Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | November 2004 (3.87) |
| Protection available since | 30 September 2004 08:00:41 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-WO is a network worm and backdoor for the Windows platform. The worm spreads to shared folders with weak passwords.
The backdoor component connects to a predefined IRC server and waits for commands from a remote attacker.
When run W32/Sdbot-WO copies itself to the Windows system folder as IEXPLORE.exe. The worm ensures that the copy is run each time Windows starts by adding the registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Explorer Updater = IEXPLORE.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Explorer Updater = IEXPLORE.exe
The backdoor component allows a remote attacker to:
transfer files to and from the infected computer
steal CD keys for certain game software
use the infected computer as a proxy server
launch distributed denial of service attacks
