Summary

Summary
Action
More Information
| Included in our products from | April 2004 (3.80) |
|---|---|
| Protection available since | 5 March 2004 15:19:43 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Troj/Sdbot-GG.
More Information
Troj/Sdbot-GG is a backdoor Trojan which runs in the background as a service process and allows unauthorised remote access to the computer via IRC channels.
The Trojan copies itself to the Windows system folder as CMD32.EXE and creates entries in the registry at the following locations to run itself on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Ass and titties
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Ass and titties
The Trojan remains resident, listening for commands from remote users. If it receives the appropriate command the Trojan attempts to copy itself to remote network shares with weak passwords.
