Skip to main content

Backdoor:W32/Pushbot.gen!A

Classification

Category:

Malware

Type:

Backdoor

Aliases:

  • W32/Sdbot.worm
  • GenPack:Generic.Malware.SYN!!BdQ!wg.78A8B029
  • W32.IRCBot (Symantec)
  • Worm:Win32/Pushbot (Microsoft)
  • W32/Sdbot.worm (McAfee)

Summary

A remote administration tool (RAT) that bypasses the security features of a program, computer or network to give unauthorized access or control to its user.

Removal

Technical Details

Pushbot is a backdoor program that can be operated through IRC. The backdoor is usually sized around 28-55KB.Pushbot is able to propagate through multiple vectors:

  • Removable media such as USB thumb drives
  • Instant Messaging (IM) networks such as AIM, MSN, ICQ and Triton
  • Network shares
  • Peer-to-Peer (P2P) networks such as Edonkey2000, Morpheus, KAZAA, LimeWire, BearShare and Grokster (via the application's shared folders)

Installation

During installation, the backdoor program creates a copy of itself in:

  • %windir%\service.exe

Activity

Upon execution, Pushbot displays the following:

While active, the program has the following functionalities:

  • Perform SYN Floods
  • Perform Distributed Denial of Service (DDoS) attacks
  • View MSN, AIM and Triton Threads
  • Propagate via AIM, MSN and Triton
  • Download files
  • Update itself
  • Steal passwords from Protected Storage
  • View processes
  • Create processes
  • Visit user defined websites
  • Perform shell executions

The backdoor program is also able to detect applications or services such as VMware, Nepenthes, sandboxes and honeypots.

Registry

The backdoor program creates the following Registry key in order to automatically execute its copy in the Windows directory:

  • SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services = "service.exe"

It also creates the following Autorun.inf to facilitate its propagation on removable media such as USB thumb drives:

  • [autorun]open=RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exeicon=%SystemRoot%\system32\SHELL32.dll,4action=Open folder to view filesshell\open=Openshell\open\command=RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exeshell\open\default=1

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.