Troj/Sdbot-EF is an IRC backdoor Trojan that has spreading capability.
Troj/Sdbot-EF copies itself into the Windows system folder as vjdhdg.exe and creates entries under the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
djdsdvqwa = vjdhdg.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\djdsdvqwa = vjdhdg.exe
Troj/Sdbot-EF attempts to run as a service process.
Troj/Sdbot-EF logs onto a predefined IRC server and waits for backdoor commands.
The spreading functionality of the Trojan can be activated by a backdoor command. When activated, the Trojan will attempt to copy itself into shares.