W32/Sdbot-DOR is a worm for the Windows platform.
W32/Sdbot-DOR copies itself to <SYSTEM>\drivers\Regv.exe
W32/Sdbot-DOR spreads via removable storage devices, copying itself to drives upon insertion and creating an autorun.inf on the drive detected as Mal/AutoInf-A.
W32/Sdbot-DOR also modifies <SYSTEM>\drivers\tcpip.sys to increase the maximum number of connections allowed.
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
0x00000001
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
0x00000001
W32/Sdbot-DOR sets the following registry entries, disabling the automatic startup of other software:
HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry
Start
0x00000004
HKLM\SYSTEM\CurrentControlSet\Services\wscsvc
Start
0x00000004
Registry entries are set as follows:
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
0x00000001
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0x00000000
HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0x00000000
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0x00000000
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe %windir%\system32\drivers\Regv.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
0xffffff9d
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
0x00000001