
SonicWALL UTM Research team observed a new Autorun.inf worm variant starting on Monday, January 26, 2009 which has IRC Bot functionality and spreads via network shares or by exploiting windows vulnerabilities.
SonicWALL has received 7 copies of this network aware worm. It performs following activities when executed:
Host level activities
Network level activities
The worm is also known as Exploit:Win32/MS06040.gen , IRC/SdBot trojan , and Worm/SdBot.735232.1
SonicWALL Gateway AntiVirus provides protection against this malware via GAV: SdBot.NW (Worm) signature .

Share This Article

An Article By
An Article By
Security News
Security News