Summary

Summary
Action
More Information
| Protection available since | 16 June 2004 08:16:14 (GMT) |
|---|---|
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-DQ is an IRC backdoor Trojan and network worm which can run in the background as a service process and allow unauthorised remote access to a remote intruder via the IRC channel.
W32/Sdbot-DQ copies itself to the Windows System (or System32 under MS Win NT/2000/XP) folder as IEXPLORERS.EXE and creates the following registry
entries so that this worm is run automatically on system restart:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
iexplorers loader = iexplorers.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
iexplorers loader = iexplorers.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
iexplorers loader = iexplorers.exe
W32/Sdbot-DQ remains resident, listening for commands from the remote intruder.
If the appropriate commands are received the worm will begin scanning the
internet for network shares with weak administrator passwords and will attempt
to copy itself to these shares.
This worm can also initiate Synflood attacks, exploit computers infected with
W32/MyDoom and attempt to steal CD keys from several computer games.
W32/Sdbot-DQ can also delete shared drives and exploit the DCOM vulnerability on unpatched computers.
