Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | July 2006 (4.07) |
| Protection available since | 7 September 2005 12:57:48 (GMT) |
| Last updated | 29 May 2006 22:40:20 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Sdbot-ACW is a worm and IRC backdoor Trojan for the Windows platform.
W32/Sdbot-ACW spreads:
- to other network computers infected with W32/Sasser
- to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812), WINS (MS04-045) and MSSQL (MS02-039) (CAN-2002-0649)
- by copying itself to network shares protected by weak passwords
W32/Sdbot-ACW runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Sdbot-ACW includes functionality to:
- carry out DDoS flooder attacks
- silently download, install and run new software
- modify the HOSTS file
- disable other applications
When first run W32/Sdbot-ACW copies itself to
The file msdirectx.sys is detected as Troj/NtRootK-F.
The following registry entries are created to run msnzx.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Media-XP-Service-Pack3
msnzx.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Media-XP-Service-Pack3
msnzx.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Media-XP-Service-Pack3
msnzx.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Media-XP-Service-Pack3
msnzx.exe
W32/Sdbot-ACW sets the following registry entries, disabling the automatic startup of other software:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4
HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
Start
4
Registry entries are set as follows:
HKCU\SYSTEM\CurrentControlSet\Control\Lsa
Media-XP-Service-Pack3
msnzx.exe
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
Media-XP-Service-Pack3
msnzx.exe
HKCU\Software\Microsoft\OLE
Media-XP-Service-Pack3
msnzx.exe
HKLM\SOFTWARE\Microsoft\Ole
Media-XP-Service-Pack3
msnzx.exe
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1
W32/Sdbot-ACW may modify the HOSTS file, changing the URL-to-IP mappings for selected websites, therefore preventing normal access to these sites. The new HOSTS file will typically contain the following:
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com
127.0.0.1 http://www.virustotal.com
127.0.0.1 virusscan.jotti.org/
127.0.0.1 windowsupdate.microsoft.com/
1.3.3.7 www.bullguard.com/
127.0.0.1 www.techguy.org/
127.0.0.1 www.castlecops.com/
127.0.0.1 www.bleepingcomputer.com/
127.0.0.1 www.ozzu.com/
127.0.0.1 www.annoyances.org/
127.0.0.1 www.geekstogo.com/
127.0.0.1 www.designtechnica.com/
127.0.0.1 members.connectto.net/
127.0.0.1 www.spywareinfo.dk/
127.0.0.1 www.ccleaner.com/
127.0.0.1 www.spywareguide.com/
127.0.0.1 www.ewido.net/
127.0.0.1 www.webroot.com/
127.0.0.1 www.microsoft.com/spyware/
127.0.0.1 www.thespykiller.co.uk/
127.0.0.1 www.filehippo.com/
127.0.0.1 www.noidea.us/
127.0.0.1 forums.net-integration.net/
The following patches for the operating system vulnerabilities exploited by W32/Sdbot-ACW can be obtained from the Microsoft website:
