W32/Sdbot-DIV

Category: Viruses and Spyware Protection available since:19 Nov 2007 14:15:12 (GMT)
Type: Win32 worm Last Updated:19 Nov 2007 14:15:12 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Sdbot-DIV is a network worm with IRC backdoor functionality.

When first run W32/Sdbot-DIV copies itself to <Windows>\ccSvcHst.exe and creates the file <Windows>\Dance_dec_jpg.zip.

The following registry entry is created to run ccSvcHst.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ccSvcHst.exe
<Windows>\ccSvcHst.exe

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions
!
<pathname of the worm executable>

download Try Sophos products for free
Download now