F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : SdBot.vc

[Summary] | [Disinfection] | [Detailed Description] | [Detection]



NAME:SdBot.vc
ALIAS:Backdoor.Win32.SdBot.vc, SDBot
SIZE:71047

Summary

SdBot represents the large family of backdoors - hacker's remote access tools. These tools allow to contol victims' computers remotely by sending specific commands via IRC channels. Also these backdoors can steal data, spread to local network and to computers vulnerable to exploits.

Disinfection

F-Secure provides the special disinfection utility to eliminate SdBot.vc worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-bot.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-bot.zip

Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-bot.txt

System administrators who are using F-Secure Policy Manager, can distribute the tool as a JAR package automatically to all workstations.

System administrators can download the JAR version from:

http://www.europe.f-secure.com/tools/f-bot.jar

ftp://ftp.f-secure.com/anti-virus/tools/f-bot.jar

F-Secure Anti-Virus starting from version 5.40 can disinfect a computer infected with SdBot.vc automatically by renaming the backdoor's file. A computer has to be restarted to complete disinfection.

Manual disinfection for SdBot.vc backdoor requires renaming of an infected file named WUPDATED.EXE located in Windows System folder and restarting a system.

If the infection is in a local network, please follow the instructions on this webpage:

http://www.f-secure.com/v-descs/netdisinf.shtml

Back to the Top


Detailed Description

The backdoor's file is a PE executable about 71 kilobytes long, packed with Exe32Pack file compressor. The backdoor contains the PSEXEC utility in its body.

When the backdoor's file is started, it copies itself as WUPDATED.EXE file to Windows System folder and then creates the following startup key value in the Registry:

 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "Configuration Loaded"="WUPDATED.EXE"

The backdoor can also create the following key value:

 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
 "Configuration Loaded"="WUPDATED.EXE"

When the backdoor is active, it connects to an IRC server (on port 6667), joins a certain channel and acts as a bot there. The backdoor starts IDENTD server on port 113.

The backdoor tries to contact the following IRC servers:

 irc.undernet.org
 kan3.de

The backdoor joins the following password-protected IRC channels:

 #maerchenland
 #kellyfamily

Here's how the code of the backdoor looks in disassembler's window:

A hacker can send commands to the bots to control infected computers. A hacker can do any of the following:

 * perform ping, SYN, ICMP and UDP flood
 * get system information including information about OS, network and drives
 * update the backdoor's file from Internet
 * operate backdoor's bot (nick change, join/part channels, etc.)
 * redirect traffic on certain ports
 * open a URL with default web browser
 * steal CD keys from popular games
 * spread to computers via LAN (performs dictionary attack on share passwords)
 * join and spy on certain IRC channels
 * start remote processes using PSEXEC.EXE utility (extracted from the backdoor)
 * download and execute files

SdBot.vc steals CD keys for the following games if they are installed on an infected computer:

 Half-Life
 Unreal Tournament 2003
 Counter-Strike (Retail)
 Project IGI 2
 Battlefield 1942
 Battlefield 1942 Road To Rome
 Rainbow Six III RavenShield
 Neverwinter Knights
 Soldier of Fortune 2
 The Gladiators
 Need for Speed Hot Persuit 2
 FIFA 2003
 Command & Conquer Generals
 Red Alert 2
 Tiberian Sun


Back to the Top


Detection

F-Secure Anti-Virus detects SdBot.vc with the following update:

[FSAV_Database_Version]

Version=2005-02-09_02

Back to the Top


Technical Details: Alexey Podrezov, May 25th, 2005;

Description Updated: Alexey Podrezov, November 17th, 2005;

F-Secure Corporation