MSN Christmas photo (Backdoor. Win32.PBot. a) virus Analysis Solution

Source: Internet
Author: User

File Name: devic.exe

File Size: 23304 bytes

AV name: (only one report is displayed on virustotal) Backdoor. Win32.SdBot. cok

Shelling method: Unknown

Programming Language: VC

Virus Type: IRCbot

File MD5: 45de608d74ee4fb86b20da86dcbeb55c

Behavior Analysis:

1. Release virus copies:

C: \ WINDOWS \ devic.exe, 23304 bytes
C: \ WINDOWS \ img5-2007.zip, 23456 bytes

2. Add the registry and start it after it is started:

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run

(Registry value) SystemDevic = "devic.exe"

3. Test the network and connect to the IRC server irc.pNet.com every five seconds. log on with a random name and a blank password.

4. The following command may be accepted:

PB. Main->
PB. irc->
PB. Thread->
PB. wget->
PB. update->
PB. Spam-MSN->
PB. Botkiller->
PB. pStore->
PB. Visit->
PB. DDos->

5. Send a virus package to an MSN friend and one of the following random packages:

Qu? Usted piensa de este cuadro?
Consegu? A nuevo cuadro de m? La toma una mirada
Algunos cuadros de la semana pasada, consideran si usted tiene gusto en ellos.
Tiene usted visto este picure todav
Haha, es que usted?
Debo utilizar este cuadro en msn?
Qu? Usted piensa en esto?
Was denken Sie an diese?
Was denken Sie an dieses picure? Ich glaube, da? Ich h
Lich schaue :/
Sind hier eine neue Abbildung von mir
Einige Abbildungen von der letzten Woche, seche, wenn Sie m
Haha, diese sind Sie auf dieser Abbildung?
Sollte ich diese Abbildung auf msn benutzen?
Was denken Sie an dieses?
Wat denkt u aan dit picure? Ik vind ik lelijk kijk
Een paar beelden van vorige week, zien of houdt u hier van em nieuwe pic van me.
Hebt u dit picure nog gezien? : P
Hebt u dit picure nog gezien? : P
Haha, bent u dat op dat beeld?
Zou ik dit beeld op msn moeten gebruiken?
Wat denkt u over dit?
Que pensez-vous? Ce picure? Je me sens que je semble laid :/
Voici un nouveau pic de moi
Quelques images de la semaine derni
E, voient si vous les aimez
Avez-vous vu ce picure encore?
Haha, est-vous ce sur cette image?
Si j'emploient cette image sur le msn?
Que pensez-vous? Mon image?
:(:(:(:(
Here's a new pic of me
A few pictures from last week, see if you like em
: D
Have you seen this picure yet?
Haha, is that you on that picture?
Shocould I use this picture on msn?
What do you think about this?

The other img5-2007.zip file contains the following virus names:

Www.photo5-2007-12.JPEG.com
Img3-2007-12.JPEG.com
Img2-2007-12.JPEG_www.images.com
Img-2007-12.JPEG.scr

They are all executable programs.

Solution:

1. Start-run-regedit.

2. Expand to HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run.

Delete this item: SystemDevic.

3. Restart your computer.

4. Delete hard disk files:

C: \ WINDOWS \ devic.exe

C: \ WINDOWS \ img5-2007.zip

There are other MSN worms that cannot be cleared by the above methods

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.