W32/Sdbot-KU

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Sdbot-KU is an IRC backdoor Trojan and network worm which can run in the background as a service process and allow unauthorised remote access to an intruder via the IRC network.

W32/Sdbot-KU copies itself to the Windows System (or System32 under MS Win NT/2000/XP) folder as PEREMPTION.EXE and creates the following registry entries so that this worm is run automatically on system restart:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
msgmsgs = peremption.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
msgmsgs = peremption.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
msgmsgs = peremption.exe

W32/Sdbot-KU remains resident listening for commands from the remote intruder.

If the appropriate commands are received the worm will begin scanning the internet for network shares with weak administrator passwords and will attempt to copy itself to these shares.

This worm can also initiate SYNFlood attacks, exploit computers infected with W32/MyDoom and attempt to steal CD keys from several computer games.

W32/Sdbot-KU can also delete shared drives and exploit the DCOM vulnerability on unpatched computers.

download Try Sophos products for free
Download now