W32/SdBot-T

Category: Viruses and Spyware Protection available since:08 Jan 2004 00:00:00 (GMT)
Type: Win32 worm Last Updated:08 Jan 2004 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/SdBot-T is a worm which attempts to spread to remote shares which have weak passwords. The worm also allows unauthorized remote access to the computer via IRC channels. W32/SdBot-T is a worm which attempts to spread to remote shares which have weak passwords. The worm also allows unauthorized remote access to the computer via IRC channels.

W32/SdBot-T copies itself to the Windows system folder as MAIN.EXE and creates entries in the registry in the following locations to run itself on system restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

download Try Sophos products for free
Download now