Home Malware Programs Trojans Backdoor.Small.EO

Backdoor.Small.EO

Posted: May 26, 2010

Backdoor.Small.EO is a malicious Trojan which provides IRC remote access to an infected machine by exploiting a known Microsoft vulnerability. Backdoor.Small.EO can be installed onto a computer via a security hole or browser exploit. Once installed, Backdoor.Small.EO can further compromise the infected system by allowing a remote attacker access. Remove Backdoor.Small.EO before it wreaks havoc on your PC.

Aliases

Backdoor.Win32.Small.eo (Kaspersky Lab)
W32/Sdbot.worm.gen (McAfee)
BKDR_SDBOT.GAA (Trend Micro)
W32/Hwbot-A (Sophos)
Backdoor:Win32/Small.BX (Microsoft)
Win-Trojan/Small.6694 (AhnLab)
packed with PE_Patch (Kaspersky Lab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\hwclock.exe
    2 %Windir%\Debug\dcpromo.log

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
Loading...