| General information of W32.Pinkslipbot | |
| Name: | W32.Pinkslipbot (Free Scan) |
| Affected OS: | Windows NT/2000/XP/Vista |
| Category: | Spyware |
| Risk level : |
![]() |
When executed, the worm copies itself into the following location:
And drops the following files
The following registry value has been added to the system
The above mentioned registry entry confirms that the Bot executes every time when windows starts.
The following registry value has been modified
The above mentioned registry entry confirms that the Bot executes every time when windows starts.
Once the users system is compromised, the worm connects to the following sites to receive bot commands and to perform malicious activities.
And it steals the following system information
The worm creates a mutex object called 搆xvia� to mark its presence and creates the following configuration files
Also the worm monitors the following sites in the compromised system, when visited by the user.
[%Appdata%\ is C:\Documents and Settings\All Users\Application Data\]
-----------------------------------------------
Some variants of this bot are found to be using javascript to download
This bot also creates a
Some variants of this bot drops a copy of itself and its components in the following directory:
The following files are also created:
(Where %all users profile% is the Windows user profile folder, e.g. C:\Documents and Settings\All Users)
It Modifies existing autostart entries in the registry to automatically execute at startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"[original application registry name]" = "[original application registry value]" ""%all users profile%\_qbothome\_qbotinj.exe" "%all users profile%\_qbothome\_qbot.dll" /c "[original application registry value]"
It then injects its dll component into iexplorer.exe.
It connects to the following domain to send information and receive commands.
Information sent includes:
Commands received includes malware update and install additional malware in the system.