Computing.Net > Forums > Windows XP > backdoor sdbot

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

backdoor sdbot

Reply to Message Icon

Name: Max
Date: July 2, 2003 at 05:34:47 Pacific
OS: XP
CPU/Ram: -
Comment:

i have the virus backdoor.sdbot on my computer in file winxp/system32 under the filename system32.exe. i have looked in the appropriate directories for the files that the trojan is supposed to leave and i can't find any of the files. i looked in my registry and i can't find the registry entries that the trojan is supposed to leave. I found the file system 32.exe but i cant delete it my NAV pops up every five minutes notifying me of the virus but i can't remove the virus or delete it NAV says unable to repaire the file. can someone please help me.



Sponsored Link
Ads by Google

Response Number 1
Name: Tufenuf
Date: July 2, 2003 at 05:48:33 Pacific
Reply:

Max, Follow the instructions at the link below.

http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html

HTH
Tufenuf


0

Response Number 2
Name: Max
Date: July 2, 2003 at 07:18:46 Pacific
Reply:

I did but i cant find cnfgldr.exe. or


"Configuration Manager"="Cnfgldr.exe"
"System Monitor"="Sysmon16.exe"
"MSSQL"="Mssql.exe"
"Configuration Loader" = "aim95.exe"
"Internet Config" = "svchosts.exe"
"System33" = "%System%\FB_PNU.exe"
"Configuration Loader"="cmd32.exe"


0

Response Number 3
Name: Tufenuf
Date: July 2, 2003 at 07:28:45 Pacific
Reply:

Max, Note that it states:

Copies itself to the %System% folder. The filename to which it copies itself can vary. Some known filenames are:
Cnfgldr.exe
Sysmon16.exe
Sys3f2.exe
Syscfg32.exe
Mssql.exe
Aim95.exe
Svchosts.exe
FB_PNU.EXE
Cmd32.exe
Sys32.exe

"The filename to which it copies itself can vary. Some known filenames are:"

That doesn't necessarily mean that it copies all of those files.

Tufenuf


0

Response Number 4
Name: ranchhand
Date: July 2, 2003 at 11:12:01 Pacific
Reply:

Did you go into the RUN hive in your Register as per the Symantec directions? It's easier to identify a foreign entry that you don't recognize there, delete it, and it stops the virus from loading on boot. Then at least it buys you some time to delete the other files. But as long as it loads on boot, Windows won't let you delete it.


0

Response Number 5
Name: devilscal
Date: July 3, 2003 at 12:54:50 Pacific
Reply:

damthe virus
always stick with the system files...~~
how can i Qill them all..??


0

Related Posts

See More



Response Number 6
Name: stljibaro
Date: July 4, 2003 at 14:56:48 Pacific
Reply:

The Backdoor.Sdbot program name I found in, and removed from, my son's computer is called svchosts.exe... the corresponding Run and RunServices registry name appears to be svshosts! Other "infected" programs found were regstr.exe, qyqcc.exe, and kempoo.exe.

I also simultaneously found the Backdoor.Optix trojan... under the name wsock32.exe


0

Response Number 7
Name: Neiro
Date: July 18, 2003 at 13:52:03 Pacific
Reply:

Is there any information on how big this file's supposed to be?
I've found a suspicious looking file on my computer called svshosts.exe (1.672.192 bytes) which was running in the background. When I take a look at the file it seems to be packed by something called PEPACK. Most of the file's blank (ie 0x00).
I've killed the process and removed the file. I can't see any entries in my registry hive that indicates sdbot, and my antivirus (nav2002) has not said a word. But it's not the first time that software has failed me.
Any help to find here?

Regards,


0

Response Number 8
Name: reenie_thisgirl
Date: July 19, 2003 at 10:05:04 Pacific
Reply:

how did u delete it?!?!

I got the same file running now and its communicating through my broadband connection as we speak!

My antivirus (AVG) has not said a word and my firewall (Sygate) wont block it!

I've found the file in the system folder but it wont let me delete it as its says windows is running it.. i would stop it running but it aint in the close dialog box!

ARGHHHHHHH please help.....


0

Response Number 9
Name: Ozzie
Date: July 26, 2003 at 17:40:25 Pacific
Reply:

w00t! ?

I hade the backdoor.Sdbot virus in a file called svshosts.exe and I just pressed ctrl+alt+del and stopped the program (svshosts.exe) and the i did a virus scan *PhoW* the virus was gone :D

and now i'm so happpy!!! :DDD

....damn irc virus .... musn't been when i joined the #porn channel for fun :/

well WOOHOO!!! l8r


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: backdoor sdbot

trojan horse IRC/BackDoor.SdBot.25. www.computing.net/answers/windows-xp/trojan-horse-ircbackdoorsdbot25/109629.html

Backdoor.sdbot on winsys32.exe www.computing.net/answers/windows-xp/backdoorsdbot-on-winsys32exe/53025.html

virus Backdoor.SDBot.Gen www.computing.net/answers/windows-xp/virus-backdoorsdbotgen/79777.html