Sophos

W32/Sdbot-CZX

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2007 (4.16)
Protection available since 28 February 2007 03:29:44 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-CZX is a worm with backdoor functionality for the Windows platform.

When first run W32/Sdbot-CZX copies itself to <System>\algose32.exe.

W32/Sdbot-CZX sets the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Office Monitorse
<path to worm executable>

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Office Monitorse
<path to worm executable>

The worm also sets the following registry entries:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer