Troj/Sdbot-EF

Category: Viruses and Spyware Protection available since:19 Dec 2003 00:00:00 (GMT)
Type: Trojan Last Updated:19 Dec 2003 00:00:00 (GMT)
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Sdbot-EF is an IRC backdoor Trojan that has spreading capability.

Troj/Sdbot-EF copies itself into the Windows system folder as vjdhdg.exe and creates entries under the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
djdsdvqwa = vjdhdg.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\djdsdvqwa = vjdhdg.exe

Troj/Sdbot-EF attempts to run as a service process.

Troj/Sdbot-EF logs onto a predefined IRC server and waits for backdoor commands.

The spreading functionality of the Trojan can be activated by a backdoor command. When activated, the Trojan will attempt to copy itself into shares.

download Try Sophos products for free
Download now