Virus introduction:
Virus name: mdesvc.exe \ backdoor. win32.ircbot
Chinese alias: MSN Worm
File length: 10752 bytes
File MD5: 633fc2332287108885ba0633efd81601
Dependency platform: Win 9x/ME/NT/2 k/XP/2K3
Virus analysis:
1. Release virus copies:
% SystemRoot % \ system32 \ mdesvc.exe 10752 bytes
2. Add the registry and start it after it is started:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
Registry Value: Logical Disk detection = REG_SZ, "mdesvc.exe"
3. Connect 80.93.214. ** to the IRC server and accept remote control.
4. computers infected with viruses can respond to the following IRC commands:
Code:
Part
Join
Quit: removing
Quit: Reconnecting
Pong
Sync
............
5. In addition, the MSN worm variant can be transmitted by Yahoo Messenger (Yahoo Messenger.
6. They will find friends on MSN and may send virus packets and some words.
7. After all the viruses are released, CMD will be called to delete itself.
Solution:
1. Download: Sreng
2. Open Sreng and delete (for example ):
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
Registry Value: Logical Disk detection = REG_SZ, "mdesvc.exe"
3. Restart your computer and delete it:
% SystemRoot % \ system32 \ mdesvc.exe 10752 bytes
Virus fixing