Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Apr 16, 2009 | Updated Sep 15, 2017

Worm:Win32/Pushbot.KR

Detected by Microsoft Defender Antivirus

Aliases: W32/Sdbot.worm (McAfee) Backdoor.Win32.SdBot.joa (Kaspersky) W32/Chode-AE (Sophos) Backdoor.Sdbot (Symantec)

Summary

Worm:Win32/Pushbot.KR is a worm that may spread via MSN Messenger and/or AIM. The worm also contains backdoor functionality that allows unauthorized access to an affected machine. This worm does not spread automatically upon installation, but must be ordered to spread by a remote attacker.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, see http://www.microsoft.com/protect/computer/viruses/vista.mspx.
Follow us