Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Included in our products from | July 2005 (3.95) |
| Protection available since | 6 June 2005 20:32:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-BFW is a network worm with backdoor functionality for the Windows platform.
When first run, W32/Sdbot-BFW copies itself to the Windows system folder as w32dns.exe and creates the following registry entries in order to run each time a user logs on:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Windows Updates
w32dns.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Windows Updates
w32dns.exe
The worm spreads through network shares protected by weak passwords, MS-SQL servers and through various operating system vulnerabilities.
W32/Sdbot-BFW connects to a predetermined IRC channel and awaits further commands from remote users. The backdoor component of W32/Sdbot-BFW can be instructed to perform the following functions:
scan networks for vulnerabilities
download/execute arbitrary files
start an ftp server
Patches for the vulnerabilities exploited by W32/Sdbot-BFW can be obtained from Microsoft at:
