W32/SdBot-U is a worm which attempts to spread to remote shares which have weak passwords. The worm also allows unauthorized remote access to the computer via IRC channels.
W32/SdBot-U is a worm which attempts to spread to remote shares which have weak passwords. The worm also allows unauthorized remote access to the computer via IRC channels.
W32/SdBot-U copies itself to the Windows system folder as WIN32OP.EXE and creates entries in the registry in the following locations to run itself on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices