Sophos

W32/Sdbot-QC

Aliases
  • WORM_SDBOT.QC
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
  • Chat programs
Affected operating systems Windows
Protection available since 5 August 2004 13:36:44 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Sdbot-QC is a Network worm with IRC backdoor functionality.
When started the worm will copy itself to the Windows System folder as rbot32.exe and create the following registry entries so as to auto-start on user logon or system boot:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
sl4 rules = rbot32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
sl4 rules = rbot32.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
sl4 rules = rbot32.exe

When active W32/Sdbot-QC will attempt to connect to a remote IRC server and join a secret channel from where further commands may be issued by an attacker.

As other members of the Sdbot family, the worm will also attempt to bruteforce weak network shares and steal game key information.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer