Sophos

Troj/Sdbot-LH

Aliases
  • IRCbot.em
  • Randex.gen
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from June 2004 (3.82)
Protection available since 12 May 2004 15:11:21 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Sdbot-LH is a member of the Troj/Sdbot family of backdoor Trojans.

Troj/Sdbot-LH allows a malicious user remote access to an infected computer
through IRC channels.

In order to run automatically when Windows starts up Troj/Sdbot-LH copies itself
to the file aupdater.exe in the Windows system folder and creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Auto Updater=aupdater.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer