Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Oct 16, 2007 | Updated Sep 15, 2017

Backdoor:Win32/Sdbot.ZA

Detected by Microsoft Defender Antivirus

Aliases: Win32/IRCBot.worm.variant (AhnLab) W32/SDBot.VSF (Command) Win32/Sdbot (ESET) Backdoor.Win32.SdBot.aql (Kaspersky) Generic.dv (McAfee) W32/Spybot.BEUL (Norman) W32/Gaobot.OLI.worm (Panda) W32/Sdbot-CVP (Sophos) W32.IRCBot (Sunbelt Software) WORM_SDBOT.BUU (Trend Micro)

Summary

Backdoor:Win32/Sdbot.ZA is a backdoor Trojan that allows an attacker to take control of an infected computer. When a computer is infected, the Trojan connects to an Internet Relay Chat (IRC) server and joins a channel in order to receive commands from the controlling attacker. This malware can also spread via network shares with weak passwords, and by exploiting a known vulnerability in the RPCSS Service (addressed in Microsoft Security Bulletin MS03-039).
Backdoor:Win32/Sdbot.ZA may download and install additional malicious software, thus manual removal is not recommended. To detect and remove this Trojan and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx
Follow us