Sophos

W32/SdBot-MX

Category
Type
What to do
Prevalence low high

Summary

Action

More Information

W32/SdBot-MX is a worm which spreads via network shares. When first run the worm will create a copy of itself named asclt.exe in the Windows system folder and create the following registry entry to ensure that the copy is run every time Windows starts:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Configurations Asclt

W32/SdBot-MX searches for shared folders with weak passwords and copies itself to the Windows system folder of a vulnerable computer as gt.exe. The worm includes backdoor functions which can be controlled by a remote attacker over IRC.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer