The Web    Google
3/25: Sdbot-WG a Worm and IRC Trojan

3/25: Sdbot-WG a Worm and IRC Trojan
March 25, 2005

W32/Sdbot-WG is a network worm and IRC backdoor Trojan for the Windows platform that allows a remote intruder to access and control the computer via IRC channels. W32/Sdbot-WG also drops a file to the current folder that is detected by Sophos products as Troj/NtRootK-F.

The backdoor component joins a specific channel on an IRC server and then runs continuously in the background as a service process, listening on the IRC channel for specific commands and carrying out the appropriate actions.

More information can be found at Sophos page.

  • ActivCard Enhances Authentication for Remote Access Over Web
  • Network Security Management Market Heats Up
  • Bagle-BK Worm Downloads Code
  • 12/17: Atak.J Worm Uses Own Engine
  • War Threat Threaded to Digital Attacks?
  • Virus Alert: Worm Spreads Via Hidden System Shares
  • It's Time to Talk Mobile Phone Security
  • 9/9: Mydoom-U Worm Packed with UPX
  • 5/11: Ifbo-A Worm Exploits LSASS Flaw
  • 5/17: Flush-D Trojan Modifies DNS Server
  • SunGard to Spin Off Disaster Recovery Biz
  • Cheap Security Camera