Home Malware Programs Viruses W32/Sdbot.worm!fn

W32/Sdbot.worm!fn

Posted: December 15, 2009

W32/Sdbot.worm!fn is a computer virus that provides a remote hacker with full access to a compromised computer via an IRC (Internet Relay Chat) protocol. W32/Sdbot.worm!fn can spread through spam email messages, network shared drives or downloaded by other threats like Trojans. W32/Sdbot.worm!fn poses a severe security threat as it leaves your PC defenseless in the hands of malicious hackers. Remove W32/Sdbot.worm!fn immediately once detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\sectray.exe
    2 [Drive]:\autorun.inf
    3 [Drive]:\removeMe%i%i%i%i.bat
    4 [Drive]:\usbassistant.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER \S-1-5-21-1454471165-926492609-839522115-500\Software\Microsoft\Windows\CurrentVersion\RunHKEY..\..\..\..{RegistryKeys}Windows Network Setup Manager = "%AppData%\sectray.exe"
Loading...