Category: Viruses and SpywareProtection available since:22 Jan 2004 00:00:00 (GMT)
Type: Win32 wormLast Updated:22 Jan 2004 00:00:00 (GMT)
Prevalence: Small Number of Reports

W32/SdBot-W is a worm that attempts to spread to remote shares which have weak passwords. The worm also allows unauthorised remote access to the computer via IRC channels.

W32/SdBot-W copies itself to the Windows system folder as ADVAP.EXE and creates entries in the registry in the following locations to run itself on system restart: