W32/Sdbot-LQ is a worm which attempts to spread to remote network shares.
It also contains backdoor Trojan functionality, allowing unauthorised remote access to the infected computer via IRC channels.
It spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate command from a remote user.
Can delete shared network drives and collect CD keys from several popular computer games and applications.
Copies itself to the Windows system folder as NAVCPE.EXE and creates entries in the registry at the following locations to run itself on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
System Information Manager = navcpe.exe
Remove it with RegRun.
Removal: navcpe.exe is removed by RegRun.
Read more... Removal instructions...
UnHackMe - Rootkit/Malware killer
Also recommended software:
RegRun Security Suite Platinum - removal and protection.
UnHackMe is a part of RegRun Security Suite Platinum.
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
November 16 2009
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?