Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 12 November 2004 08:58:49 (GMT) |
| Last updated | 11 October 2005 19:27:47 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Sdbot-RH is a backdoor Trojan that allows unauthorised remote access to the infected computer via IRC channels while running as a process in the background.
When run Troj/Sdbot-RH copies itself to the Windows system folder as et3rd.exe.
The Trojan also creates the following registry entries so that it is able to run on computer restart:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
alt CTRL Shift = et3rd.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
alt CTRL Shift = et3rd.exe
Troj/Sdbot-RH will attempt to partake in distributed denial of service (DDoS) attacks, steal computer information, download and run files from the Internet when instructed to do so by a remote attacker.
