Summary

Summary
Action
More Information
| Included in our products from | April 2004 (3.80) |
|---|---|
| Protection available since | 19 February 2004 12:01:34 (GMT) |
| Last updated | 21 April 2004 08:57:54 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SdBot-FQ is an internet worm and an IRC backdoor Trojan.
W32/SdBot-FQ copies itself into the Windows system folder as Beta.EXE and creates the following registry entries to point to it:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
W32/SdBot-FQ attempts to run as a service process.
W32/SdBot-FQ scans networks for shares protected by weak passwords and attempts to copy itself over to those shares. The worm also logs onto a predefined IRC server and waits for backdoor commands.
