Sophos

W32/Sdbot-DGI

Aliases
  • Backdoor.Win32.SdBot.bkl
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from August 2007 (4.20)
Protection available since 13 July 2007 12:12:46 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-DGI is a worm with IRC backdoor functionality for the Windows platform.

W32/Sdbot-DGI runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When first run W32/Sdbot-DGI copies itself to <System>\sys32.exe.

The following registry entries are created to run sys32.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Firewall Controls
sys32.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Firewall Controls
sys32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Firewall Controls
sys32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Firewall Controls
sys32.exe

Registry entries are set as follows:

HKCU\Software\Microsoft\OLE
Firewall Controls
sys32.exe

HKLM\SOFTWARE\Microsoft\Ole
Firewall Controls
sys32.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer