mystifiednewbie
June 23rd, 2004, 06:19 PM
Hi,
I put up an xp system onto the net, that was only protected by sygate free firewall (no antivirus), and noticed that I had an unknown service navscan32.exe running on the sytem. Recognised this only cos the firewall asked for permission to open up an irc channel to a xxx.biz site.
Searching the system for this file, came across a file called navscan32.exe - 360f0aec.pf in windows\prefetch; googling got me the only sane reference from sophos av site - who called it a "W32/SDBOT-DO" variant. At that point I kept the original file, but deleted the registry entries as they suggested.
Then downloaded TDS-3 (eval version) and installed onto the infected system, as is. Did not update databases, did not update radius files or anything. Ran a full system scan twice, including drives, memory processes et al. It comes up clean, every time.
- Is this expected behaviour of TDS-3?
- Should I be doing something else as well?
Thanks in advance
I put up an xp system onto the net, that was only protected by sygate free firewall (no antivirus), and noticed that I had an unknown service navscan32.exe running on the sytem. Recognised this only cos the firewall asked for permission to open up an irc channel to a xxx.biz site.
Searching the system for this file, came across a file called navscan32.exe - 360f0aec.pf in windows\prefetch; googling got me the only sane reference from sophos av site - who called it a "W32/SDBOT-DO" variant. At that point I kept the original file, but deleted the registry entries as they suggested.
Then downloaded TDS-3 (eval version) and installed onto the infected system, as is. Did not update databases, did not update radius files or anything. Ran a full system scan twice, including drives, memory processes et al. It comes up clean, every time.
- Is this expected behaviour of TDS-3?
- Should I be doing something else as well?
Thanks in advance