TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_SDBOT.ZD
Overview

Malware type: Backdoor

Aliases: Backdoor.Win32.SdBot.gen (Kaspersky), W32/Sdbot.worm.gen (McAfee), W32.Randex.gen (Symantec), Worm/SdBot.58880 (Avira), W32/Sdbot-BQ (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP

Encrypted: No

Overall risk rating:


Description: 

This memory-resident backdoor program drops copies of itself in the Windows system folder and creates autostart entries in several registry keys of the affected system.

It allows a malicious user to remotely access files and resources of a target system, thus compromising it. It also steals important system information from the compromised system.

This malware has the ability launch a SYN flood attack to the affected network. It also enables a remote user to use the infected system in order to download and upload malicious files.

It runs on Windows 95, 98, ME, NT, 2000 and XP.

For additional information about this threat, see:
Solution
Technical Details

Description created: Mar. 30, 2004 2:16:44 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.