Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 5 August 2004 13:36:44 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please read the instructions for removing W32/Sdbot-QC.
More Information
W32/Sdbot-QC is a Network worm with IRC backdoor functionality.
When started the worm will copy itself to the Windows System folder as rbot32.exe and create the following registry entries so as to auto-start on user logon or system boot:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
sl4 rules = rbot32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
sl4 rules = rbot32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
sl4 rules = rbot32.exe
When active W32/Sdbot-QC will attempt to connect to a remote IRC server and join a secret channel from where further commands may be issued by an attacker.
As other members of the Sdbot family, the worm will also attempt to bruteforce weak network shares and steal game key information.
