種類 |
I-Worm
|
危険度/拡散度 |
/
|
発見日 |
[korea] 2009-12-06 [Foreign] 0000-00-00
|
Virobot対応 |
2009-12-07 [Able to detect & repair]
|
[Symptoms of Infection] 2) The contents of the created Kosong.Bron.Tok.txt file is like below. Brontok.A By: HVM31 -- JowoBot #VM Community -- 3) It writes a string like "pause" to (Route)\autoexec.bat file. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKCU\Software\Microsoft\Windows\CurrentVersion\Run 5) By modifying registry value, it restrics the use of folder option, registry, and CMD. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System 6) By modifying registry value, it hides below files. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\advanced HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\advanced HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\advanced
8) It downloads datas by accessing to a certain server.
9) It send a mail to certain mail account.
10) Once a program which has certain string is executed, it reboots system. |
|
[How to repair] 1. If you are WinXP/ME users, please be inactivate System Recovery Function. The reason why being inactivate of the system recovery is to clean the virus completely. - Use the trial version of ViRobot products (30days only) a. Run your ViRobot, and choose "all files" in scan option. - ViRobot Desktop 5.5 : [Tools] -> [Configuration] -> [Virus Scan] : Check all files - LiveCall (Free Scan) : [Advanced Scan] : Check |