Aliases
Backdoor.IRCBot.gen, IRC/SdBot.OD
Type
Win32 worm
Description
W32/SdBot-HJ is an internet worm and an IRC backdoor Trojan.
W32/SdBot-HJ copies itself into the Windows system folder as asclt.EXE and creates the following registry entries to point to it:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
W32/SdBot-HJ attempts to run as a service process.
W32/SdBot-HJ scans networks for shares protected by weak passwords and attempts to copy itself over to those shares. The worm also logs onto a predefined IRC server and waits for backdoor commands.
http://www.sophos.com/virusinfo/analyses/w32sdbothj.html

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic