Sophos

W32/Sdbot-RI

Aliases
  • W32/Sdbot.worm.gen
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from January 2005 (3.89)
Protection available since 13 November 2004 16:16:43 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-RI is a worm with backdoor Trojan functionality.

W32/Sdbot-RI spreads by copying a dropper file named AMQNF.EXE to computers on the local network protected by weak passwords. The dropper file is detected as W32/Sdbot-RI. The dropper file also drops and runs Troj/Ranck-BA.

When first run, W32/Sdbot-RI copies itself to the Windows system folder as ADDIT.EXE and runs this copy of the worm. In order to run each time a user logs on, W32/Sdbot-RI will set the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
1 = addit.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
1 = addit.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
1 = addit.exe

The worm runs continuously in the background providing backdoor access to the infected computer over IRC channels.

Sophos's anti-virus products include proactive protection technology, which can defend against new threats without requiring an update. Sophos customers have been protected against the dropper component of W32/Sdbot-RI (detected as Troj/Ranck-Gen) since version 3.85 with archive handling activated.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer