Aristotle Arjas Arky asd Atkins Augustus Aurelius Axelrod Axworthy Ayiemba Aykroyd Ayling Azima Bachmuth backup Backus Bady Baglivo Bagnold Bailar Bakanowsky Baleja Ballatori Ballew Baltz Banta Barabesi Barajas Baranczak Baranowska Barberi Barbetti Barneson Barnett Barriola Barry Bartholomew Bartolome Bartoo Basavappa Bashevis Batchelder Baumiller Bayles Bayo Beacon Beal Bean Beckman Beder Bedford Behenna Belanger Belaoussof Belfer Belin-Collart Bellavance Bellhouse Bellini Belloc Benedict-Dye Bergson Berke-Jenkins Bernardo Bernassola Bernston Berrizbeitia Betti Beynart Biagioli Bickel bill Binion Bir Bisema Bisho bitch Blackbourn Blackwell Blagg Blakemore blank Blanke Bliss Blizard Bloch Bloembergen Bloemhof Bloxham Blyth bob Bolger Bolick Bollinger Bologna Boner Bonham Boniface Bontempo Book Bookbinder Boone Boorstin Borack Borden Bossi Bothman Botosh Boudin Boudrot Bourneuf Bowers Boxer Boyajian Boyes Boyland Boym Boyne Bracalente Bradac Bradach Brecht Breed Brenan Brennan Brewer brian Bridgeman Bridges Brinton Britz Broca Brook Brzycki Buchan Budding Bullard Bunton Burden Burdzy Burke Burridge Busetta Byatt Byerly Byrd Cage Calnan Cammelli Cammilleri Canley Capanni Caperton Capocaccia Capodilupo Cappuccio Capursi Caratozzolo Carayannopoulos Carlin Carlos Carlyle Carmichael Caroti Carper Cartmill Cascio Case Caspar Castelda Cavanagh Cavell Ceniceros Cerioli changeme Chapman Charles Cheang Cherry Chervinsky Chiassino Chien Childress Childs Chinipardaz Chinman chris Christenson Christian Christiano Christie Christopher Chu Chupasko Church Ciampaglia Cicero Cifarelli cisco Claffey Clancy Clark Clement Clifton Clow Coblenz Coito Coldren Colella Collard Collis comp compaq Compton computer Comstock Concino Condodina Connors const control Corey Cornish Cosmides Counter country Coutaux Crawford Crocker Croshaw Croxen Croxton Cui Cunningham Currier Cutler Cvek Cyders D'Ambra D'arcangelo D'fini D'souza Daldalian Daly Danieli Dante Dapice Das Dasgupta daSilva Daskalu data database databasepass databasepassword David Dawkins dba dbpass dbpassword Debroff Dees default Defeciani DeGennaro del'Enclos DeLaPena Delattre Deleon-Rendon Delger dell Dell'acqua Deming demo Dempster Demusz Denault Denham Denison deRousse Desombre Deutsch Dicks Diefenbach Difabio Difronzo Dilworth Dionysius Dirksen Dockery Doherty domain domainpass domainpassword Donahue Donner Doonan Dore Dorf Dosi Doty Doug Dowsland Drinker Duffin Durrett Dussault Dwyer Eardley Ebeling Eckel Edley Edner Edward Eickenhorst Eliasson Elmendorf Elmerick Elvis Encinas Enyeart Eppling Erbach Erdman Erdos Erez eric Espinoza Estes Etter Euripides Everett exchange Fabbris Fagan Faioes Falco-Acosta Falorsi Faris Farone Farren Fasso' Fates Feigenbaum Fejzo Feldman Fernald Fernandes Ferrante Ferriell Feuer Fido Field Fink Finkelstein Finnegan Fiorina Fisk Fitzmaurice Flier Flores Folks Forester Fortes Fortier Fossey Fossi Francisco Franklin-Kenea Franz Frazier-Davis fred Freid Freundlich Fried Friedland Frisken Frowiss Fryberger Frye fuck Fujii-Abe Fuller Furth Fusaro Gabrielli Gaggiotti Galeotti Galwey Gambini Garfield Garman Garonna Geller Gemberling george Georgi Gerrett Ghorai Gibbens Gibson Gilbert Gili Gill Gillispie Gist Gleason Glegg Glendon god Goldfarb Goncalves Gonzalez Good Goodearl Goody Gozzi Gravell Greenberg Greenfeld Griffiths Grigoletto Grummell Gruner Gruppe Guenthart guest Gunn Guo Haar Hackman Hackshaw Haley Halkias Hallowell Halpert Hambarzumjan Hamer Hammerness Hand Hanssen Harding Hargraves Harlow Harrigan Hartman Hartmann Hartnett Harwell Haviaras Hawkes Hayes Haynes Hazlewood Heermans Heft Heiland hell Hellman Hellmiss hello Helprin Hemphill Henery Henrichs Hernandez Herrera Hester Heubert Heyeck Himmelfarb Hind Hirst Hitchcock Hoang Hock Hoffer Hoffman Hokanson Hokoda Holmes Holoien Holter Holway Holzman home homeuser Hooker Hopkins Horsley Hoshida Hostage Hottle Howard Hoy Huey Huidekoper Hungerford Huntington Hupp Hurtubise Hutchings Hyde ian Iaquinta ibm Ichikawa Igarashi Inamura Inniss internet intranet Isaac Isaievych Isbill Isserman Iyer Jacenko Jackson Jagers Jagger Jagoe Jain Jamil Janjigian Jarnagin Jarrell Jay Jeffers Jellis jen Jenkins Jespersen Jewett joe Johannesson Johannsen john Johns Jolly Jorgensen Jucks Juliano Julious Kabbash Kaboolian Kafadar Kalbfleisch Kaligian Kalil Kalinowski Kalman Kamel Kangis Karpouzes Kassower Kasten kate katie Kawachi Kee Keenan Keepper Keith Kelker Kelsey Kempton Kemsley Kendall Kerry Keul Khong Kimmel Kimmett Kimura Kindall Kinsley Kippenberger Kirscht Kittridge Kleckner Kleiman Kleinfelder Klemperer Kling Klinkenborg Klint Knuff Kobrick Koch Kohn Koivumaki Kommer Koniaris Konrad Kool | Korzybski Kotter Kovaks Kraemer Krailo Krasney Kraus Kroemer Krysiak Kuenzli Kumar Kusman Kuwabara l'Enclos Labunka Lafler Laing Lallemant lan Landes Lankes Lantieri Lanzit Laserna Lashley Lawless Lecar Lecce Leclercq lee Leite Lenard Lesser Lessi letter Liakos Lidano Liem Light Lightfoot Lim Linares Linda Linder Line Linehan linux Linzee Lippmann Lipponen Little Litvak Livernash Livi Livolsi Lizardo Locatelli login loginpass Longworth Loss Loveman Lowenstein Loza Lubin Lucas Luciano Luczkow Luecke luke Lunetta Luoma Lussier Lutcavage Luzader Maccormac Macdonald Maceachern Macintyre Mackenney MacMillan Macy Madigan Maggio Mahony Maier mail main Maine-Hershey Maisano Malatesta Maller Malova Manalis Mandel Manganiello Mantovan March Marchbanks Marcus Margalit Margetts Marques Martinez Martochio Marton Marubini mary Mass Matalka Matarazzo Matsukata Mattson Mauzy May Mazzali Mazziotta Mcbride Mccaffery Mccall Mcclearn Mcdowell Mcelroy McFadden Mcghee Mcgoldrick McIlroy Mcintosh Mckenna Mclane Mclaren Mcnealy Mcnulty Meccariello Memisoglu Menzies Merikoski Merlani Merminod Merseth Merz Metelka Metropolis Meurer Michelman Middle Mieher mike Mills Minh Mini Minichiello Mitropoulos Mittal Mocroft Modestino Moeller Mohr Moiamedi Monque Montilio MooreDeCh. Morani Moreton Morrison Morrow Mortimer Mosher Mosler Mostafavi Motooka Mudarri Muello Mugnai Mulkern Mulroy Mumford Mussachio Naddeo Napolitano Nardi Nardone Naviaux Nayduch neil Nelson Nenna Nesci Neuman Newfeld Newlin Nickerson Nickoloff Nisenson Nitabach nokia none Notman null Nuzum O'hagan O'malley O'meara Ocougne oem oeminstall oemuser office Ogata Oldford Olsen Olson Olszewski Oman Opel oracle orainstall Oray Orfield Orsi Ospina Ostrowski Ottaviani Otten Ouchida outlook Ovid owner PaesDealmeida Paine Palayoor Palepu Pallara Palmitesta Panadero Panizzon Pantilla Paoletti Parmeggiani Parris Partridge Pascucci pass pass1234 passwd password password1 Patefield Patrick Pattullo Pavetti Pavlon Pawloski Paynter Peabody Pearlberg Pederson Peishel Penny Pereira Perko Perlak Perlman Perna Perone Perrimon peter Peters Petruzello Pettibone Pettit Pfister Pilbeam Pinot Plancon Plant Plasket Plous Pocobene Poincaire Pointer Poirier Polak Polanyi Politis Poma Poolman Powers Presper Preucel Prevost Pritchard Pritz Proietti Prothrow-Stith Puccia Pugh pwd Pynchon qaz Quaday Quetin qwe qwerty Rabe Rabkin Radeke Rajagopalan Raney Rangan Rankin Rapple Rayport real Redden-Tyler Reedquist Reinold Remak Renick Repetto Resnik Rhea Richmond Rielly Rindos Rineer Rish Rivera Robinson Rocha Roesler Rogers Ronen root Row Royal Ruan Ruderman Ruescher Rush Ryu Sabatello Sadler Safire Sahu Sali sam Samson Sanchez-Ramirez Sanna Sapers Sarin Sartore Sase Satin Satta Satterthwaite Sawtell Sayied Scarponi Scepan Scharf Scharlemann Scheiner Schiano Schifini Schilling Schmitt Schossberger Schuman Schutte Schuyler Schwan Schwickrath Scovel Scudder Seaton Seeber Segal Sekler Selvage Sen Sennett server Seterdahl sex Sexton Seyfert Shaikh Shakis Shankland Shanley Shar Shatrov Shavelson Shea Sheats Shepherd Sheppard Shepstone Shesko Shia Shibata Shimon siemens Siesto Sigalot Sigini Signa Silverman Silvetti Sinsabaugh Sirilli Sites Skane Skerry Skoda Sloan Slowe slut Smilow Sniffen Snodgrass Socolow Solon Somers Sommariva Sorabella Sorg Sottak Soukup Soule Soultanian Spanier Sparrow Spaulding Speizer Spence Sperber Spicer Spiegelhalter Spiliotis Spinrad sql sqlpassoainstall staff Stalvey Stam Stang Stassinopolus States Statlender Stefani Steiner Stephanian Stepniewska Stewart-Oaten Stiepock Stillwell StMartin Stock Stockton Stockwell Stolzenberg Stonich Storer Stott Strange Strauch Streiff Stringer student sue Sullivan Sumner Suo Surdam susan Sweeting Sweetser Swindle system Tagiuri Tai Talaugon Tambiah Tandler Tanowitz Tatar Taveras Tawn Tcherepnin teacher Teague technical Temes Temmer Tenney Terracini test Than Thavaneswaran Theodos Thibault Thisted Thomsen Throop Tierney Till Timmons Tofallis Tollestrup Tolls Tolman Tomford Toomer Topulos Torresi Torske Towler Toye Traebert Trenga Trewin Tringali Troiani Troy Truss Tsiatis Tsomides Tsukurov Tuck Tudge Tukan Turano Turek Tuttle Twells Tzamarias Ullman unix Untermeyer Upsdell Urban Urdang-Brown Usdan user Uzuner Vacca Valberg Valencia vanAllen Vandenberg Vanheeckeren VanZwet Vasquez Velasquez Venne Verghese Viana Viano Viens Vignola Villarreal Vitali Viviani Voigt VonHoffman Vorhaus Votey Waite Wales Wallenberg Walter Warshafsky Wasowska Waugh web Weighart Weingarten Weinhaus Weissbourd Weissman Welles Welsh Wengret Wescott Wetzel Whately Whilton White Whitla Whittaker Wiedersheim Wiener Wilder Wilhelm Wilk Wilkin Wilkinson Willstatter Wilson win2000 win2k win98 windows winnt winpass winxp Wolk Woo Wooden Woods Woods-Powell www wwwadmin Yacono Yamane Yankee Yarchuk Yates Ybarra Yedidia Yesson Yetiv Yoffe Yoo Youk-See Zachary Zahedi Zangwill Zegans Zerbini Zoldak Zucconi Zurn Zwiers zxc Zytowski |
Exploit
Sdbot.ZA also attempts to spread by exploiting the "Buffer Overrun In RPCSS Service Could Allow Code Execution" vulnerability, addressed in Microsoft Security Bulletin
MS03-039.
Payload
Backdoor Functionality
Sdbot.ZA connects to a particular IRC channel on 'nety.cdmon.org' via port 6667 in order to be controlled by a remote attacker. Using this backdoor a remote attacker can perform the following actions:
Download and execute arbitrary files
List and terminate threads, processes and services
Emulate an FTP server in order to transfer files to and from the affected system using TFTP
Scan local area network for listening ports
Perform Distributed Denial of Service (DDoS) and flood attacks against specified targets
Steals Sensitive Information
Sdbot.ZA attempts to steal CD keys of the following game applications, should they be installed on the affected system:
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlefield Vietnam
Black and White
Chrome
Command and Conquer: Generals
Command and Conquer: Generals (Zero Hour)
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Command and Conquer: Tiberian Sun
Counter-Strike (Retail)
CustomerNumber
FIFA 2002
FIFA 2003
Freedom Force
Global Operations
Gunman Chronicles
Half-Life
Hidden & Dangerous 2
IGI 2: Covert Strike
Industry Giant 2
James Bond 007: Nightfire
Legends of Might and Magic
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Nascar Racing 2002
Nascar Racing 2003
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Neverwinter Nights
NHL 2002
NHL 2003
NOX
Rainbow Six III RavenShield
RegNumber
Shogun: Total War: Warlord Edition
Software\Red Storm Entertainment\RAVENSHIELD
Software\Westwood\Red Alert
Software\Westwood\Red Alert 2
Software\Westwood\Tiberian Sun
Soldier of Fortune II - Double Helix
Soldiers Of Anarchy
The Gladiators
Unreal Tournament 2003
Unreal Tournament 2004
This malware may also log user keystrokes to %windir%\k3y706.xml.
Terminates Services
Sdbot.ZA terminates the following services (mostly associated with security-related applications) on the affected machine:
_AVP32.EXE _AVPCC.EXE _AVPM.EXE ACKWIN32.EXE ADAWARE.EXE ADVXDWIN.EXE AGENTSVR.EXE AGENTW.EXE ALERTSVC.EXE ALEVIR.EXE ALOGSERV.EXE AMON9X.EXE ANTI-TROJAN.EXE ANTIVIRUS.EXE ANTS.EXE APIMONITOR.EXE APLICA32.EXE APVXDWIN.EXE ARR.EXE ATCON.EXE ATGUARD.EXE ATRO55EN.EXE ATUPDATER.EXE ATWATCH.EXE AU.EXE AUPDATE.EXE AUTO-PROTECT.NAV80TRY.EXE AUTODOWN.EXE AUTOTRACE.EXE AUTOUPDATE.EXE AVCONSOL.EXE AVE32.EXE AVGCC32.EXE AVGCTRL.EXE AVGNT.EXE AVGSERV.EXE AVGSERV9.EXE AVGUARD.EXE AVGW.EXE AVKPOP.EXE AVKSERV.EXE AVKSERVICE.EXE AVKWCTl9.EXE AVLTMAIN.EXE AVNT.EXE AVP.EXE AVP32.EXE AVPCC.EXE AVPDOS32.EXE AVPM.EXE AVPTC32.EXE AVPUPD.EXE AVSCHED32.EXE AVSYNMGR.EXE AVWIN95.EXE AVWINNT.EXE AVWUPD.EXE AVWUPD32.EXE AVWUPSRV.EXE AVXMONITOR9X.EXE AVXMONITORNT.EXE AVXQUAR.EXE BACKWEB.EXE BARGAINS.EXE bbeagle.exe BD_PROFESSIONAL.EXE BEAGLE.EXE BELT.EXE BIDEF.EXE BIDSERVER.EXE BIPCP.EXE BIPCPEVALSETUP.EXE BISP.EXE BLACKD.EXE BLACKICE.EXE BLSS.EXE BOOTCONF.EXE BOOTWARN.EXE BORG2.EXE BPC.EXE BRASIL.EXE BS120.EXE BUNDLE.EXE BVT.EXE CCAPP.EXE CCEVTMGR.EXE CCPXYSVC.EXE CDP.EXE CFD.EXE CFGWIZ.EXE CFIADMIN.EXE CFIAUDIT.EXE CFINET.EXE CFINET32.EXE Claw95.EXE CLAW95CF.EXE CLEAN.EXE CLEANER.EXE CLEANER3.EXE CLEANPC.EXE CLICK.EXE CMD32.EXE CMESYS.EXE CMGRDIAN.EXE CMON016.EXE CONNECTIONMONITOR.EXE CPD.EXE CPF9X206.EXE CPFNT206.EXE CTRL.EXE CV.EXE CWNB181.EXE CWNTDWMO.EXE d3dupdate.exe DATEMANAGER.EXE DCOMX.EXE DEFALERT.EXE DEFSCANGUI.EXE DEFWATCH.EXE DEPUTY.EXE DIVX.EXE DLLCACHE.EXE DLLREG.EXE DOORS.EXE DPF.EXE DPFSETUP.EXE DPPS2.EXE DRWATSON.EXE DRWEB32.EXE DRWEBUPW.EXE DSSAGENT.EXE DVP95.EXE DVP95_0.EXE ECENGINE.EXE EFPEADM.EXE EMSW.EXE ENT.EXE ESAFE.EXE ESCANH95.EXE ESCANHNT.EXE ESCANV95.EXE ESPWATCH.EXE ETHEREAL.EXE ETRUSTCIPE.EXE EVPN.EXE EXANTIVIRUS-CNET.EXE EXE.AVXW.EXE EXPERT.EXE EXPLORE.EXE F-AGNT95.EXE F-AGOBOT.EXE F-PROT.EXE F-PROT95.EXE F-STOPW.EXE FAMEH32.EXE FAST.EXE FCH32.EXE FIH32.EXE FINDVIRU.EXE FIREWALL.EXE FLOWPROTECTOR.EXE FNRB32.EXE FP-WIN.EXE FP-WIN_TRIAL.EXE FPROT.EXE FRW.EXE FSAA.EXE FSAV.EXE FSAV32.EXE FSAV530STBYB.EXE FSAV530WTBYB.EXE FSAV95.EXE FSGK32.EXE FSM32.EXE FSMA32.EXE FSMB32.EXE GATOR.EXE GBMENU.EXE GBPOLL.EXE GENERICS.EXE GMT.EXE GUARD.EXE GUARDDOG.EXE HACKTRACERSETUP.EXE HBINST.EXE HBSRV.EXE HIJACKTHIS.EXE HOTACTIO.EXE HOTPATCH.EXE HTLOG.EXE HTPATCH.EXE HWPE.EXE HXDL.EXE HXIUL.EXE i11r54n4.exe IAMAPP.EXE IAMSERV.EXE IAMSTATS.EXE IBMASN.EXE IBMAVSP.EXE ICLOAD95.EXE ICLOADNT.EXE ICMON.EXE ICSUPP95.EXE ICSUPPNT.EXE IDLE.EXE IEDLL.EXE IEDRIVER.EXE IEXPLORER.EXE IFACE.EXE IFW2000.EXE INETLNFO.EXE INFUS.EXE INFWIN.EXE INIT.EXE INTDEL.EXE INTREN.EXE IOMON98.EXE IPARMOR.EXE IRIS.EXE irun4.exe ISASS.EXE ISRV95.EXE ISTSVC.EXE JAMMER.EXE JDBGMRG.EXE JEDI.EXE KAVLITE40ENG.EXE KAVPERS40ENG.EXE KAVPF.EXE KAZZA.EXE KEENVALUE.EXE KERIO-PF-213-EN-WIN.EXE KERIO-WRL-421-EN-WIN.EXE KERIO-WRP-421-EN-WIN.EXE KERNEL32.EXE KILLPROCESSSETUP161.EXE LAUNCHER.EXE LDNETMON.EXE LDPRO.EXE LDPROMENU.EXE LDSCAN.EXE LNETINFO.EXE LOADER.EXE LOCALNET.EXE LOCKDOWN.EXE LOCKDOWN2000.EXE LOOKOUT.EXE LORDPE.EXE LSETUP.EXE LUALL.EXE LUAU.EXE LUCOMSERVER.EXE LUINIT.EXE LUSPT.EXE MAPISVC32.EXE MCAGENT.EXE MCMNHDLR.EXE MCSHIELD.EXE MCTOOL.EXE MCUPDATE.EXE MCVSRTE.EXE MCVSSHLD.EXE MD.EXE MFIN32.EXE MFW2EN.EXE MFWENG3.02D30.EXE MGAVRTCL.EXE MGAVRTE.EXE MGHTML.EXE MGUI.EXE MINILOG.EXE MMOD.EXE MONITOR.EXE MOOLIVE.EXE MOSTAT.EXE MPFAGENT.EXE MPFSERVICE.EXE MPFTRAY.EXE MRFLUX.EXE MSAPP.EXE MSBB.EXE MSBLAST.EXE MSCACHE.EXE MSCCN32.EXE MSCMAN.EXE MSCONFIG.EXE mscvb32.exe MSDM.EXE MSDOS.EXE MSIEXEC16.EXE MSINFO32.EXE MSLAUGH.EXE MSMGT.EXE MSMSGRI32.EXE MSSMMC32.EXE MSSYS.EXE MSVXD.EXE MU0311AD.EXE MWATCH.EXE N32SCANW.EXE NAV.EXE NAVAP.NAVAPSVC.EXE NAVAPSVC.EXE | NAVAPW32.EXE NAVDX.EXE NAVENGNAVEX15.NAVLU32.EXE NAVLU32.EXE NAVNT.EXE NAVSTUB.EXE NAVW32.EXE NAVWNT.EXE NC2000.EXE NCINST4.EXE NDD32.EXE NEOMONITOR.EXE NEOWATCHLOG.EXE NETARMOR.EXE NETD32.EXE NETINFO.EXE NETMON.EXE NETSCANPRO.EXE NETSPYHUNTER-1.2.EXE NETSTAT.EXE NETUTILS.EXE NISSERV.EXE NISUM.EXE NMAIN.EXE NOD32.EXE NORMIST.EXE NORTON_INTERNET_SECU_3.0_407.EXE NOTSTART.EXE NPF40_TW_98_NT_ME_2K.EXE NPFMESSENGER.EXE NPROTECT.EXE NPSCHECK.EXE NPSSVC.EXE NSCHED32.EXE NSSYS32.EXE NSTASK32.EXE NSUPDATE.EXE NT.EXE NTRTSCAN.EXE NTVDM.EXE NTXconfig.EXE NUI.EXE NUPGRADE.EXE NVARCH16.EXE NVC95.EXE NVSVC32.EXE NWINST4.EXE NWSERVICE.EXE NWTOOL16.EXE OLLYDBG.EXE ONSRVR.EXE OPTIMIZE.EXE OSTRONET.EXE OTFIX.EXE OUTPOST.EXE OUTPOSTINSTALL.EXE OUTPOSTPROINSTALL.EXE PADMIN.EXE PandaAVEngine.exe PANIXK.EXE PATCH.EXE PAVCL.EXE PAVPROXY.EXE PAVSCHED.EXE PAVW.EXE PCC2002S902.EXE PCC2K_76_1436.EXE PCCIOMON.EXE PCCNTMON.EXE PCCWIN97.EXE PCCWIN98.EXE PCDSETUP.EXE PCFWALLICON.EXE PCIP10117_0.EXE PCSCAN.EXE PDSETUP.EXE PENIS.EXE Penis32.exe PERISCOPE.EXE PERSFW.EXE PERSWF.EXE PF2.EXE PFWADMIN.EXE PGMONITR.EXE PINGSCAN.EXE PLATIN.EXE POP3TRAP.EXE POPROXY.EXE POPSCAN.EXE PORTDETECTIVE.EXE PORTMONITOR.EXE POWERSCAN.EXE PPINUPDT.EXE PPTBC.EXE PPVSTOP.EXE PRIZESURFER.EXE PRMT.EXE PRMVR.EXE PROCDUMP.EXE PROCESSMONITOR.EXE PROCEXPLORERV1.0.EXE PROGRAMAUDITOR.EXE PROPORT.EXE PROTECTX.EXE PSPF.EXE PURGE.EXE PUSSY.EXE PVIEW95.EXE QCONSOLE.EXE QSERVER.EXE RAPAPP.EXE rate.exe RAV7.EXE RAV7WIN.EXE RAV8WIN32ENG.EXE RAY.EXE RB32.EXE RCSYNC.EXE REALMON.EXE REGED.EXE REGEDIT.EXE REGEDT32.EXE RESCUE.EXE RESCUE32.EXE RRGUARD.EXE RSHELL.EXE RTVSCAN.EXE RTVSCN95.EXE RULAUNCH.EXE RUN32DLL.EXE RUNDLL.EXE RUNDLL16.EXE RUXDLL32.EXE SAFEWEB.EXE SAHAGENT.EXE SAVE.EXE SAVENOW.EXE SBSERV.EXE SC.EXE SCAM32.EXE SCAN32.EXE SCAN95.EXE SCANPM.EXE SCRSCAN.EXE SCRSVR.EXE SCVHOST.EXE SD.EXE SERV95.EXE SERVICE.EXE SERVLCE.EXE SERVLCES.EXE SETUP_FLOWPROTECTOR_US.EXE SETUPVAMEEVAL.EXE SFC.EXE SGSSFW32.EXE SH.EXE SHELLSPYINSTALL.EXE SHN.EXE SHOWBEHIND.EXE SMC.EXE SMS.EXE SMSS32.EXE SOAP.EXE SOFI.EXE SPERM.EXE SPF.EXE SPHINX.EXE SPOLER.EXE SPOOLCV.EXE SPOOLSV32.EXE SPYXX.EXE SREXE.EXE SRNG.EXE SS3EDIT.EXE ssate.exe SSG_4104.EXE SSGRATE.EXE ST2.EXE START.EXE STCLOADER.EXE SUPFTRL.EXE SUPPORT.EXE SUPPORTER5.EXE SVC.EXE SVCHOSTC.EXE SVCHOSTS.EXE SVSHOST.EXE SWEEP95.EXE SWEEPNET.SWEEPSRV.SYS.SWNETSUP.EXE SYMPROXYSVC.EXE SYMTRAY.EXE SYSEDIT.EXE sysinfo.exe SysMonXP.exe SYSTEM.EXE SYSTEM32.EXE SYSUPD.EXE TASKMG.EXE TASKMO.EXE TASKMON.EXE TAUMON.EXE TBSCAN.EXE TC.EXE TCA.EXE TCM.EXE TDS-3.EXE TDS2-98.EXE TDS2-NT.EXE TEEKIDS.EXE TFAK.EXE TFAK5.EXE TGBOB.EXE TITANIN.EXE TITANINXP.EXE TRACERT.EXE TRICKLER.EXE TRJSCAN.EXE TRJSETUP.EXE TROJANTRAP3.EXE TSADBOT.EXE TVMD.EXE TVTMD.EXE UNDOBOOT.EXE UPDAT.EXE UPDATE.EXE UPGRAD.EXE UTPOST.EXE VBCMSERV.EXE VBCONS.EXE VBUST.EXE VBWIN9X.EXE VBWINNTW.EXE VCSETUP.EXE VET32.EXE VET95.EXE VETTRAY.EXE VFSETUP.EXE VIR-HELP.EXE VIRUSMDPERSONALFIREWALL.EXE VNLAN300.EXE VNPC3000.EXE VPC32.EXE VPC42.EXE VPFW30S.EXE VPTRAY.EXE VSCAN40.EXE VSCENU6.02D30.EXE VSCHED.EXE VSECOMR.EXE VSHWIN32.EXE VSISETUP.EXE VSMAIN.EXE VSMON.EXE VSSTAT.EXE VSWIN9XE.EXE VSWINNTSE.EXE VSWINPERSE.EXE W32DSM89.EXE W9X.EXE WATCHDOG.EXE WEBDAV.EXE WEBSCANX.EXE WEBTRAP.EXE WFINDV32.EXE WGFE95.EXE WHOSWATCHINGME.EXE WIMMUN32.EXE WIN-BUGSFIX.EXE WIN32.EXE WIN32US.EXE WINACTIVE.EXE WINDOW.EXE WINDOWS.EXE WININETD.EXE WININIT.EXE WININITX.EXE WINLOGIN.EXE WINMAIN.EXE WINNET.EXE WINPPR32.EXE WINRECON.EXE WINSERVN.EXE WINSSK32.EXE WINSTART.EXE WINSTART001.EXE winsys.exe WINTSK32.EXE winupd.exe WINUPDATE.EXE WKUFIND.EXE WNAD.EXE WNT.EXE WRADMIN.EXE WRCTRL.EXE WSBGATE.EXE WUPDATER.EXE WUPDT.EXE WYVERNWORKSFIREWALL.EXE XPF202EN.EXE ZAPRO.EXE ZAPSETUP3001.EXE ZATUTOR.EXE ZONALM2601.EXE ZONEALARM.EXE |
Additional Information
Sdbot.ZA may delete the files it creates using the batch file 'sdel.bat'.
Prevention