Sophos

W32/Sdbot-DHY

Aliases
  • Backdoor.Win32.SdBot.bzy
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
  • Network shares
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2007 (4.23)
Protection available since 5 October 2007 18:14:47 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-DHY is a worm for the Windows platform.

W32/Sdbot-DHY spreads to other network computers by exploiting common buffer overflow vulnerabilities and via email messages and network shares and MSSQL servers protected by weak passwords.

W32/Sdbot-DHY runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Sdbot-DHY includes functionality to access the internet and communicate with
a remote server via HTTP.

The worm also is able to steal credentials from:

Windows AutoComplete entries
Internet Explorer AutoComplete entries
Outlook and Outlook Express (including deleted accounts that have not been trashed)
Protected storage volumes
Microsoft Messenger / Windows Live Messenger

When first run W32/Sdbot-DHY copies itself to <Windows>\LBTWiz.exe and creates the file <Windows>\Nokia_19_jpg.zip. This file is also detected as W32/Sdbot-DHY.

The following registry entry is created to run LBTWiz.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LBTWiz.exe
<Windows>\LBTWiz.exe

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions
t
<pathname of the worm executable>

W32/Sdbot-DHY attempts to disable the system file checker by modifying sfc_os.dll or sfc.dll and setting the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
ffffff9d

W32/Sdbot-DHY replaces the following files with a program that does nothing.
<system>\ftp.exe
<system>\tftp.exe

The original version of sfc_os.dll or sfc.dll is copied to <system>\trash<random number>.
The original version of ftp.exe is copied to <system>\Microsoft\backup.ftp.
The original version of tftp.exe is copied to <system>\Microsoft\backup.tftp.

Also the following registry entries are set:

HKLM\SYSTEM\CurrentControlSet\Control
WaitToKillServiceTimeout
7000

HKLM\SYSTEM\CurrentControlSet\Control
ServiceCurrent
0x0000000a

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer