Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 3 March 2007 15:21:48 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-DAA is a worm for Windows platforms.
When run, W32/Sdbot-DAA copies itself to the following folder :
<System>\znnsvc.exe.
If successful, W32/Sdbot-DAA runs itself with the following option :
"<System>\znnsvc.exe --install"
W32/Sdbot-DAA includes functionality to steal local personal information including passwords.
This sensitive data is sent to a remote server.
W32/Sdbot-DAA attempts to download and execute code from a remote ftp server.
The worm W32/Sdbot-DAA scans the local network looking for network shares protected by weak passwords.
If successful, W32/Sdbot-DAA will connect and spread itself to the new exploited computer.
W32/Sdbot-DAA also attempts to scan local networks for SQL servers such as Oracle or MS SQL Server and attempts to spread through them.
The following registry entry is set for automatic startup :
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
'ZNN'
'<System>\znnsvc.exe'
