Sophos

W32/SdBot-FQ

Aliases
  • Backdoor.IRCBot.gen
  • W32/Sdbot.worm.gen
  • IRC/SdBot.OA
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from April 2004 (3.80)
Protection available since 19 February 2004 12:01:34 (GMT)
Last updated 21 April 2004 08:57:54 (GMT)
Detected by All Sophos products

Action

More Information

W32/SdBot-FQ is an internet worm and an IRC backdoor Trojan.

W32/SdBot-FQ copies itself into the Windows system folder as Beta.EXE and creates the following registry entries to point to it:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\

W32/SdBot-FQ attempts to run as a service process.

W32/SdBot-FQ scans networks for shares protected by weak passwords and attempts to copy itself over to those shares. The worm also logs onto a predefined IRC server and waits for backdoor commands.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer