Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | November 2007 (4.23) |
| Protection available since | 5 October 2007 18:14:47 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-DHY is a worm for the Windows platform.
W32/Sdbot-DHY spreads to other network computers by exploiting common buffer overflow vulnerabilities and via email messages and network shares and MSSQL servers protected by weak passwords.
W32/Sdbot-DHY runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Sdbot-DHY includes functionality to access the internet and communicate with
a remote server via HTTP.
The worm also is able to steal credentials from:
Windows AutoComplete entries
Internet Explorer AutoComplete entries
Outlook and Outlook Express (including deleted accounts that have not been trashed)
Protected storage volumes
Microsoft Messenger / Windows Live Messenger
When first run W32/Sdbot-DHY copies itself to <Windows>\LBTWiz.exe and creates the file <Windows>\Nokia_19_jpg.zip. This file is also detected as W32/Sdbot-DHY.
The following registry entry is created to run LBTWiz.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LBTWiz.exe
<Windows>\LBTWiz.exe
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions
t
<pathname of the worm executable>
W32/Sdbot-DHY attempts to disable the system file checker by modifying sfc_os.dll or sfc.dll and setting the following registry entries:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
ffffff9d
W32/Sdbot-DHY replaces the following files with a program that does nothing.
<system>\ftp.exe
<system>\tftp.exe
The original version of sfc_os.dll or sfc.dll is copied to <system>\trash<random number>.
The original version of ftp.exe is copied to <system>\Microsoft\backup.ftp.
The original version of tftp.exe is copied to <system>\Microsoft\backup.tftp.
Also the following registry entries are set:
HKLM\SYSTEM\CurrentControlSet\Control
WaitToKillServiceTimeout
7000
HKLM\SYSTEM\CurrentControlSet\Control
ServiceCurrent
0x0000000a
