Sophos

W32/Sdbot-RE

Aliases
  • Backdoor.Win32.SdBot.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 9 November 2004 09:54:30 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-RE is a worm that attempts to spread via remote network shares. The worm tries to access various network computers with shared folders using weak passwords.

W32/Sdbot-RE contains backdoor Trojan functions that allows unauthorised remote access to the infected computer via IRC channels while running in the background.

When run W32/Sdbot-RE copies itself to the Windows system folder as dsabdw.exe.

The worm also creates the following registry entries so that it is able to run on user logon or computer restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
DASDS VSAVdjs = dsabdw.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
DASDS VSAVdjs = dsabdw.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
DASDS VSAVdjs = dsabdw.exe

W32/Sdbot-RE will attempt to perform the following actions when instructed to do so by a remote attacker:

- download and run files from the Internet
- partake in DDoS (denial of service) attacks
- may copy to network shares as the filename abbsasn.exe
- steal computer information (eg. CPU, memory)
- terminates processes

Sophos's anti-virus products include proactive protection technology, which can defend against new threats without requiring an update. Sophos customers have been protected against W32/Sdbot-RE (detected as W32/Sdbot-Fam) since version 3.85.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer