Sophos

W32/Sdbot-RF

Aliases
  • W32/Sdbot.worm.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from December 2004 (3.88)
Protection available since 10 November 2004 10:00:07 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-RF is a worm with backdoor Trojan functionality for the Windows platform that allows a malicious user remote access to an infected computer via IRC channels while running in the background as a service process.

W32/Sdbot-RF may arrive in a RAR archive that extracts the worm main executable with the filename sbsfbsat.exe to the \WinNT\system32 folder, which copies itself with the filename sdqdqg.exe to the Windows system folder.

W32/Sdbot-RF also extracts Troj/Ranck-AZ with the filename sbsvsd.exe to the Windows system folder.

In order to run automatically when Windows starts up W32/Sdbot-RF creates the following registry entries with the path to the sdqdqg.exe file:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\genserv path

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\genserv path

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\genserv path

W32/Sdbot-RF spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer