Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2005 (3.95) |
| Protection available since | 19 May 2005 21:34:15 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please read the instructions for removing W32/Sdbot-YI.
More Information
W32/Sdbot-YI is a worm with backdoor Trojan functionality.
W32/Sdbot-YI connects to an IRC channel and listens for backdoor commands from a remote attacker. The worm may spread to remote network shares with weak passwords.
The backdoor functionality of the worm includes the ability to participate in denial-of-service attacks, delete network shares, steal registration keys for certain software products and download and run further malicious code.
When first run the worm copies itself to the Windows system folder as iwnujdss2.exe.
The following registry entries are created to run iwnujdss2.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Sts
"iwnujdss2.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Sts
"iwnujdss2.exe"
