Sophos

W32/Sdbot-DQ

Aliases
  • IRCBot
  • Randex
Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 16 June 2004 08:16:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Sdbot-DQ is an IRC backdoor Trojan and network worm which can run in the background as a service process and allow unauthorised remote access to a remote intruder via the IRC channel.

W32/Sdbot-DQ copies itself to the Windows System (or System32 under MS Win NT/2000/XP) folder as IEXPLORERS.EXE and creates the following registry
entries so that this worm is run automatically on system restart:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
iexplorers loader = iexplorers.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
iexplorers loader = iexplorers.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
iexplorers loader = iexplorers.exe

W32/Sdbot-DQ remains resident, listening for commands from the remote intruder.

If the appropriate commands are received the worm will begin scanning the
internet for network shares with weak administrator passwords and will attempt
to copy itself to these shares.

This worm can also initiate Synflood attacks, exploit computers infected with
W32/MyDoom and attempt to steal CD keys from several computer games.

W32/Sdbot-DQ can also delete shared drives and exploit the DCOM vulnerability on unpatched computers.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer