Sophos

W32/Sdbot-BFW

Aliases
  • WORM_SDBOT.BFW
  • Backdoor.Win32.SdBot.zk
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Included in our products from July 2005 (3.95)
Protection available since 6 June 2005 20:32:14 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-BFW is a network worm with backdoor functionality for the Windows platform.

When first run, W32/Sdbot-BFW copies itself to the Windows system folder as w32dns.exe and creates the following registry entries in order to run each time a user logs on:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows Updates
w32dns.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Windows Updates
w32dns.exe

The worm spreads through network shares protected by weak passwords, MS-SQL servers and through various operating system vulnerabilities.

W32/Sdbot-BFW connects to a predetermined IRC channel and awaits further commands from remote users. The backdoor component of W32/Sdbot-BFW can be instructed to perform the following functions:

scan networks for vulnerabilities
download/execute arbitrary files
start an ftp server

Patches for the vulnerabilities exploited by W32/Sdbot-BFW can be obtained from Microsoft at:

MS02-039
MS04-011
MS04-012

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer