Sophos

W32/Sdbot-YI

Aliases
  • W32/Sdbot.worm.gen.bi
  • WORM_SDBOT.BUX
  • Trojan.SdBot-316
  • W32.Randex
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2005 (3.95)
Protection available since 19 May 2005 21:34:15 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-YI is a worm with backdoor Trojan functionality.

W32/Sdbot-YI connects to an IRC channel and listens for backdoor commands from a remote attacker. The worm may spread to remote network shares with weak passwords.

The backdoor functionality of the worm includes the ability to participate in denial-of-service attacks, delete network shares, steal registration keys for certain software products and download and run further malicious code.

When first run the worm copies itself to the Windows system folder as iwnujdss2.exe.

The following registry entries are created to run iwnujdss2.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Sts
"iwnujdss2.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Sts
"iwnujdss2.exe"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer