W32/Sdbot-DOR

Category: Viruses and Spyware Protection available since:11 May 2009 20:17:46 (GMT)
Type: Win32 worm Last Updated:11 May 2009 20:17:46 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Sdbot-DOR is a worm for the Windows platform.

W32/Sdbot-DOR copies itself to <SYSTEM>\drivers\Regv.exe

W32/Sdbot-DOR spreads via removable storage devices, copying itself to drives upon insertion and creating an autorun.inf on the drive detected as Mal/AutoInf-A.

W32/Sdbot-DOR also modifies <SYSTEM>\drivers\tcpip.sys to increase the maximum number of connections allowed.

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
0x00000001

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
0x00000001

W32/Sdbot-DOR sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry
Start
0x00000004

HKLM\SYSTEM\CurrentControlSet\Services\wscsvc
Start
0x00000004

Registry entries are set as follows:

HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
0x00000001

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0x00000000

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0x00000000

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0x00000000

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe %windir%\system32\drivers\Regv.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
0xffffff9d

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
0x00000001

download Try Sophos products for free
Download now