Sophos

W32/Sdbot-H

Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from January 2004 (3.77)
Protection available since 12 November 2003 15:12:44 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-H is a worm with a backdoor component that spreads via weakly protected network shares.

In order to run automatically when Windows starts up the worm copies itself to the Windows system folder and adds the following registry entries pointing to this file:

HKLM\Software\Microsoft\Windows\CurrentVersion\
Run\Configuration loaded

HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\Configuration loaded

W32/Sdbot-H attempts to copy itself to network shares by using all possible combinations of the following usernames and passwords:
wwwadmin
user
system
sqlagent
sql
root
owner
guest
database
administrator
admin

!@#$%^&*
!@#$%^&
!@#$%^
!@#$%
!@#$
654321
123456
1234
123
111
1
wwwadmin
user
system
sqlagent
sql
server
secret
root
password
password123
pass
pass123
owner
hidden
guest
database
asdfgh
asdf
administrator
admin

The worm has a backdoor component that allows a malicious user to remotely control a compromised computer via the IRC network.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer