AIM SDBot Worm Installs Lockx.exe RootKit, Takes You to eza1netsearch.com

The Internet Patrol default featured image
Share the knowledge

A new AOL Instant Messenger worm called SDBot.add has been discovered which installs the Lockx.exe rootkit on your computer, and redirects your searches to eza1netsearch[dot]com

A rootkit (also known as “root kit”) is a usually undetectable piece of malicious software which, once installed, allows someone to have full root (master) access to your computer. Once the Lockx.exe rootkit has been installed, it opens a direct connection to an IRC channel, through which people can take control of your computer.

In addition to installing the Lockx.exe root kit, SDBot.add installs a host of other malware, spyware, and adware.

The new AIM worm is being propagated by the usual AIM worm methods – you receive an AIM message from someone, often someone you know, with a link in it, and when you click on the link, the worm is transferred to your computer.

The SDBot.add AIM worm and its Lockx.exe rootkit were discovered by FaceTime Communications, an online security company.

The Internet Patrol is completely free, and reader-supported. Your tips via CashApp, Venmo, or Paypal are appreciated! Receipts will come from ISIPP.

CashApp us Square Cash app link

Venmo us Venmo link

Paypal us Paypal link

Said Tyler Wells of FaceTime, “A very nasty bundle is downloaded to your machine. This is the first time that we have seen a rootkit as part of the bundle of applications that is sent to your machine. It is a disturbing trend.”

Get New Internet Patrol Articles by Email!

The Internet Patrol is completely free, and reader-supported. Your tips via CashApp, Venmo, or Paypal are appreciated! Receipts will come from ISIPP.

CashApp us Square Cash app link

Venmo us Venmo link

Paypal us Paypal link

 


Share the knowledge

One thought on “AIM SDBot Worm Installs Lockx.exe RootKit, Takes You to eza1netsearch.com

  1. Removal instructions here:
    Here: http://www.daniweb.com/techtalkforums/thread33918.html

Leave a Reply

Your email address will not be published. Required fields are marked *

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.