Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | December 2004 (3.88) |
| Protection available since | 10 November 2004 10:00:07 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-RF is a worm with backdoor Trojan functionality for the Windows platform that allows a malicious user remote access to an infected computer via IRC channels while running in the background as a service process.
W32/Sdbot-RF may arrive in a RAR archive that extracts the worm main executable with the filename sbsfbsat.exe to the \WinNT\system32 folder, which copies itself with the filename sdqdqg.exe to the Windows system folder.
W32/Sdbot-RF also extracts Troj/Ranck-AZ with the filename sbsvsd.exe to the Windows system folder.
In order to run automatically when Windows starts up W32/Sdbot-RF creates the following registry entries with the path to the sdqdqg.exe file:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\genserv path
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\genserv path
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\genserv path
W32/Sdbot-RF spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user.
