Sophos

W32/Sdbot-ACW

Aliases
  • WORM_RBOT.CDJ
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2006 (4.07)
Protection available since 7 September 2005 12:57:48 (GMT)
Last updated 29 May 2006 22:40:20 (GMT)
Detected by All Sophos products

Action

More Information

W32/Sdbot-ACW is a worm and IRC backdoor Trojan for the Windows platform.

W32/Sdbot-ACW spreads:

- to other network computers infected with W32/Sasser
- to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812), WINS (MS04-045) and MSSQL (MS02-039) (CAN-2002-0649)
- by copying itself to network shares protected by weak passwords

W32/Sdbot-ACW runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Sdbot-ACW includes functionality to:

- carry out DDoS flooder attacks
- silently download, install and run new software
- modify the HOSTS file
- disable other applications

When first run W32/Sdbot-ACW copies itself to \msnzx.exe and creates the file \%CurrentFolder%\msdirectx.sys.

The file msdirectx.sys is detected as Troj/NtRootK-F.

The following registry entries are created to run msnzx.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Media-XP-Service-Pack3
msnzx.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Media-XP-Service-Pack3
msnzx.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Media-XP-Service-Pack3
msnzx.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Media-XP-Service-Pack3
msnzx.exe

W32/Sdbot-ACW sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
Start
4

Registry entries are set as follows:

HKCU\SYSTEM\CurrentControlSet\Control\Lsa
Media-XP-Service-Pack3
msnzx.exe

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
Media-XP-Service-Pack3
msnzx.exe

HKCU\Software\Microsoft\OLE
Media-XP-Service-Pack3
msnzx.exe

HKLM\SOFTWARE\Microsoft\Ole
Media-XP-Service-Pack3
msnzx.exe

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

W32/Sdbot-ACW may modify the HOSTS file, changing the URL-to-IP mappings for selected websites, therefore preventing normal access to these sites. The new HOSTS file will typically contain the following:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 kaspersky-labs.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com
127.0.0.1 www.grisoft.com
127.0.0.1 http://www.virustotal.com
127.0.0.1 virusscan.jotti.org/
127.0.0.1 windowsupdate.microsoft.com/
1.3.3.7 www.bullguard.com/
127.0.0.1 www.techguy.org/
127.0.0.1 www.castlecops.com/
127.0.0.1 www.bleepingcomputer.com/
127.0.0.1 www.ozzu.com/
127.0.0.1 www.annoyances.org/
127.0.0.1 www.geekstogo.com/
127.0.0.1 www.designtechnica.com/
127.0.0.1 members.connectto.net/
127.0.0.1 www.spywareinfo.dk/
127.0.0.1 www.ccleaner.com/
127.0.0.1 www.spywareguide.com/
127.0.0.1 www.ewido.net/
127.0.0.1 www.webroot.com/
127.0.0.1 www.microsoft.com/spyware/
127.0.0.1 www.thespykiller.co.uk/
127.0.0.1 www.filehippo.com/
127.0.0.1 www.noidea.us/
127.0.0.1 forums.net-integration.net/

The following patches for the operating system vulnerabilities exploited by W32/Sdbot-ACW can be obtained from the Microsoft website:

MS04-011
MS04-012
MS03-049
MS04-045
MS02-039

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer