MSN Christmas photo (BACKDOOR.WIN32.PBOT.A) Virus analysis Solution _ virus killing

Source: Internet
Author: User
Tags win32 zip
File name: Devic.exe

File Size: 23304 bytes

AV name: (virustotal only card bar a home newspaper) Backdoor.Win32.SdBot.cok

Adding shell mode: Unknown

Writing language: VC

Virus type: IRCBot

File md5:45de608d74ee4fb86b20da86dcbeb55c

Behavioral Analysis:

1. Release virus copy:

C:\WINDOWS\devic.exe, 23304 bytes.
C:\WINDOWS\img5-2007.zip, 23456 bytes.

2, add the registry, boot:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


(registry value) Systemdevic = "Devic.exe"

3, every 5 seconds to explore the network and connect the Korean IRC server: irc.pNet.com, with random name and null password user login.

4. The following commands may be accepted:

Pb.main->
Pb.irc->
Pb.thread->
Pb.wget->
Pb.update->
Pb.spam-msn->
Pb.botkiller->
Pb.pstore->
Pb.visit->
Pb.ddos->

5, to MSN Friends to send virus compression package and the following random one:

qu?usted piensa de este cuadro?
Consegu?a Nuevo cuadro de m?la toma una
Algunos cuadros de la semana pasada, Consideran si usted tiene-gusto en ellos.
Tiene usted visto este picure todav
Haha, es que usted?
Debo utilizar este cuadro en msn?
qu?usted piensa en esto?
Was Denken Sie an diese?
Was Denken Sie a dieses Picure? Ich glaube, Da?ich h
Lich Schaue:/
Sind hier eine neue Abbildung von Mir
Einige Abbildungen von der letzten Woche, sehen, wenn Sie Sie m
Haha, diese sind Sie auf dieser?
Sollte ich diese Abbildung auf msn Benutzen?
Was Denken Sie an dieses?
Wat denkt u aan dit picure? Ik vind ik lelijk kijk
Een paar beelden van Vorige Week, zien of Houdt u hier van em nieuwe pic van me. :)
Hebt u dit picure nog gezien?:p
Hebt u dit picure nog gezien? :p
Haha, Bent u dat op dat beeld? :)
Zou ik dit beeld op msn moeten gebruiken?
Wat denkt u over dit?
Que pensez-vous ce picure? Je me sens que je semble laid:/
Voici un nouveau pic de moi
Quelques images de la semaine derni
E, voient si vous les aimez
avez-vous vu ce picure encore?
Haha, est-vous ce sur cette image?
Si J ' emploient cette image sur le msn?
Que pensez-vous? mon image?
:(:(:(:(
Here ' s a new pic of me
A few pictures from last week, and if you are like em
:D:D: D::D
Have you seen this picure yet?
Haha, is and that?
Should I use this picture on MSN?
What Do you are about this?

In addition to that img5-2007.zip, the virus inside may be named:

Www.photo5-2007-12.JPEG.com
Img3-2007-12. Jpeg.com
Img2-2007-12. JPEG_www.images.com
Img-2007-12. Jpeg.scr

are executable programs, hehe.

Workaround:

1, start-run-regedit.

2, expand to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Delete this item: Systemdevic.

3, restart the computer.

4, delete hard disk files:

C:\WINDOWS\devic.exe

C:\WINDOWS\img5-2007.zip

In addition there are other MSN worm variants, which cannot be removed by the above methods

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.