Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/SdBot-MX is a worm which spreads via network shares. When first run the worm will create a copy of itself named asclt.exe in the Windows system folder and create the following registry entry to ensure that the copy is run every time Windows starts:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Configurations Asclt
W32/SdBot-MX searches for shared folders with weak passwords and copies itself to the Windows system folder of a vulnerable computer as gt.exe. The worm includes backdoor functions which can be controlled by a remote attacker over IRC.
