Aliases
Backdoor.IRCBot.gen, W32/Sdbot.worm.gen, IRC/SdBot.OC
Type
Win32 worm
Description
W32/SdBot-HI is an internet worm and an IRC backdoor Trojan.
W32/SdBot-HI copies itself into the Windows system folder as Svhost.EXE and creates the following registry entries to point to it:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
W32/SdBot-HI attempts to run as a service process.
W32/SdBot-HI scans networks for shares protected by weak passwords and attempts to copy itself over to those shares. The worm also logs onto a predefined IRC server and waits for backdoor commands.
http://www.sophos.com/virusinfo/analyses/w32sdbothi.html

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic