Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

W32/Sdbot.worm.73728

Feb 19, 2004 8:48AM PST

Date Discovered: 10/13/2003
Date Added: 10/16/2003
Origin: Unknown
Length: 73,728 bytes
Type: Virus
SubType: Internet Worm

This threat is detected as W32/Randbot.worm with the current DAT files. DAT files prior to 4298 detect this threat as New Malware.b when scanning with program heuristics enabled.

When run, it copies itself to the WINDOWS SYSTEM (%sysDir%) directory and creates a registry run keys to load the worm at system startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ Run "Microsoft Netview Component v5.1" = msnv32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ RunServices "Microsoft Netview Component v5.1" = msnv32.exe

Read more: http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100748

Discussion is locked