W32/SdBot.WV!tr

description-logoAnalysis

W32/SdBot.WV-tr is a trojan. When executed, it modifies registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist

Auto-Execute at Windows Startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_USERS\...\Software\Microsoft\Windows\CurrentVersion\Run
   Configuration Loading Service = wscel.exe
This trojan drops a file "ornie.dll" which is the same copy as this trojan.

recommended-action-logoRecommended Action

Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option

Telemetry logoTelemetry

Detection Availability

FortiGate
Extended
FortiClient
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR