Computing.Net > Forums > Security and Virus > Backdoor.Sdbot -System32.exe -Again

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Backdoor.Sdbot -System32.exe -Again

Reply to Message Icon

Name: Tallican
Date: February 16, 2004 at 23:30:43 Pacific
OS: Windows XP Pro
CPU/Ram: Intel P4 - 2.4Ghz, 512mb
Comment:

http://www.computing.net/security/wwwboard/forum/7773.html

This is a continuation on from the above thread all concerning the virus

-> Backdoor.Sdbot

...please help me!!!

=============================

As with all of you I have the virus also...(refering to the above thread)

I want to follow the above ways to remove the virus but Im really really sceptical.

(it was mentioned that your going to have to delete system32.exe and then go into registery and get rid of one of the registry keys)

Just as josh has mentioned that his machine is running slower (once he deleted system32.exe), what effect will this have on my machine? Is system32.exe a executable that is supposed to be with windows or is it a virus?....or has the virus actually implemented itself into the executable and isn't removable until its deleted?

And by deleting system32.exe won't that make my windows (xp pro) less of a product than what it was before? Meaning, isn't the system32 executable meant for the running of windows, and if so, won't it actually cause performance issues if its gone?

From what I have read all your doing is getting rid of this file and then Windows is shouting back "Hey where is my file?" and then your going into registery, deleting a segment initially fooling the poor thing....

So atm Im keeping this virus on my machine until I know exactly if system32 is a virus in its on right, or has this virus (Backdoor.Sdbot) actually written itself into the system32 executable (required by windows) therefore needing to delete it. If its the latter, then it might be safer to reinstall windows...(if the virus can't get passed my router firewall, and im not using IRC).

Can anyone help with my questions? Thankyou.



Sponsored Link
Ads by Google

Response Number 1
Name: Valerie (by Garibaldi)
Date: February 17, 2004 at 00:27:59 Pacific
Reply:

Search the WWW for system32.exe - lots of info there!!

V...


0

Response Number 2
Name: Tallican
Date: February 17, 2004 at 00:37:38 Pacific
Reply:

Oh I have looked for system32.exe, don't you worry, Just im getting no results...everything im coming back with though is all related to it and virus's...not its actual functionality...so I can't determine wether or not it is an actual windows executable or infact it is a virus in disguse *shudders*.


0

Response Number 3
Name: Tallican
Date: February 17, 2004 at 00:39:10 Pacific
Reply:

I don't know much about windows's inner most workings :( im a newb to its infrastructure.


0

Response Number 4
Name: G_B1
Date: February 17, 2004 at 01:16:33 Pacific
Reply:

Have a look here

I use this site most of the time i want info on the windows system processes it's pretty conclusive. Lots of viruses have exectuables that look genuine, one of my worst hated is the Rundll.exe part of the LOXOSCAM virus. The necessary file that you don't want to delete is Rundll32.exe


0

Response Number 5
Name: Tallican
Date: February 17, 2004 at 03:05:38 Pacific
Reply:

Thankyou very much for that...its always good to have a bit of reasurance before jumping into something :)


0

Related Posts

See More



Response Number 6
Name: Exodus
Date: February 17, 2004 at 09:17:06 Pacific
Reply:

In my experience, when you get a file thats part of Windows that shows up as a virus, the virus itself has actually REPLACED or RENAMED the file. Deleting a registry key is a key part of the removal process. Dont be afraid to do it.. just MAKE SURE you follow instructions to the T! Most of them will have you to rename in DOS a .exe file to a .com file, then use it.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Backdoor.Sdbot -System32.exe -Again

Backdoor.Sdbot - System32.exe www.computing.net/answers/security/backdoorsdbot-system32exe/7773.html

Killing the Backdoor.sdbot Virus www.computing.net/answers/security/killing-the-backdoorsdbot-virus/3901.html

irc/sdbot has my system32.exe www.computing.net/answers/security/ircsdbot-has-my-system32exe/5058.html