Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Sep 12, 2007 | Updated Sep 15, 2017

Backdoor:Win32/Sdbot.ZD

Detected by Microsoft Defender Antivirus

Aliases: Win32/Weapbot.A (CA) Backdoor.Win32.SdBot.bxr (Kaspersky) W32/Checkout (McAfee) Backdoor:Win32/SDBot.ZD (Microsoft) Trojan.Peed.Gen (Sunbelt Software) W32.Neeris (Symantec) WORM_SDBOT.FEL (Trend Micro)

Summary

Worm:Win32/Neeris.A is a chat client worm with backdoor Trojan functionality. The worm uses API calls for both Windows Messenger and AOL Messenger to send messages to contacts, with an attached file containing a copy of the worm. Worm:Win32/Neeris.A connects to an IRC server and waits to receive commands, such as to self-update, remove itself, download various programs and malware, or terminate running processes.
Worm:Win32/Neeris.A may download and install additional malicious software, thus manual removal is not recommended. To detect and remove this Trojan and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx
Follow us