W32/Sdbot-CZQ is a worm and IRC backdoor Trojan for the Windows platform.
W32/Sdbot-CZQ runs continuously in the background, providing a backdoor service which allows a remote intruder to access the computer via IRC channels.
W32/Sdbot-CZQ attempts to spread via network shares protected by weak passwords.
The worm copies itself to <System>\miyhart.exe and adds entries to the registry at:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Fxoekm
miyhart.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Fxoekm
miyhart.exe
W32/Sdbot-CZQ includes functionality to download code from the internet.