Virus bkdr sdbot.cc

  • taintedmemories
  • Newbie
  • Newbie
  • User avatar
  • Joined: Aug 21, 2003
  • Posts: 7
  • Loc: La Mesa, CA
  • Status: Offline

Post April 15th, 2004, 11:30 pm

I've got a virus called BKDR SDBOT.CC that I've tried to get rid of. When I scan it and try to delete it, I'm told that it is in use. Does anyone know how I can get rid of it manually? or any other program that will get rid of it? When I do a search for it, it doesn't show up.

I've gone to http://housecall.trendmicro.com

It is located at C:/WINDOWS/SYSTEM32/MS.EXE
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post April 15th, 2004, 11:30 pm

  • Ragnar78
  • Proficient
  • Proficient
  • No Avatar
  • Joined: Feb 12, 2004
  • Posts: 279
  • Status: Offline

Post April 16th, 2004, 1:56 am

-Low risk manipulation...
Open task manager
Check in the processes the file MS.EXE...
End the processess and then go to the directory where the file is found and delete it...

-High risk manipulation (save the registry before)
Open the registry and go to this key (start, run, regedit)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Remove the key that has MS.EXE in it

Restart the computer in Safe mode...
go to the directory where the file is found and delete it...

Last but not least, check this page

http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sadmind.html
  • taintedmemories
  • Newbie
  • Newbie
  • User avatar
  • Joined: Aug 21, 2003
  • Posts: 7
  • Loc: La Mesa, CA
  • Status: Offline

Post April 16th, 2004, 7:07 pm

Awesome, thanks so much that worked perfectly.
  • Ragnar78
  • Proficient
  • Proficient
  • No Avatar
  • Joined: Feb 12, 2004
  • Posts: 279
  • Status: Offline

Post April 16th, 2004, 11:30 pm

no problem :)
  • soundbird
  • Born
  • Born
  • No Avatar
  • Joined: Apr 25, 2004
  • Posts: 2
  • Status: Offline

Post April 25th, 2004, 9:52 am

Hmmmmm.... I have just found a similar virus called BKDR Coreflood which I can't remove with Trend Micro free scan. How do I remove this one? Any ideas? Also could this Virus be the reason why my Yahoo mail account seems to have been hijacked and I can't access it? :cry:
Thanks
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23407
  • Loc: Woodbridge VA
  • Status: Offline

Post April 25th, 2004, 10:25 am

Here are symantec's instructions. You'll need to run your virus scan in safe mode, similar to what Symantec suggests to running there's (shouldn't make much of a difference which virus scan you use as long as it detects it).

Also note the instructions to disable system restore (ME/XP)

And don't miss the registry key that needs deleted.


And to answer your question about Yahoo -- Yes, this trojan uses the IRC channel to access it's servers.
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • Smokenjoe
  • Mastermind
  • Mastermind
  • User avatar
  • Joined: Apr 09, 2004
  • Posts: 1573
  • Loc: Anchorage, AK
  • Status: Offline

Post April 25th, 2004, 8:06 pm

Cool, i just got the same virus. Thx for the help on that one. :)
For all your engineering related inquiries:
http://www.eng-tips.com/index.cfm
  • soundbird
  • Born
  • Born
  • No Avatar
  • Joined: Apr 25, 2004
  • Posts: 2
  • Status: Offline

Post April 29th, 2004, 5:45 am

Thanks for all the info, I'll give it a go. Really pissed :evil: about my Yahoo account though. Anyway of me or Yahoo recovering it that you know of?
soundbird xx

Post Information

  • Total Posts in this topic: 8 posts
  • Users browsing this forum: No registered users and 89 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
cron
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.