TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_SDBOT.ZG
Overview

Malware type: Worm

Aliases: W32/Sdbot.worm.gen.o (McAfee), Backdoor.IRC.Bot (Symantec), TR/Spy.Estpak (Avira), W32/Sdbot-LG (Sophos),

In the wild: Yes

Destructive: Yes

Language: English

Platform: Windows 95, 98, ME,NT, 2000, XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This worm scans the network and attempts to propagate by dropping a copy of itself into target machines. It uses the a list of text strings as user names and passwords to access a target system.

This malware attempts to perform denial of service (DoS) attacks against the following Web sites:

  • hayer.cjb.net
  • hayerorg.com

It terminates processes related to antivirus and security utilities. It also steals the CD keys of several games.

It runs on Windows 98, ME, NT, 2000 and XP.

For additional information about this threat, see:
Solution
Technical Details

Description created: Apr. 27, 2004 6:28:07 PM GMT -0800
Description updated: Apr. 27, 2004 6:49:03 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.