W32/Sdbot-JB is a worm which attempts to spread to remote network shares. It
also contains backdoor Trojan functionality, allowing unauthorised remote
access to the infected computer via IRC channels while running in the
background as a service process.
W32/Sdbot-JB copies itself to the Windows system folder as WINUPDATE.EXE
and creates entries in the registry at the following locations so as to run itself
on system startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
W32/Sdbot-JB attempts to spread to network shares with weak passwords.
W32/Sdbot-JB also sits in the background as a service process waiting for
commands from a remote user.