Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 30 September 2004 08:00:41 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-WZ is a network worm and backdoor for the Windows platform. The worm spreads to shared folders with weak passwords.
The backdoor component connects to a predefined IRC server and waits for commands from a remote attacker.
When run W32/Sdbot-WZ copies itself to the Windows system folder as grwfsrs.exe. The worm ensures that the copy is run each time Windows starts by adding the registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
gcsxgsqfss = grwfsrs.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
gcsxgsqfss = grwfsrs.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
gcsxgsqfss = grwfsrs.exe
The backdoor component allows a remote attacker to:
transfer files to and from the infected computer
steal CD keys for certain game software
use the infected computer as a proxy server
launch distributed denial of service attacks
Sophos Anti-Virus version 3.84 detects this worm as W32/Sdbot-Fam without requiring an update.
