Sophos

W32/Sdbot-DAA

Aliases
  • Backdoor.Win32.VanBot.ay
  • WORM_RBOT.FAS
  • W32/Sdbot.worm.gen.ai
  • virus
  • !!!
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 3 March 2007 15:21:48 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Sdbot-DAA is a worm for Windows platforms.

When run, W32/Sdbot-DAA copies itself to the following folder :

<System>\znnsvc.exe.

If successful, W32/Sdbot-DAA runs itself with the following option :

"<System>\znnsvc.exe --install"

W32/Sdbot-DAA includes functionality to steal local personal information including passwords.

This sensitive data is sent to a remote server.

W32/Sdbot-DAA attempts to download and execute code from a remote ftp server.

The worm W32/Sdbot-DAA scans the local network looking for network shares protected by weak passwords.

If successful, W32/Sdbot-DAA will connect and spread itself to the new exploited computer.

W32/Sdbot-DAA also attempts to scan local networks for SQL servers such as Oracle or MS SQL Server and attempts to spread through them.

The following registry entry is set for automatic startup :

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
'ZNN'
'<System>\znnsvc.exe'

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer