Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2005 (3.95) |
| Protection available since | 6 June 2005 20:32:14 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-BFX is a network worm with backdoor functionality for the Windows platform.
When run, W32/Sdbot-BFX copies itself to the Windows folder as aim.exe and registers itself as a system service with the display name "AIM". The following registry entries are created:
HKLM\System\CurrentControlSet\Services\Aim
<several entries>
HKLM\System\CurrentControlSet\Enum\Root\LEGACY_AIM
<several entries>
W32/Sdbot-BFX drops the file rdriv.sys to the Windows system folder and registers the dropped file as a system service with the display name "RDRIV". Sophos's anti-virus products detect rdriv.sys as Troj/RootKit-W.
The worm spreads through network shares protected by weak passwords, MS-SQL servers and through various operating system vulnerabilities.
W32/Sdbot-BFX connects to a predetermined IRC channel and awaits further commands from remote users. The backdoor component of W32/Sdbot-BFX can be instructed to perform the following functions:
scan networks for vulnerabilities
download/execute arbitrary files
start an ftp server
Patches for the vulnerabilities exploited by W32/Sdbot-BFX can be obtained from Microsoft at:
