Sophos

W32/Sdbot-DEW

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2007 (4.19)
Protection available since 6 June 2007 05:19:55 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-DEW is a worm with backdoor functionality for the Windows platform.

W32/Sdbot-DEW spreads to other network computers by exploiting common buffer overflow vulnerabilities.

W32/Sdbot-DEW can be instructed to perform the following functions:

 start an FTP server
 start a Proxy server
 start a web server
 start an IRC daemon
 take part in distributed denial of service (DDoS) attacks
 log keypresses (such as username password)
 capture screen/webcam images
 packet sniffing
 port scanning
 download/execute arbitrary files
 start a remote shell (RLOGIN)
 steal product registration information from certain software
 turn off security software such as anti-virus or firewall

The worm may also spread via networks shares protected by weak passwords.

When first run W32/Sdbot-DEW copies itself to <Windows>\VTTimer.exe.

Registry entries are modified under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\winLogon

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer