W32/Sdbot-XN

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Sdbot-XN is a network worm and backdoor Trojan which runs in the background as a service process and allows unauthorised remote access to the computer via
IRC channels.

When executed W32/Sdbot-XN copies itself to the Windows System32 folder with the filename iexplorer.exe and sets the following registry entries so that it is automatically executed every time the computer restarts:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Internet Explorer = iexplorer.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Internet Explorer = iexplorer.exe

download Try Sophos products for free
Download now