Sponsored Content
Full Discussion: Troj_sdbot.ia
Special Forums Cybersecurity Malware Advisories (RSS) Troj_sdbot.ia Post 302209085 by Linux Bot on Wednesday 25th of June 2008 07:40:08 PM
Old 06-25-2008
Troj_sdbot.ia

This Trojan may be dropped by other malware. It may arrive bundled with malware packages as a malware component. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries. It modifies registry entries to enable its automatic execution at every system startup.
It disables the DCOM protocol. It disables Automatic Windows Update. As a result, once updates are released, affected users are unable to get Windows updates automatically. It disables Security Center functions. It disables Windows Firewall settings. It disables Task Manager. It does the said routine to avoid termination from the affected system's memory. It creates and modifies registry key(s)/entry(ies) as part of its installation routine. It modifies files.
It drops component files.It deletes itself after execution.


More...
 
REGDIFF(1)							  [FIXME: manual]							REGDIFF(1)

NAME
regdiff - Diff program for Windows registry files SYNOPSIS
regdiff [--help] [--backend=BACKEND] [--backend=BACKEND] [--credentials=CREDENTIALS] [--credentials=CREDENTIALS] [location] [location] DESCRIPTION
regdiff compares two Windows registry files key by key and value by value and generates a text file that contains the differences between the two files. A file generated by regdiff can later be applied to a registry file by the regpatch utility. regdiff and regpatch use the same file format as the regedit32.exe utility from Windows. OPTIONS
--help Show list of available options. --backend BACKEND Name of backend to load. Possible values are: creg, regf, dir and rpc. The default is dir. This argument can be specified twice: once for the first registry file and once for the second. --credentials=CREDENTIALS Credentials to use, if any. Password should be separated from user name by a percent sign. This argument can be specified twice: once for the first registry file and once for the second. VERSION
This man page is correct for version 4.0 of the Samba suite. SEE ALSO
gregedit, regshell, regpatch, regtree, samba, patch, diff AUTHOR
This utility is part of the Samba[1] suite, which is developed by the global Samba Team[2]. This manpage and regdiff were written by Jelmer Vernooij. NOTES
1. Samba http://www.samba.org/ 2. Samba Team http://www.samba.org/samba/team/ [FIXME: source] 04/16/2014 REGDIFF(1)
All times are GMT -4. The time now is 06:15 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy