File Name: devic.exe
File Size: 23304 bytes
AV name: (only one report is displayed on virustotal) Backdoor. Win32.SdBot. cok
Shelling method: Unknown
Programming Language: VC
Virus Type: IRCbot
File MD5: 45de608d74ee4fb86b20da86dcbeb55c
Behavior Analysis:
1. Release virus copies:
C: \ WINDOWS \ devic.exe, 23304 bytes
C: \ WINDOWS \ img5-2007.zip, 23456 bytes
2. Add the registry and start it after it is started:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run
(Registry value) SystemDevic = "devic.exe"
3. Test the network and connect to the IRC server irc.pNet.com every five seconds. log on with a random name and a blank password.
4. The following command may be accepted:
PB. Main->
PB. irc->
PB. Thread->
PB. wget->
PB. update->
PB. Spam-MSN->
PB. Botkiller->
PB. pStore->
PB. Visit->
PB. DDos->
5. Send a virus package to an MSN friend and one of the following random packages:
Qu? Usted piensa de este cuadro?
Consegu? A nuevo cuadro de m? La toma una mirada
Algunos cuadros de la semana pasada, consideran si usted tiene gusto en ellos.
Tiene usted visto este picure todav
Haha, es que usted?
Debo utilizar este cuadro en msn?
Qu? Usted piensa en esto?
Was denken Sie an diese?
Was denken Sie an dieses picure? Ich glaube, da? Ich h
Lich schaue :/
Sind hier eine neue Abbildung von mir
Einige Abbildungen von der letzten Woche, seche, wenn Sie m
Haha, diese sind Sie auf dieser Abbildung?
Sollte ich diese Abbildung auf msn benutzen?
Was denken Sie an dieses?
Wat denkt u aan dit picure? Ik vind ik lelijk kijk
Een paar beelden van vorige week, zien of houdt u hier van em nieuwe pic van me.
Hebt u dit picure nog gezien? : P
Hebt u dit picure nog gezien? : P
Haha, bent u dat op dat beeld?
Zou ik dit beeld op msn moeten gebruiken?
Wat denkt u over dit?
Que pensez-vous? Ce picure? Je me sens que je semble laid :/
Voici un nouveau pic de moi
Quelques images de la semaine derni
E, voient si vous les aimez
Avez-vous vu ce picure encore?
Haha, est-vous ce sur cette image?
Si j'emploient cette image sur le msn?
Que pensez-vous? Mon image?
:(:(:(:(
Here's a new pic of me
A few pictures from last week, see if you like em
: D
Have you seen this picure yet?
Haha, is that you on that picture?
Shocould I use this picture on msn?
What do you think about this?
The other img5-2007.zip file contains the following virus names:
Www.photo5-2007-12.JPEG.com
Img3-2007-12.JPEG.com
Img2-2007-12.JPEG_www.images.com
Img-2007-12.JPEG.scr
They are all executable programs.
Solution:
1. Start-run-regedit.
2. Expand to HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run.
Delete this item: SystemDevic.
3. Restart your computer.
4. Delete hard disk files:
C: \ WINDOWS \ devic.exe
C: \ WINDOWS \ img5-2007.zip
There are other MSN worms that cannot be cleared by the above methods