









 |
W32/DsBot.OX Trojan
| Name |
W32/DsBot.OX Trojan |
| Aliases |
Win32:DsBot-Q, Backdoor.Win32.DsBot.ox, Worm:Win32/Neeris.Y, WORM_SDBOT.CLZ, W32.Spybot.Worm |
| Discovered on |
August 18, 2008 |
Virus Information - W32/DsBot.OX Trojan:
W32/DsBot.OX is a trojan. The trojan will infect Windows systems.
The trojan may be dropped by other malware or may be downloaded from remote website by other malware. It may also be downloaded unknowingly by a user while visiting malicious Website.
Upon execution, the trojan drops scvhost.exe in the Windows System folder.
The trojan modifies registry at the following locations:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Action Script\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Action Script\ImagePath
HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Security Center\UpdatesDisableNotify
HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify
HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Security Center\FirewallDisableNotify
HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Security Center\AntiVirusOverride
HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Security Center\FirewallOverride
HKEY_LOCAL_MACHINESOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2

|