Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

WORM_SDBOT.EW

Feb 4, 2004 8:05AM PST

Virus type: Worm

Destructive: No

Aliases: W32.SDBOT.Worm, W32/SDBOT.worm.gen

Description:

This worm drops a copy of itself in the Windows system folder as SVCHOSTX.EXE.

It then drops copies of itself in the shared folders of file-sharing applications such as the following:


Kazaa
Imesh
eDonkey2000
LimeWire
Morpheus
It uses enticing file names so that other users are tempted to download the malware copy.

It has backdoor capabilities. This malware sets up an IRC (Internet Relay Chat) server and awaits for commands from a remote attacker. It is able to perform the following actions:

More: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.EW

Discussion is locked