Sophos

W32/Sdbot-DKS

Aliases
  • WORM/SdBot.540672.11
  • Backdoor.Win32.SdBot.bhk
  • W32/Sdbot.worm
  • IRC/SdBot
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2008 (4.33)
Protection available since 16 July 2008 19:05:13 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-DKS is a worm with IRC backdoor functionality.

When first run, W32/Sdbot-DKS copies itself to <Windows>\WinMgmt.exe and creates the following registry entry in order to be run automatically:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
Shell
Explorer.exe %WINDIR%\WinMgmt.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer