Sophos

W32/Sdbot-DKM

Aliases
  • W32/Sdbot.worm.gen.ci
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2008 (4.31)
Protection available since 10 June 2008 19:11:06 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-DKM is a worm for the Windows platform.

When first run W32/Sdbot-DKM copies itself to <System>\filename.exe.

The following registry entries are created to run filename.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HOT FIX
filename.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HOT FIX
filename.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HOT FIX
filename.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HOT FIX
filename.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HOT FIX
filename.exe

The file filename.exe is registered as a new file system driver service named "hotfix.microsoft.com", with a display name of "HOT FIX" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\hotfix.microsoft.com

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer