W32/Sdbot-CRR is a worm for the Windows platform.
W32/Sdbot-CRR contains functionality to allow remote access via a backdoor.
W32/Sdbot-CRR is a worm for the Windows platform.
W32/Sdbot-CRR contains functionality to allow remote access via a backdoor.
When installed, W32/Sdbot-CRR will copy itself to the following filename:
<Windows>\windows.exe
and create the following file:
<System>\rdriv.sys - detected as Troj/Rootkit-W
W32/Sdbot-CRR may also create a new service with the name "Java development
Services" and ImagePath of "<Windows>\windows.exe" to allow it to automatically
start up.