Sophos

W32/SdBot-CH

Aliases
  • Backdoor.IRCBot.gen
  • W32/Sdbot.worm.gen
  • W32.IRCBot.Gen
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from June 2004 (3.82)
Protection available since 13 May 2004 13:57:37 (GMT)
Detected by All Sophos products

Action

More Information

W32/SdBot-CH is a network worm and a backdoor Trojan which runs in the
background as a service process and allows unauthorised remote access
to the computer via IRC channels.

When executed W32/SdBot-CH copies itself to the Windows system folder with
the filename mdms.exe and sets the registry entries

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Machine Debug Manager=mdms.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Machine Debug Manager=mdms.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Machine Debug Manager=mdms.exe

with the path to the copy.

W32/SdBot-CH attempts to copy itself to remote network shares with weak
passwords.

As a backdoor W32/SdBot-CH can be used to install and execute programs
on your computer, retrieve system information and flood other computers
with network packets.

The information the worm retrieves includes computer name, user name, operating
system, memory size and CD-keys for various games.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer