Martinf
April 8th, 2003, 11:39 PM
i guess my question is am I clean what should I do now. I am running windows 2K.
In feb 2003 I got the following message from NAV:
-{ Quote: "
C:\WINNT\System32\STDE9.exe
is infected with the Backdoor.Sdbot virus.
Unable to repair this file.
" }-
I did run norton AV in safe mode thinking that would protect me but i had problems starting up and shuting down. I moved and was off line for a few weeks. I got another message from NAV:
-{ Quote: "
Date: 3/21/2003, Time: 19:19:10, - on GTY9GVYXN0QHITL
The file
C:\WINNT\Web\printers\images\syn.exe
is infected with the Hacktool.Flooder virus.
Unable to repair this file.
Date: 3/21/2003, Time: 19:19:10, - on GTY9GVYXN0QHITL
The file
C:\WINNT\Web\printers\images\syn.exe
is infected with the Hacktool.Flooder virus.
Unable to repair this file.
C:\WINNT\system32\upload.exe
is infected with the Backdoor.Sdbot virus.
This file was quarantined." }-
things went rather whacky. I noticed some odd start up and got help from DSL reports removng the following from the satrtup file-
An bad explorer.exe in the printers folder and scvhost.exe- I removed all references from the registry too.
I decided (after searching) to add TDS to my system. It is up and running now. My scans are clean, should I do anything else to make sure the virus is removed??
My questions are as followed-
1 am I free of trojans?
2- I found STDE9.exe file I deleted it is that OK???
3- I suspect alot of this had to due with a bad older router I have a bettter router with NAT and Firewall (D-Link 614+). Why did I suddenly getting so many attacks? I have a dynamic ISP was it the old Prestige 314 router.
Thanks for your help in advance
Martin
In feb 2003 I got the following message from NAV:
-{ Quote: "
C:\WINNT\System32\STDE9.exe
is infected with the Backdoor.Sdbot virus.
Unable to repair this file.
" }-
I did run norton AV in safe mode thinking that would protect me but i had problems starting up and shuting down. I moved and was off line for a few weeks. I got another message from NAV:
-{ Quote: "
Date: 3/21/2003, Time: 19:19:10, - on GTY9GVYXN0QHITL
The file
C:\WINNT\Web\printers\images\syn.exe
is infected with the Hacktool.Flooder virus.
Unable to repair this file.
Date: 3/21/2003, Time: 19:19:10, - on GTY9GVYXN0QHITL
The file
C:\WINNT\Web\printers\images\syn.exe
is infected with the Hacktool.Flooder virus.
Unable to repair this file.
C:\WINNT\system32\upload.exe
is infected with the Backdoor.Sdbot virus.
This file was quarantined." }-
things went rather whacky. I noticed some odd start up and got help from DSL reports removng the following from the satrtup file-
An bad explorer.exe in the printers folder and scvhost.exe- I removed all references from the registry too.
I decided (after searching) to add TDS to my system. It is up and running now. My scans are clean, should I do anything else to make sure the virus is removed??
My questions are as followed-
1 am I free of trojans?
2- I found STDE9.exe file I deleted it is that OK???
3- I suspect alot of this had to due with a bad older router I have a bettter router with NAT and Firewall (D-Link 614+). Why did I suddenly getting so many attacks? I have a dynamic ISP was it the old Prestige 314 router.
Thanks for your help in advance
Martin