PDA

View Full Version : Help with multiple Trojan attacks


Martinf
April 8th, 2003, 11:39 PM
i guess my question is am I clean what should I do now. I am running windows 2K.

In feb 2003 I got the following message from NAV:
-{ Quote: "
C:\WINNT\System32\STDE9.exe
is infected with the Backdoor.Sdbot virus.
Unable to repair this file.
" }-

I did run norton AV in safe mode thinking that would protect me but i had problems starting up and shuting down. I moved and was off line for a few weeks. I got another message from NAV:
-{ Quote: "
Date: 3/21/2003, Time: 19:19:10, - on GTY9GVYXN0QHITL
The file
C:\WINNT\Web\printers\images\syn.exe
is infected with the Hacktool.Flooder virus.
Unable to repair this file.

Date: 3/21/2003, Time: 19:19:10, - on GTY9GVYXN0QHITL
The file
C:\WINNT\Web\printers\images\syn.exe
is infected with the Hacktool.Flooder virus.
Unable to repair this file.

C:\WINNT\system32\upload.exe
is infected with the Backdoor.Sdbot virus.
This file was quarantined." }-

things went rather whacky. I noticed some odd start up and got help from DSL reports removng the following from the satrtup file-

An bad explorer.exe in the printers folder and scvhost.exe- I removed all references from the registry too.

I decided (after searching) to add TDS to my system. It is up and running now. My scans are clean, should I do anything else to make sure the virus is removed??


My questions are as followed-

1 am I free of trojans?

2- I found STDE9.exe file I deleted it is that OK???

3- I suspect alot of this had to due with a bad older router I have a bettter router with NAT and Firewall (D-Link 614+). Why did I suddenly getting so many attacks? I have a dynamic ISP was it the old Prestige 314 router.

Thanks for your help in advance
Martin

Gavin - DiamondCS
April 8th, 2003, 11:46 PM
Hi Martin,

If any of these still exist, please zip and email these files in, submit@diamondcs.com.au

TDS would detect the SDBot trojan in memory if it existed, you can kill it quick - open the Process List (CTRL O) right click it and choose Kill Process and Delete File.

Make sure you have the latest databases for TDS, and you should be clean of SDBot. A good way to verify this is to try the demo of Port Explorer, and send in a dump of what is listening - click FILE > Save Table and send that to us too :)

Martinf
April 9th, 2003, 12:16 AM
Gavin Will do tomorrow pm it is late in t he US and I am going to sleep and I have all three files two quarnteened one deleated.

Martin

Martinf
April 9th, 2003, 07:52 PM
Gavin,

I sent you all three I was wrong about STDE9.exe NAV didn't detect it as a trojan. I have it in my garbage bin ready to delete. Let me know if it is a trojan or a system file.

Jooske
April 9th, 2003, 10:22 PM
Hi Martinf,
Does TDS say anything about them and did you send in that STDE9.exe (zipped) to Gavin too for examination?
If it's a system file, you should be able to get a fresh one from your install cd-rom i suppose?

Gavin - DiamondCS
April 10th, 2003, 12:13 AM
I'll post back in a moment, from my first quick inspection I would say yes its a trojan, but i'll look closer now :)

Also, i saw this exact filename referenced in a BAT file owned by IRC trojan ZCrew, (mIRC and Serv-U based backdoor) Do you by any chance have a weak or non existent ADMIN pass ? Set one if so, even if you dont require that password to login..

Yep, its a variant of SDBot, as expected. Adding detection now (it should be detected once installed already, both by trace detection and in memory)