Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2007 (4.19) |
| Protection available since | 6 June 2007 05:19:55 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-DEW is a worm with backdoor functionality for the Windows platform.
W32/Sdbot-DEW spreads to other network computers by exploiting common buffer overflow vulnerabilities.
W32/Sdbot-DEW can be instructed to perform the following functions:
start an FTP server
start a Proxy server
start a web server
start an IRC daemon
take part in distributed denial of service (DDoS) attacks
log keypresses (such as username password)
capture screen/webcam images
packet sniffing
port scanning
download/execute arbitrary files
start a remote shell (RLOGIN)
steal product registration information from certain software
turn off security software such as anti-virus or firewall
The worm may also spread via networks shares protected by weak passwords.
When first run W32/Sdbot-DEW copies itself to <Windows>\VTTimer.exe.
Registry entries are modified under:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\winLogon
