Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 8 September 2004 08:25:39 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-OU is a network worm and backdoor Trojan. The worm spreads by copying itself to network shares that have weak passwords.
W32/Sdbot-OU creates a copy of itself named MAJDE.EXE in the Windows system folder and adds the following registry entries to ensure that the copy is run each time the computer restarts:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
ValuSet = MaJde.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
ValuSet = MaJde.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
ValuSet = MaJde.exe
The backdoor component of the worm attempts to connect to an IRC server and awaits commands from a remote attacker.
