Summary

Summary
Action
More Information
| Included in our products from | June 2004 (3.82) |
|---|---|
| Protection available since | 13 May 2004 13:57:37 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SdBot-CH is a network worm and a backdoor Trojan which runs in the
background as a service process and allows unauthorised remote access
to the computer via IRC channels.
When executed W32/SdBot-CH copies itself to the Windows system folder with
the filename mdms.exe and sets the registry entries
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Machine Debug Manager=mdms.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Machine Debug Manager=mdms.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Machine Debug Manager=mdms.exe
with the path to the copy.
W32/SdBot-CH attempts to copy itself to remote network shares with weak
passwords.
As a backdoor W32/SdBot-CH can be used to install and execute programs
on your computer, retrieve system information and flood other computers
with network packets.
The information the worm retrieves includes computer name, user name, operating
system, memory size and CD-keys for various games.
