Malware type: Worm
Platform: Windows 98, ME, NT, 2000, XP, Server 2003http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SDBOT.DHY
This worm may be dropped by other malware. It may arrive via network shares. It may be downloaded unknowingly by a user when visiting malicious Web sites.
It drops copies of itself. It terminates the initially executed copy and executes the dropped copy. It also drops and executes a malicious file.
It creates registry entries, some of which enable its automatic execution at every system startup.
It connects to a specified IRC server and joins specified channels. Once connected, a remote user may execute various commands on the affected system.
It uses a list of user names and passwords to access password-protected shares.
It terminates certain services if found on the system. It creates mutex(es) to ensure that only one instance of itself is running in memory.