IRC Bot not flagged by NOD32

Discussion in 'NOD32 version 2 Forum' started by BTW, May 17, 2005.

Thread Status:
Not open for further replies.
  1. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
  2. Primrose

    Primrose Registered Member

    Joined:
    Sep 21, 2002
    Posts:
    2,743
    And when that one is clean off by Norton..is the PC then crippled..or are they just left..I am trying to figure out the need to detect them if the exploit is stopped.
     
  3. Primrose

    Primrose Registered Member

    Joined:
    Sep 21, 2002
    Posts:
    2,743
  4. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    if they are not removed then the usual way of running the legitimate process by start/run and just typing the name won't work

    so CMD
    netstat
    ping
    regedit
    tasklist
    taskkill
    tracert

    won't work

    the authors of the worm obviously thought that by disabling the ability to remove it easily & it's reg keys etc it would continue to do it's deeds

    You know that it's almost impossible to delete a running file and if taskkill is disabled to stop it running and regedit is disabled to stop the start up keys being fixed then it's harder to kill off
     
  5. Primrose

    Primrose Registered Member

    Joined:
    Sep 21, 2002
    Posts:
    2,743
    Thanks..yup seen many do the hijackthis having to deal with that problem left since not many type in cmd.exe etc etc..but I did not think that if Norton cleaned the PC of the p2p thingie..that it would then leave a PC still crippled.

    But doing it all manually does create a problem..and have seen people who had parts of it cleaned..find out later they could not do a regedit..ping or cmd...unles the typed in the full regedit.exe.


    http://www.wiscnet.net/cl-ping
     
  6. BTW

    BTW Guest

    Maybe, after seeing one, I thought it was a netsky variant and did not pay much more attention

    Yes I do : it's my resident for years and KAV on demand. At least it's well set on my machine. It was not detected by NOD32 on demand with advanced heuristic till added to the DB

    Lot of lambda users click like lucky Luke and don't remember after five minutes what they have done and why ;)
    When you tell them, they never listen and if by any chance they listen , they never learn, alas ;(
    I think this little bot like many others is just a poor SK job unpacking and repacking a stupid trojan written with the feeds. No chance for wide spreading for this one :-D

    Cheers,
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.