Firestorm: UK Web Design, Development, Management, Security and Hosting. 

Online Quote  |  Testimonials  |  My Account  |  Latest Virus News

   
UK Web Design & Development

 Virus Library: W32 Sdbot DNZ / Virut

IRC Infection / Attack

W32/Sdbot-DNZ is a worm that is spread by IRC Programs such as MSN Messenger. It runs in the background, providing a backdoor server which allows an intruder to gain access to control the computer via IRC channels.


When W32 is first run it copies itself to C:\\Program Files\VMwareService.exe. The file named VMwareService.exe is created as a new system driver service called "VMwareService", with the display name "VMwareService" and is set to startup automatically.


Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\VMwareService


The W32/Sdbot-DNZ worm spreads via MSN and copies itself into the recycling bin of connected drives e.g usb sticks, flash drives etc... The worm then creates an autorun.inf file in the root of that share to run itself the next time the drive is mounted.


Some particular variants of this virus are capable of infecting web files and program files, often irreparably, and if the computer in question is acting as a web server than the virus is itself capable of infecting anyone who visits  any of the sites located on the server.


The W32/Sdbot-DNZ worm is also known as:

W32/Virut.remnants
Win32/AutoRun.Delf.AG Worm
Virus.Win32.Virut.n

Write Up By: Baz {FireStorm}



Website Owners / Administrators
It is imperative that server security is a priority. You should ensure any publicly accessible systems are behind firewalls, with good quality antivirus software. Webside: querystring and form data should be checked vigorously and fully cleaned before being executed against the database or on any pages. All session objects should also be subject to the same checking methods. Simply checking 'Server Variables' is not acceptable protection, these can be spoofed. Restricting database rights is important on high use front end web applications, only allow what is absolutely essential.



go back   |   top
Online Support

 Advert

Refreshing Web Design

 Powerful Hosting ?


All of our hosting packages come with the following features as standard.

  • Unlimited Bandwidth
  • Online Account Control
  • Instant Setup
  • Webmail Access
  • FTP Access
Refreshing Web Design

 Something Refreshing ?

At FireStorm we can offer bespoke, custom website design packages. Whatever your requirements or budget, we have the knowledge and tools required to build you a colourful, eye catching website, giving your idea or business the best possible chance of success.

Read More
Online Support

 Advert

Website Security Essentials

 Security Essentials

Website security has become an important consideration for anyone who own or runs a website. Secure your website now by downloading the latest version of our renowned website security Firefile ®

More About Security
Domain Registration

 Domain Registration

Use our domain search tool to find and register your perfect domain name. We offer some of the most competetive prices available and all domains come with free online control, email access and web forwarding.
Visit the domains section for more information on domain pricing and registration terms.
Domains Section
UK SEO Specialists

 Search Engine Optimisation

Ensuring your customers can find your website amongst the millions, is one of the top priorities for a site owner. We can help you drive more relevant traffic to your site, connecting you with the people looking for your product.

More About SEO
toolbar powered by Conduit
Web Design  |  Web Management  |  Web Security  |  Web Hosting  |  Support  |  Contact  |  Terms & Conditions  |  My Account  |  Pay Online  |  Feedback  |  Firefile  |  Search Engine Optimisation
Copyright © 2008-2010 Firestorm Online Ltd  |  All Rights Reserved  |  Company Reg: 06654958 Firestorm: Official Partners With Sage PayPayment methods