SdBot represents the large family of backdoors - hacker's remote
access tools. These tools allow to contol victims' computers
remotely by sending specific commands via IRC channels. Also
these backdoors can steal data, spread to local network and to
computers vulnerable to exploits.
F-Secure provides the special disinfection utility to eliminate
SdBot.vc worm infection. You can download this utility from our
ftp site:
ftp://ftp.f-secure.com/anti-virus/tools/f-bot.exe
ftp://ftp.f-secure.com/anti-virus/tools/f-bot.zip
Disinfection instructions can be found here:
ftp://ftp.f-secure.com/anti-virus/tools/f-bot.txt
System administrators who are using F-Secure Policy Manager,
can distribute the tool as a JAR package automatically to all
workstations.
System administrators can download the JAR version from:
http://www.europe.f-secure.com/tools/f-bot.jar
ftp://ftp.f-secure.com/anti-virus/tools/f-bot.jar
F-Secure Anti-Virus starting from version 5.40 can disinfect a
computer infected with SdBot.vc automatically by renaming the
backdoor's file. A computer has to be restarted to complete
disinfection.
Manual disinfection for SdBot.vc backdoor requires renaming of an
infected file named WUPDATED.EXE located in Windows System folder
and restarting a system.
If the infection is in a local network, please follow the
instructions on this webpage:
http://www.f-secure.com/v-descs/netdisinf.shtml
The backdoor's file is a PE executable about 71 kilobytes long,
packed with Exe32Pack file compressor. The backdoor contains the
PSEXEC utility in its body.
When the backdoor's file is started, it copies itself as
WUPDATED.EXE file to Windows System folder and then creates the
following startup key value in the Registry:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Configuration Loaded"="WUPDATED.EXE"
The backdoor can also create the following key value:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Configuration Loaded"="WUPDATED.EXE"
When the backdoor is active, it connects to an IRC server (on
port 6667), joins a certain channel and acts as a bot there. The
backdoor starts IDENTD server on port 113.
The backdoor tries to contact the following IRC servers:
irc.undernet.org
kan3.de
The backdoor joins the following password-protected IRC channels:
#maerchenland
#kellyfamily
Here's how the code of the backdoor looks in disassembler's
window:
A hacker can send commands to the bots to control infected
computers. A hacker can do any of the following:
* perform ping, SYN, ICMP and UDP flood
* get system information including information about OS, network and drives
* update the backdoor's file from Internet
* operate backdoor's bot (nick change, join/part channels, etc.)
* redirect traffic on certain ports
* open a URL with default web browser
* steal CD keys from popular games
* spread to computers via LAN (performs dictionary attack on share passwords)
* join and spy on certain IRC channels
* start remote processes using PSEXEC.EXE utility (extracted from the backdoor)
* download and execute files
SdBot.vc steals CD keys for the following games if they are
installed on an infected computer:
Half-Life
Unreal Tournament 2003
Counter-Strike (Retail)
Project IGI 2
Battlefield 1942
Battlefield 1942 Road To Rome
Rainbow Six III RavenShield
Neverwinter Knights
Soldier of Fortune 2
The Gladiators
Need for Speed Hot Persuit 2
FIFA 2003
Command & Conquer Generals
Red Alert 2
Tiberian Sun
F-Secure Anti-Virus detects SdBot.vc with the following update:
[FSAV_Database_Version]
Version=2005-02-09_02
Technical Details:
Alexey Podrezov, May 25th, 2005;
Description Updated:
Alexey Podrezov, November 17th, 2005;
F-Secure Corporation