Sophos

W32/Sdbot-ACE

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 26 November 2004 08:49:46 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Sdbot-ACE is a network worm and IRC backdoor Trojan for the Windows platform.

When first run W32/Sdbot-ACE copies itself to the Windows system folder as sessionmgr.exe. W32/Sdbot-ACE creates the following registry entries in order to run on user logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
irc session = "sessionmgr.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
irc session = "sessionmgr.exe"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
irc session = "sessionmgr.exe"

The worm spreads through network shares protected by weak passwords. The filename used when spreading through network shares is "session.exe"

The backdoor component of W32/Sdbot-ACE joins an IRC channel and awaits commands from a remote user. W32/Sdbot-ACE can then be instructed to perform tasks such as to:

take part in distributed denial of service (DDoS) attacks
download/execute arbitrary files
scan networks for vulnerabilities
steal product registration keys for certain software
send email

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer