The Web    Google
3/25: Sdbot-WG a Worm and IRC Trojan

3/25: Sdbot-WG a Worm and IRC Trojan
March 25, 2005

W32/Sdbot-WG is a network worm and IRC backdoor Trojan for the Windows platform that allows a remote intruder to access and control the computer via IRC channels. W32/Sdbot-WG also drops a file to the current folder that is detected by Sophos products as Troj/NtRootK-F.

The backdoor component joins a specific channel on an IRC server and then runs continuously in the background as a service process, listening on the IRC channel for specific commands and carrying out the appropriate actions.

More information can be found at Sophos page.

  • 2/24: Agobot-QE a Backdoor Trojan & Worm
  • Startup Unveils Web Server Assessment, Defense Toolkit
  • Critical Flaws Spoil Opera Tune
  • Sophos Small-Business Suite Fights Viruses, Spam
  • 10/28: Backdoor.Futro a Server Program
  • 12/27: Worm_Santy-F Targets phpBB Applications
  • 10/13: Bifrose a Trojan Horse
  • Homeland Security Names First Privacy Czar
  • 6/14: Dansh.worm!irc an IRC Bot
  • 10/20: Mydoom-AA Worm Spreads Via Email
  • 1/3: Hilin Worm Written in Visual Basic
  • Cheap Security Camera