WORM_SDBOT.BEF

Malware type: Worm

Aliases: Backdoor.Win32.SdBot.gen (Kaspersky), W32/Sdbot.worm.gen.bw (McAfee), Backdoor.Sdbot (Symantec), TR/Crypt.ULPM.Gen (Avira), W32/Sdbot-Fam (Sophos), Backdoor:Win32/Sdbot (Microsoft)

In the wild: No

Destructive: Yes

Language: English

Platform: Windows 2000, Advanced 2000 Server, XP

Encrypted: No

Overall risk rating:

Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This worm generates IP addresses and spreads by attempting to drop a copy of itself in target addresses' default shares. If the said shares are password-protected, it uses gathered lists of user names and passwords as well as a hardcoded list of user names and passwords as its login credentials to gain access.

It connects to an Internet Relay Chat (IRC) server and joins a specific channel, where it listens for commands from a remote malicious user. The said commands are executed locally on affected machines.

It performs a distributed denial of service attack against target sites using different flood methods. It is capable of gathering CD keys of popular software products installed on affected machines.

For additional information about this threat, see:

Description created: Jun. 8, 2005 6:19:17 AM GMT -0800


TECHNICAL DETAILS


File type: PE

Memory resident:  Yes

Size of malware: 98, 816 Bytes

Initial samples received on: May 30, 2005

Details:

Installation and Autostart Techniques

Upon execution, this worm drops a copy of itself as MANAGER.EXE in the Windows system folder.

It has a keylogger function that logs keystrokes in an affected system and then drops the following files:

  • %Root%\b.bat � used to disable access to antivirus Web sites
  • %System%\keylog.txt � saved file of logged keystrokes

(Note: %Root% refers to the root folder, which is usually C:\. %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows 2000 or C:\Windows\System32 on Windows XP.)

It then creates the following autostart entries to ensure its automatic execution at every system startup:

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
Microsoft Syn Manager = "Manager.exe"

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\RunServices
Microsoft Syn Manager = "Manager.exe"

HKEY_CURRENT_USERS\Software\Microsoft\
Windows\CurrentVersion\Run
Microsoft Syn Manager = "Manager.exe"

As part of its stealth mechanism, it uses the ROOTKIT technology to be invisible to a user. It adds the service name GencTurk Rootkit and registers itself under the following registry key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\
Services\GencTurk Rootkit

It also hides the Windows system from Windows Explorer such that the user is unable to browse the folder.

Network Propagation

This worm generates IP addresses and spreads by attempting to drop a copy of itself in the following target addresses' default shares:

  • ADMIN$
  • C$
  • D$
  • IPC$

If the said shares are password-protected, it uses available lists of user names and passwords as well as the following list of hardcoded user names and passwords as its login credentials to gain access:

  • 00000
  • 000000
  • 00000000
  • 0wn3d
  • 0wned
  • 111111
  • 11111111
  • 121212
  • 123123
  • 12345
  • 123456
  • 1234567
  • 12345678
  • 123456789
  • 12346
  • 123467
  • 1234678
  • 12346789
  • 123467890
  • 1234qwer
  • 123abc
  • 123asd
  • 123qwe
  • 54321
  • 654321
  • 88888888
  • abc123
  • academia
  • academic
  • accept
  • ACCESS
  • access
  • account
  • accounting
  • accounts
  • action
  • ADMIN
  • admin
  • admin123
  • Administrator
  • ADMINISTRATOR
  • administrator
  • adrian
  • adrianna
  • adult
  • aerobics
  • airplane
  • alaska
  • albany
  • albatros
  • albatross
  • albert
  • alert
  • alexande
  • Alexander
  • algebra
  • aliases
  • alice
  • alicia
  • alisa
  • alison
  • allison
  • allow
  • alpha
  • alphabet
  • amadeus
  • amanda
  • amber
  • america
  • amorphou
  • amorphous
  • analog
  • anarchis
  • anarchy
  • anchor
  • andrea
  • android
  • andromac
  • andromache
  • angela
  • angerine
  • angie
  • animal
  • animals
  • anita
  • annette
  • anonymou
  • answer
  • anthrax
  • anthropo
  • anthropogenic
  • anvils
  • anything
  • apollo13
  • april
  • ariadne
  • arlene
  • arrow
  • arthur
  • artist
  • asian
  • asshole
  • athena
  • atmosphe
  • atmosphere
  • attack
  • authoriz
  • aztecs
  • azure
  • bacchus
  • backdoor
  • backup
  • BACKUP
  • badass
  • bailey
  • banana
  • bananas
  • bandit
  • banks
  • barbara
  • barber
  • baritone
  • bartman
  • baseball
  • basic
  • bassoon
  • batch
  • batman
  • beach
  • beammeup
  • beast
  • beater
  • beauty
  • beaver
  • becky
  • beethove
  • beethoven
  • begin
  • behead
  • beloved
  • beowulf
  • berkeley
  • berlin
  • berliner
  • beryl
  • betsie
  • betty
  • beverly
  • bible
  • bicamera
  • bicameral
  • bigfoot
  • billy
  • binary
  • bishop
  • bitch
  • bitmap
  • bitnet
  • black
  • blank
  • blonde
  • blondie
  • blood
  • bloodaxe
  • blowjob
  • blues
  • board
  • boner
  • boobs
  • boyscout
  • bradley
  • brandi
  • brandy
  • bravo
  • break
  • breast
  • brenda
  • brian
  • bridget
  • broadway
  • brothel
  • bruce
  • brunette
  • brute
  • brutefor
  • bulls
  • bullshit
  • bumbling
  • burgess
  • butch
  • butthead
  • californ
  • camille
  • campanil
  • campanile
  • camping
  • candi
  • candy
  • cantor
  • capitol
  • captain
  • capture
  • cardinal
  • caren
  • carla
  • carmen
  • carol
  • carole
  • carolina
  • caroline
  • carrie
  • carson
  • cascades
  • castle
  • catherin
  • catherine
  • catholic
  • cathy
  • cayuga
  • cecily
  • celtic
  • celtics
  • cerulean
  • change
  • changeme
  • Changeme
  • charity
  • charles
  • charlie
  • charming
  • charon
  • chemistr
  • chemistry
  • chess
  • chester
  • chris
  • christin
  • christina
  • christine
  • christy
  • cigar
  • cigarett
  • cindy
  • cisco
  • class
  • classes
  • classic
  • claudia
  • claymore
  • cleavage
  • clinton
  • cluster
  • clusters
  • coast
  • cocacola
  • cocainco
  • codename
  • codeword
  • coffee
  • collins
  • color
  • combat
  • comics
  • commit
  • commrade
  • commrades
  • company
  • compaq
  • computer
  • computin
  • comrade
  • comrades
  • condo
  • condom
  • connect
  • connie
  • conserva
  • console
  • continue
  • control
  • cookbook
  • cookie
  • cooper
  • copper
  • corneliu
  • cornelius
  • correct
  • counters
  • country
  • couscous
  • cowboy
  • crack
  • crackpot
  • crash
  • cream
  • create
  • creation
  • creature
  • credit
  • creosote
  • cretin
  • crime
  • criminal
  • cristina
  • crystal
  • cshrc
  • customer
  • cyber
  • cyberpun
  • cyberspa
  • cynthia
  • daemon
  • daisy
  • dancer
  • daniel
  • danielle
  • danny
  • dapper
  • darkaven
  • database
  • databasepass
  • databasepassword
  • db1234
  • dbpass
  • dbpassword
  • death
  • deathsta
  • debbie
  • deborah
  • debug
  • december
  • DEFAULT
  • default
  • defoe
  • delta
  • deluge
  • democrat
  • denise
  • dennis
  • desiree
  • desktop
  • desperat
  • desperate
  • develop
  • device
  • devil
  • diamond
  • diana
  • diane
  • diehard
  • dieter
  • digital
  • dinosaur
  • dipshit
  • direct
  • director
  • dirty
  • discipli
  • disclose
  • discover
  • discovery
  • diskette
  • disney
  • display
  • doctor
  • dollar
  • domain
  • domainpass
  • domainpassword
  • donaldduck
  • doom2
  • doomii
  • doomsday
  • doonesbu
  • doors
  • download
  • dragon
  • drdoom
  • drive
  • drought
  • dudette
  • duelist
  • dulce
  • duncan
  • dungeon
  • eager
  • eagle
  • earth
  • easier
  • eatme
  • eddie
  • edges
  • edinburg
  • edinburgh
  • edition
  • educatio
  • education
  • edwin
  • edwina
  • egghead
  • eiderdow
  • eiderdown
  • eileen
  • einsiein
  • einstein
  • elaine
  • elanor
  • electron
  • elephant
  • elizabet
  • elizabeth
  • ellen
  • email
  • emerald
  • emily
  • emmanuel
  • enable
  • enemy
  • engine
  • engineer
  • england
  • english
  • enter
  • enterpri
  • enterprise
  • enzyme
  • erenity
  • erica
  • erika
  • erotic
  • ersatz
  • establis
  • establish
  • estate
  • eternity
  • euclid
  • evelyn
  • exchange
  • exchnge
  • expert
  • explode
  • explore
  • explorer
  • explosiv
  • extensio
  • extension
  • fairway
  • faith
  • falcon
  • false
  • family
  • farad
  • faraday
  • felicia
  • fender
  • fermat
  • ferrari
  • fidelity
  • field
  • fight
  • FILES
  • finite
  • firewall
  • fishers
  • flakes
  • float
  • florida
  • flower
  • flowers
  • foobar
  • foolproo
  • foolproof
  • football
  • force
  • foresigh
  • foresight
  • forever
  • format
  • fornicat
  • forsythe
  • fourier
  • foxtrot
  • france
  • frank
  • freak
  • freddy
  • freedom
  • french
  • friday
  • friend
  • friends
  • frighten
  • fryguy
  • fubar
  • fucked
  • fucker
  • fucking
  • fuckme
  • fuckyou
  • fudge
  • function
  • fungible
  • gabriel
  • games
  • gardner
  • garfield
  • gateway
  • gatherin
  • gauss
  • george
  • gertrude
  • ghost
  • gibson
  • gigabyte
  • ginger
  • glacier
  • godblessyou
  • golden
  • golfer
  • gorgeous
  • gorges
  • gosling
  • gouge
  • govermen
  • grades
  • graham
  • grahm
  • grand
  • grant
  • great
  • green
  • group
  • gryphon
  • guardian
  • gucci
  • guess
  • guessme
  • guest
  • GUEST
  • guitar
  • gumption
  • guntis
  • h4x0r1ng
  • h4x0ring
  • h4x1ng
  • hacked
  • hacker
  • hagar
  • hallowee
  • hamlet
  • hamster
  • handel
  • handily
  • handjob
  • happenin
  • happening
  • hardcore
  • harddriv
  • harmony
  • harold
  • harvey
  • haven
  • hawaii
  • hax0r
  • haxing
  • headbang
  • headoffice
  • heathen
  • heather
  • heaven
  • hebrides
  • heidi
  • heinlein
  • hello
  • herbert
  • heroin
  • hewlett
  • hexadeci
  • hiawatha
  • hibernia
  • hidden
  • highland
  • hitler
  • holly
  • hollywoo
  • homepage
  • homer
  • homeuser
  • homework
  • honey
  • hooker
  • hooters
  • horny
  • horrible
  • horror
  • horse
  • horus
  • hotdog
  • hotel
  • hunter
  • hutchins
  • hydrogen
  • hyper
  • hypertxt
  • icecream
  • ihavenopass
  • illumina
  • image
  • imbrogli
  • imbroglio
  • immortal
  • imperial
  • include
  • india
  • indian
  • indiana
  • indians
  • ingres
  • ingress
  • ingrid
  • innocuou
  • innocuous
  • input
  • inside
  • integer
  • Internet
  • internet
  • intranet
  • invent
  • irene
  • irishman
  • irule
  • jackie
  • janet
  • janice
  • janie
  • japan
  • jasmin
  • jeanne
  • jenni
  • jennifer
  • jenny
  • jerry
  • jerusale
  • jessica
  • jester
  • jewelry
  • jixian
  • joanne
  • johndoe
  • johnny
  • joseph
  • joshua
  • journal
  • joyce
  • judith
  • juggle
  • juicy
  • julia
  • julie
  • juliet
  • jupiter
  • karen
  • karie
  • karina
  • katana
  • kathleen
  • kathrine
  • kathy
  • katie
  • katina
  • katrina
  • kelly
  • kermit
  • kernel
  • kerri
  • kerrie
  • kerry
  • kevin
  • keybord
  • keyin
  • keyword
  • kiddie
  • killer
  • killthem
  • kimberly
  • kirkland
  • kissmyas
  • kitten
  • klingon
  • knife
  • knight
  • knightma
  • known
  • krista
  • kristen
  • kristi
  • kristie
  • kristin
  • kristine
  • kristy
  • ladeda
  • ladies
  • ladle
  • lakers
  • lambda
  • laminati
  • lamination
  • laptop
  • larkin
  • larry
  • laser
  • laura
  • lazarus
  • lazer
  • lebesgue
  • leftwing
  • legal
  • leland
  • leroy
  • lesbian
  • leslie
  • letmein
  • lewis
  • lexluthe
  • liberal
  • library
  • licker
  • light
  • lightsab
  • limbaugh
  • limited
  • linda
  • linux
  • literatu
  • LOCAL
  • lockout
  • lockword
  • logic
  • login
  • loginpass
  • loginwor
  • lolopc
  • loose
  • lorin
  • lorraine
  • loser
  • louis
  • lovebug
  • lover
  • lucus
  • lynne
  • machine
  • macintos
  • macintosh
  • macro
  • maggot
  • magic
  • magnet
  • maint
  • malcolm
  • malcom
  • manager
  • marci
  • marcy
  • maria
  • mariens
  • marietta
  • marijuan
  • marines
  • markus
  • marni
  • marriage
  • marty
  • marvin
  • mason
  • master
  • Matthew
  • maurice
  • meagan
  • megabyte
  • megadeth
  • megan
  • melissa
  • mellon
  • melrose
  • member
  • memory
  • menace
  • mercury
  • merlin
  • metal
  • metalhea
  • metalica
  • michael
  • michel
  • michelan
  • michele
  • michelle
  • mickey
  • micro
  • microchi
  • micropro
  • microsof
  • midieval
  • minimum
  • minsky
  • misfit
  • mission
  • modem
  • mogul
  • moguls
  • monday
  • monica
  • moose
  • morley
  • morris
  • mortal
  • mortalco
  • mortgage
  • mosaic
  • mountain
  • mouse
  • movie
  • movies
  • mozart
  • msdos
  • muppets
  • mutant
  • mypass
  • mypass123
  • mypc123
  • nagel
  • nancy
  • napoleon
  • nepenthe
  • neptune
  • net-devil
  • netdevil
  • netfuck
  • netscape
  • network
  • newborn
  • newsgrou
  • newton
  • newyork
  • nicole
  • nicotine
  • night
  • nightmar
  • Nilez
  • nintendo
  • nnaacp
  • noble
  • nobody
  • nokia
  • noreen
  • notes
  • novel
  • november
  • noxious
  • nuclear
  • nukem
  • number
  • nutritio
  • nutrition
  • nyquist
  • obscurit
  • oceanogr
  • oceanography
  • ocelot
  • oeminstall
  • oemuser
  • office
  • oldage
  • olivetti
  • olivia
  • omega
  • opening
  • openlock
  • opensesa
  • operator
  • oracle
  • orange
  • orient
  • orwell
  • oscar
  • osiris
  • outdoors
  • outlaw
  • outlook
  • output
  • outside
  • owned
  • Owner
  • OWNER
  • oxford
  • pacific
  • packard
  • packer
  • painless
  • paint
  • pakistan
  • pamela
  • paper
  • papers
  • pascal
  • passphra
  • PASSWORD
  • paste
  • patricia
  • patrick
  • patriot
  • patty
  • paula
  • peanuts
  • pecker
  • pencil
  • penelope
  • penguin
  • penis
  • penname
  • pentagon
  • pentagra
  • penthous
  • pentium
  • peoria
  • pepper
  • pepsi
  • percolat
  • percolate
  • perfect
  • permit
  • persimmo
  • persimmon
  • persona
  • pervert
  • peter
  • philip
  • phoenix
  • phone
  • photon
  • phrack
  • phrase
  • phreak
  • phuck
  • pierre
  • pinname
  • pizza
  • plane
  • playboy
  • plover
  • pluto
  • plymouth
  • poetry
  • police
  • polly
  • polynomi
  • polynomial
  • ponderin
  • pondering
  • porno
  • porsche
  • poster
  • power
  • praise
  • precious
  • prelude
  • presto
  • prince
  • princeto
  • princeton
  • printer
  • private
  • privs
  • proceed
  • processo
  • professo
  • professor
  • profile
  • program
  • prompt
  • protect
  • protozoa
  • psycho
  • psychopa
  • public
  • pumpkin
  • puneet
  • punisher
  • puppet
  • pussy
  • pw123
  • quebec
  • qwert
  • qwerty
  • rabbit
  • rachel
  • rachelle
  • rachmani
  • rachmaninoff
  • rainbow
  • raindrop
  • raleigh
  • random
  • rascal
  • razor
  • reagan
  • reality
  • really
  • reaper
  • rebal
  • rebecca
  • rebel
  • record
  • reddawn
  • redhead
  • referenc
  • regional
  • release
  • remote
  • renee
  • report
  • republic
  • resistan
  • reveal
  • rhino
  • riffraff
  • right
  • rightwin
  • ripple
  • roach
  • robert
  • robin
  • robot
  • robotics
  • robyn
  • rochelle
  • rocheste
  • rochester
  • rocky
  • rockyhor
  • rodent
  • rolex
  • romano
  • romeo
  • romulan
  • ronald
  • Rosco
  • RoscoP
  • RoscoPColtrane
  • rosebud
  • rosemary
  • roses
  • rough
  • rubber
  • ruben
  • rules
  • running
  • salami
  • samantha
  • sample
  • sandra
  • sandy
  • sarah
  • satan
  • satanic
  • satanik
  • saturday
  • saturn
  • saxon
  • scamper
  • scheme
  • school
  • schoolsucks
  • scifi
  • scorpion
  • scott
  • scotty
  • scout
  • script
  • scriptkiddie
  • search
  • secret
  • security
  • sensor
  • sentinel
  • sentry
  • serenity
  • serial
  • server
  • SERVER
  • service
  • sesame
  • shannon
  • sharc
  • SHARE
  • shark
  • sharks
  • sharon
  • sheffiel
  • sheffield
  • sheldon
  • shell
  • sherri
  • shift
  • shirley
  • shitpot
  • shiva
  • shivers
  • short
  • shuttle
  • siemens
  • sierra
  • signatur
  • signature
  • silver
  • simcity
  • simon
  • simple
  • simpsons
  • simulati
  • singer
  • single
  • skull
  • slave
  • slick
  • sliders
  • small
  • smart
  • smile
  • smiles
  • smooch
  • smother
  • snach
  • snafu
  • snake
  • snatch
  • snoopy
  • social
  • socrates
  • sodomy
  • software
  • somebody
  • sondra
  • sonia
  • sonic
  • sonya
  • sossina
  • source
  • south
  • spaceman
  • spaceshi
  • sparrows
  • spear
  • spell
  • spencer
  • spice
  • spider
  • spiderma
  • spred
  • spring
  • springer
  • spunk
  • sqlpass
  • squires
  • stacey
  • staci
  • stacie
  • stacy
  • staff
  • starship
  • start
  • startrek
  • startup
  • starwars
  • steak
  • steal
  • steel
  • steph
  • stephani
  • stephanie
  • stereo
  • steve
  • stoneage
  • stoned
  • stones
  • strange
  • strangle
  • stratfor
  • stratford
  • streetfi
  • string
  • strip
  • student
  • student1
  • stuttgar
  • stuttgart
  • subscrib
  • subway
  • success
  • suckmydi
  • sucks
  • summer
  • sunday
  • super
  • superman
  • superson
  • supersta
  • superstage
  • superuse
  • superuser
  • supervis
  • support
  • supporte
  • supported
  • surfer
  • surfing
  • susan
  • susanne
  • susie
  • suzanne
  • suzie
  • swearer
  • sweat
  • switch
  • sword
  • sybase
  • sybil
  • symmetry
  • sysadmin
  • sysop
  • SYSTEM
  • system
  • tabasco
  • tamara
  • tamie
  • tammy
  • tangerin
  • tangerine
  • tango
  • target
  • tarragon
  • taylor
  • teacher
  • teapot
  • tears
  • technical
  • teenage
  • telephon
  • telephone
  • telnet
  • temp123
  • temptati
  • temptation
  • tennis
  • terminal
  • terminat
  • test123
  • tester
  • testin
  • testing
  • tetris
  • thailand
  • theresa
  • thursday
  • tiffany
  • tiger
  • toggle
  • token
  • tokenrin
  • tomato
  • topograp
  • topography
  • tortoise
  • toxic
  • toyota
  • traci
  • tracie
  • tracy
  • trails
  • transfer
  • trapdoor
  • trisha
  • trivial
  • trojan
  • trombone
  • truth
  • tubas
  • tuesday
  • turnip
  • tuttle
  • umesh
  • uncle
  • unhappy
  • unicorn
  • uniform
  • universa
  • universe
  • universi
  • unknown
  • unlock
  • upload
  • uranus
  • urchin
  • ursula
  • usenet
  • user1
  • usermane
  • username
  • userpassword
  • utility
  • uwontguessme
  • vagina
  • valerie
  • vampire
  • vasant
  • venus
  • veronica
  • vertigo
  • vicky
  • victor
  • video
  • videogam
  • village
  • virgin
  • virginia
  • virus
  • visitor
  • visual
  • visualba
  • vodka
  • warez
  • warfare
  • wargames
  • warren
  • watchwor
  • water
  • webpage
  • wednesda
  • weenie
  • wendi
  • wendy
  • werewolf
  • western
  • wh0r3
  • wh0re
  • whatever
  • whatnot
  • whisky
  • white
  • whiting
  • whitney
  • wholesal
  • wholesale
  • whore
  • wileecoyote
  • william
  • williams
  • williamsburg
  • willie
  • wilma
  • win2000
  • win2k
  • win98
  • windose
  • windows
  • windows2k
  • windows95
  • windows98
  • windowsME
  • WindowsXP
  • windowz
  • windoze
  • windoze2k
  • windoze95
  • windoze98
  • windozeME
  • windozexp
  • winnt
  • winpass
  • winston
  • winxp
  • wired
  • wisconsi
  • wisconsin
  • wiseass
  • within
  • wizard
  • wolverin
  • woman
  • wombat
  • women
  • woodwind
  • wordperf
  • wormwood
  • WRITE
  • wyoming
  • xmodem
  • xxxxx
  • xxxxxx
  • xxxxxxx
  • xxxxxxxx
  • xxxxxxxxx
  • xyzzy
  • yankee
  • yellow
  • yellowst
  • yellowstone
  • yolanda
  • yosemite
  • young
  • youwontguessme
  • zebra
  • zeitgeis
  • ziggy
  • zimmerma
  • zimmerman
  • zmodem
  • zombie

Backdoor Capabilities

This worm connects to an Internet Relay Chat (IRC) server and joins a specific channel, where it listens for commands from a remote malicious user. It can also be used to launch a Denial of Service attack against specified target sites.

HOSTS File Modification

This worm also modifies the system's HOSTS, which contains host name to IP address mappings. It is usually located in the following folders:

  • %System%\drivers\etc
  • %Windows%

(Note: %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows 2000 and C:\Windows\System32 on Windows XP. %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)

The said routine is done so that the following sites, which are usually related to antivirus companies, can no longer be accessed by affected users:

  • avp.com
  • ca.com
  • customer.symantec.com
  • dispatch.mcafee.com
  • download.mcafee.com
  • downloads-us1.kaspersky-labs.com
  • downloads1.kaspersky-labs.com
  • downloads2.kaspersky-labs.com
  • downloads3.kaspersky-labs.com
  • f-secure.com
  • ftp.downloads1.kaspersky-labs.com
  • ftp.downloads2.kaspersky-labs.com
  • ftp.downloads3.kaspersky-labs.com
  • kaspersky-labs.com
  • kaspersky.com
  • liveupdate.symantec.com
  • liveupdate.symantecliveupdate.com
  • mast.mcafee.com
  • mcafee.com
  • my-etrust.com
  • nai.com
  • networkassociates.com
  • rads.mcafee.com
  • secure.nai.com
  • securityresponse.symantec.com
  • sophos.com
  • symantec.com
  • trendmicro.com
  • update.symantec.com
  • updates.symantec.com
  • updates1.kaspersky-labs.com
  • updates2.kaspersky-labs.com
  • updates3.kaspersky-labs.com
  • us.mcafee.com
  • viruslist.com
  • virustotal.com
  • www.avp.com
  • www.ca.com
  • www.f-secure.com
  • www.grisoft.com
  • www.kaspersky.com
  • www.mcafee.com
  • www.my-etrust.com
  • www.nai.com
  • www.networkassociates.com
  • www.sophos.com
  • www.symantec.com
  • www.trendmicro.com
  • www.viruslist.com
  • www.virustotal.com

Information Theft

This worm is capable of gathering CD keys of the following popular game applications:

  • Battlefield 1942
  • Battlefield 1942 The Road to Rome
  • Command & Conquer Generals CDKey
  • Counter-Strike ( Retail )
  • FIFA 2003 CDKey
  • Half-Life CDKey
  • Need For Speed Hot Pursuit 2
  • Neverwinter
  • Project IGI 2
  • Rainbow Six III RavenShield CDKey
  • RAVENSHIELD
  • Soldier of Fortune II - Double Helix
  • Unreal Tournament 2003

Analysis By: Hazel Mariscal


SOLUTION


Minimum scan engine version needed: 6.810

Pattern file needed: 2.650.01

Pattern release date: May 30, 2005


Important note: The "Minimum scan engine" refers to the earliest Trend Micro scan engine version guaranteed to detect this threat. However, Trend Micro strongly recommends that you update to the latest version in order to get comprehensive protection. Download the latest scan engine here.

Solution:

Identifying the Malware Program

To remove this malware, first identify the malware program.

  1. Scan your system with your Trend Micro antivirus product.
  2. NOTE all files detected as WORM_SDBOT.BEF.

Trend Micro customers need to download the latest pattern file before scanning their system. Other users can use Housecall, Trend Micro's online virus scanner.

Disabling Malware Service

This procedure terminates the running malware service on systems running Windows NT-based operating systems.

  1. Open a comand prompt window.
    Click Start>Run, type:
    CMD, then press Enter
  2. At the command prompt window, type:
    NET STOP "GencTurk Rootkit"
  3. Press Enter. A mesage should appear indicating that the service has been successfully terminated.
  4. Close the command prompt window.

Editing the Registry

This malware modifies the system's registry. Users affected by this malware may need to modify or delete specific registry keys or entries. For detailed information regarding registry editing, please refer to the following articles from Microsoft:

  1. HOW TO: Back Up, Edit, and Restore the Registry in Windows XP
  2. HOW TO: Backup, Edit, and Restore the Registry in Windows 2000

Removing Autostart Entries from the Registry

Removing autostart entries from the registry prevents the malware from executing at startup.

If the registry entries below are not found, the malware may not have executed as of detection. If so, proceed to the succeeding solution set.

  1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
  2. In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>Software>Microsoft>
    Windows>CurrentVersion>Run
  3. In the right panel, locate and delete the entry:
    Microsoft Syn Manager = "Manager.exe"
  4. In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>Software>Microsoft>
    Windows>CurrentVersion>RunServices
  5. In the right panel, locate and delete the entry:
    Microsoft Syn Manager = "Manager.exe"
  6. In the left panel, double-click the following:
    HKEY_CURRENT_USER>Software>Microsoft>
    Windows>CurrentVersion>Run
  7. In the right panel, locate and delete the entry:
    Microsoft Syn Manager = "Manager.exe"
  8. In the left panel, locate and delete the following key:
    HKEY_LOCAL_MACHINE>System>CurrentControlSet>
    Services>GencTurk Rootkit
  9. Close Registry Editor.

Removing Malware Entries from the HOSTS File

Deleting malware entries from the HOSTS file removes all malware-made changes on host name association.

  1. Open the following file using a text editor (such as NOTEPAD):
    %System%\drivers\etc\HOSTS
    %Windows%
    (Note: %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT. %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows 2000 and C:\Windows\System32 on Windows XP.)
  2. Delete the following entries:
    • 127.0.0.1 avp.com
    • 127.0.0.1 ca.com
    • 127.0.0.1 customer.symantec.com
    • 127.0.0.1 dispatch.mcafee.com
    • 127.0.0.1 download.mcafee.com
    • 127.0.0.1 downloads-us1.kaspersky-labs.com
    • 127.0.0.1 downloads1.kaspersky-labs.com
    • 127.0.0.1 downloads2.kaspersky-labs.com
    • 127.0.0.1 downloads3.kaspersky-labs.com
    • 127.0.0.1 f-secure.com
    • 127.0.0.1 ftp.downloads1.kaspersky-labs.com
    • 127.0.0.1 ftp.downloads2.kaspersky-labs.com
    • 127.0.0.1 ftp.downloads3.kaspersky-labs.com
    • 127.0.0.1 kaspersky-labs.com
    • 127.0.0.1 kaspersky.com
    • 127.0.0.1 liveupdate.symantec.com
    • 127.0.0.1 liveupdate.symantecliveupdate.com
    • 127.0.0.1 mast.mcafee.com
    • 127.0.0.1 mcafee.com
    • 127.0.0.1 my-etrust.com
    • 127.0.0.1 nai.com
    • 127.0.0.1 networkassociates.com
    • 127.0.0.1 rads.mcafee.com
    • 127.0.0.1 secure.nai.com
    • 127.0.0.1 securityresponse.symantec.com
    • 127.0.0.1 sophos.com
    • 127.0.0.1 symantec.com
    • 127.0.0.1 trendmicro.com
    • 127.0.0.1 update.symantec.com
    • 127.0.0.1 updates.symantec.com
    • 127.0.0.1 updates1.kaspersky-labs.com
    • 127.0.0.1 updates2.kaspersky-labs.com
    • 127.0.0.1 updates3.kaspersky-labs.com
    • 127.0.0.1 us.mcafee.com
    • 127.0.0.1 viruslist.com
    • 127.0.0.1 virustotal.com
    • 127.0.0.1 www.avp.com
    • 127.0.0.1 www.ca.com
    • 127.0.0.1 www.f-secure.com
    • 127.0.0.1 www.grisoft.com
    • 127.0.0.1 www.kaspersky.com
    • 127.0.0.1 www.mcafee.com
    • 127.0.0.1 www.my-etrust.com
    • 127.0.0.1 www.nai.com
    • 127.0.0.1 www.networkassociates.com
    • 127.0.0.1 www.sophos.com
    • 127.0.0.1 www.symantec.com
    • 127.0.0.1 www.trendmicro.com
    • 127.0.0.1 www.viruslist.com
    • 127.0.0.1 www.virustotal.com
  3. Save the file and close the text editor.

Additional Windows XP Cleaning Instructions

Users running Windows XP must disable System Restore to allow full scanning of infected systems.

Users running other Windows versions can proceed with the succeeding procedure set(s).

Running Trend Micro Antivirus

Scan your system with Trend Micro antivirus and delete files detected as WORM_SDBOT.BEF. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other Internet users can use HouseCall, Trend Micro's online virus scanner.




Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network, small and medium business, mobile device or home PC.