Computing.Net > Forums > Security and Virus > Need Help Cleaning Up Virus...

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Need Help Cleaning Up Virus...

Reply to Message Icon

Original Message
Name: Endtrail
Date: March 19, 2003 at 16:16:10 Pacific
Subject: Need Help Cleaning Up Virus...
OS: Windows 98
CPU/Ram: 64 RAM
Comment:

Hi, I recently scanned my computer for viruses and after cleaning up most of the viruses, one of them couldn't be repaired nor deleted. The file that is infected is called kernel32.exe and the virus name is Backdoor.Sdbot I'm using Norton AntiVirus 2002 and it can't repair, quarantine or delete the file (when I try manually, it says file in use, and I can't find it in the End Task window). I was wondering if anyone knew how to repair/delete this, maybe another antivirus program or anything. Any help will be appreciated, thanks in advance.


Report Offensive Message For Removal


Response Number 1
Name: bigjer
Date: March 19, 2003 at 16:30:26 Pacific
Reply:

http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html
I found this at the Symantec site. See if it solves your problem.
Good luck.


Report Offensive Follow Up For Removal

Response Number 2
Name: Javin
Date: March 23, 2003 at 20:50:48 Pacific
Reply:

Backdoor.SDBot has been modified more times than can be counted. I've had a number of versions of it found on my own system.

There's two places you need to check in your registry to make sure you get rid of it once it's discovered:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Remove all references to Kernel32.exe there. There should be one in each key.

Thus far, on my own computer, it's been under the names uptodo.exe and WinHelp32.exe (there were at least 7 other different copies under different names that I deleted before taking the time to jot them down.) Basically, what it comes down too is that there is NO specific name that it goes by.

The Backdoor.SDBot doesn't infect executables. It's just a simple trojan, so you won't have to worry about deleting it. If you can't disable the Kernel32.exe process in your task manager, just delete the registry keys starting it up, and reboot. Then, since it will no longer be running, just delete it.

I'm trying to isolate exactly where it came from, and I'm beginning to think that my own source for the virus is www.bootdisk.com

The virus didn't appear until I downloaded and executed an .EXE from there, and more importantly, the boot98.exe that I downloaded was the ONLY executable file that Norton was unable to scan.

To test this theory, if you're wondering where you might have gotten the virus from, check your Norton Logs and everywhere you see a "scan ommision" check the properties of it. If it's an executable, that's suspicious by itself.

Good luck everyone!

-Javin


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Need Help Cleaning Up Virus...

Need help cleaning Trojan/Virus
    Summary: I'm trying to clean a friends computer. It's a bit difficult as he didn't bring his monitor and I can't access the net on his system. (I'm on ADSL he's got dial-up)According to 'Trend Micro' anti-viru...
www.computing.net/answers/security/need-help-cleaning-trojanvirus/14664.html

Trojan virus and adware
    Summary: I have a trojan virus that is quarantined every time i run webroot antivirus. I don't understand why it keeps coming up if my antivirus is quarantining it. Also I get loads of pop ups when i'm on the ...
www.computing.net/answers/security/trojan-virus-and-adware/23723.html

Help Identifying a virus??
    Summary: Hello, I need help identifying a virus. I see a folder on the root of the C drive called C:\e056a5f39a982a9260\sp2. I cannot delete this folder and I get an access denied. I even tried deleting it ...
www.computing.net/answers/security/help-identifying-a-virus/10377.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes In 2 Days.
Discuss in The Lounge
Poll History






Data Recovery Software