W32/Sdbot-SB is a member of the W32/Sdbot family of worms with a backdoor component.
W32/Sdbot-SB is a member of the W32/Sdbot family of worms with a backdoor
component.
In order to run automatically when Windows starts up the worm copies itself to the file winprotect.exe in the Windows system folderand adds the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\winprotect
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\winprotect
W32/Sdbot-SB is dropped by Troj/Wurmark-B.