Sophos

W32/Sdbot-WO

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 30 September 2004 08:00:41 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-WO is a network worm and backdoor for the Windows platform. The worm spreads to shared folders with weak passwords.

The backdoor component connects to a predefined IRC server and waits for commands from a remote attacker.

When run W32/Sdbot-WO copies itself to the Windows system folder as IEXPLORE.exe. The worm ensures that the copy is run each time Windows starts by adding the registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Explorer Updater = IEXPLORE.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Explorer Updater = IEXPLORE.exe

The backdoor component allows a remote attacker to:

transfer files to and from the infected computer
steal CD keys for certain game software
use the infected computer as a proxy server
launch distributed denial of service attacks

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer