Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Need help with trojan backdoor.sdbot.gen. Help me@Wits end!
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Need help with trojan backdoor.sdbot.gen. Help me@Wits end!  
Forum Quick Jump
 
New Topic Post reply to : Need help with trojan backdoor.sdbot.gen.  Help me@Wits end! Printable version of : Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!
[ << Previous Thread | Next Thread >> ]

Dirrty1
New Member


Date Joined Oct 2004
Total Posts : 3
 
   Posted 10-17-2004 3:04 (GMT +1)    Quote: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!Alert an admin about: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!
I have tried to remove it with bullguard it deleted it then tried to update the file but it said Update failed.  The file that it was located in was C:/Recycler/scupdate/exe=>(zipsfxo)=ScAn.exe
 
I tried to search for the file but Recycler was an invalid dirrectory and scupdate and scan.exe came up with an invalid search as well.
 
I tried the hijacker program perhaps one of you can see what's wrong with my registry and help me delete the file.
 
It would be of tremendous help.
Thank you,
Dirrty!Logfile of HijackThis v1.98.2
Scan saved at 9:59:27 AM, on 10/17/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\GWMDMMSG.exe
C:\WINNT\GWHotKey.exe
C:\PROGRA~1\BULLGU~1\bgnewsag.exe
C:\Program Files\AIM\aim.exe
C:\WINNT\System32\wisptis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\BullGuard\BullGuard Communicator\xcommsvr.exe
C:\Program Files\Common Files\BullGuard\BullGuard Scan Server\bdss.exe
C:\Program Files\BullGuard\vsserv.exe
c:\progra~1\bullgu~1\bdmcon.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper\CCHelper.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - C:\Program Files\Panicware\Pop-Up Stopper\pstopper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\BULLGU~1\bdmcon.exe
O4 - HKLM\..\Run: [BGNewsAgent] c:\progra~1\bullgu~1\bgnewsag.exe
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B8045DA-3F66-4283-AB38-87EEC2968556}: NameServer = 205.152.37.23 205.152.132.23
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 10-17-2004 5:31 (GMT +1)    Quote: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!Alert an admin about: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!
Hey cool
You have a clean log, nothing to see there
Reboot, and tell  how things are running.


Touch
Back to Top
 

Dirrty1
New Member


Date Joined Oct 2004
Total Posts : 3
 
   Posted 10-17-2004 6:00 (GMT +1)    Quote: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!Alert an admin about: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!
I solved my problem.  Thanks for the link though.. could come in handy for something else.  I used McAfee Quick Clean and found the errant file in the junk file cleaner and deleted it.. Problem solved.  Don't know why I didn't think to use that.


Thanks Touch.
Dirrty!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13642
 
   Posted 10-17-2004 6:58 (GMT +1)    Quote: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!Alert an admin about: Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!
smilewinkgrin No prob


Touch
Back to Top
 
New Topic Post reply to : Need help with trojan backdoor.sdbot.gen.  Help me@Wits end! Printable version of : Need help with trojan backdoor.sdbot.gen.  Help me@Wits end!
 
Forum Information
Currently it is Saturday, November 22, 2008 2:46 PM (GMT +1)
There are a total of 64.052 posts in 15.836 threads.
In the last 3 days there were 26 new threads and 158 reply posts. View Active Threads
Who's Online
This forum has 27198 registered members. Please welcome our newest member, shahed.
42 Guest(s), 1 Registered Member(s) are currently online.  Details
r1ch1e
5 Latest Threads
Redirecting virus? (7)22-11-2008 13:42:54 (r1ch1e)
Antivirus trigger is now the threat or what? (6)22-11-2008 13:01:06 (thegascomp)
Generic.PWS.WoW.B7078E0 (16)22-11-2008 11:55:15 (Behram)
Help please!!! (15)22-11-2008 10:05:45 (Touch)
HELP I AM GOING MAD (5)22-11-2008 06:51:49 (Touch)