Sophos

W32/Sdbot-BFX

Aliases
  • Backdoor.Win32.SdBot.xd
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from July 2005 (3.95)
Protection available since 6 June 2005 20:32:14 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-BFX is a network worm with backdoor functionality for the Windows platform.

When run, W32/Sdbot-BFX copies itself to the Windows folder as aim.exe and registers itself as a system service with the display name "AIM". The following registry entries are created:

HKLM\System\CurrentControlSet\Services\Aim
<several entries>

HKLM\System\CurrentControlSet\Enum\Root\LEGACY_AIM
<several entries>

W32/Sdbot-BFX drops the file rdriv.sys to the Windows system folder and registers the dropped file as a system service with the display name "RDRIV". Sophos's anti-virus products detect rdriv.sys as Troj/RootKit-W.

The worm spreads through network shares protected by weak passwords, MS-SQL servers and through various operating system vulnerabilities.

W32/Sdbot-BFX connects to a predetermined IRC channel and awaits further commands from remote users. The backdoor component of W32/Sdbot-BFX can be instructed to perform the following functions:

scan networks for vulnerabilities
download/execute arbitrary files
start an ftp server

Patches for the vulnerabilities exploited by W32/Sdbot-BFX can be obtained from Microsoft at:

MS02-039
MS04-011
MS04-012

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer