Troj/Sdbot-DPF

Category: Viruses and Spyware Protection available since:03 Nov 2009 03:48:46 (GMT)
Type: Trojan Last Updated:03 Nov 2009 03:48:46 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

When first run Troj/Sdbot-DPF will copy itself to the Windows system folder as mslsrv32.exe and sets the following registry entries to ensure it is run at system logon:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Driver Setup <Windows>\mslsrv32.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Microsoft Driver Setup <Windows>\mslsrv32.exe

Troj/Sdbot-DPF may attempt to exploit the following Vulnerability:
SRVSVC (MS06-040)

download Try Sophos products for free
Download now