Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 10th, 2004, 08:57 PM
arrowsmithmidwest's Avatar
arrowsmithmidwest arrowsmithmidwest is offline
Regular Poster
 
Join Date: May 2004
Location: Midwest
Posts: 165
Default Virus information

Hi all,

I have two viruses which i need to know some more information about, i can't find much though, i have read about the sdbot.AFN in the archives in this site.


SDBOT.AFN
and
Rbot.YZ

anyone got any links to sites where info on these viruses that nod has picked up?
Or has anyone had any experience with these viruses before.

cheers
  #2  
Old November 10th, 2004, 08:58 PM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,627
Default Re: Virus information

What files are NOD32 alarming on that it says are infected with these?
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #3  
Old November 10th, 2004, 09:01 PM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Default Re: Virus information

SDBOT.AFN try:

Also known as:
W32.Randex.gen (Symantec), Backdoor/SDBot, IRC/SdBot.AFN (Eset), Backdoor.SdBot.jg (Kaspersky), W32/Sdbot.worm.gen.h (McAfee)

Gerard
__________________
25 forum posting etiquette tips
  #4  
Old November 10th, 2004, 09:05 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,601
Default Re: Virus information

Rbot.YZ look here here are the different variations
Attached Images
 
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #5  
Old November 10th, 2004, 09:12 PM
arrowsmithmidwest's Avatar
arrowsmithmidwest arrowsmithmidwest is offline
Regular Poster
 
Join Date: May 2004
Location: Midwest
Posts: 165
Default Re: Virus information

thanks for the quick repsonse, the files infected are:

msconfg.exe - sdbot.afn

atiphexx.exe - rbot.yz
  #6  
Old November 10th, 2004, 09:15 PM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Virus information

I would run a scan with Nod32 in Safe Mode, if you find there are problems with System Files affected, then after this you can place your Windows CD in the drive, click start > run, type in CMD, type in "sfc /scannow".

SFC (System File Checker, a part of Windows File Protection) will replace any changed/damaged system files with a clean copy. SFC may not solve every problem, but it's a good start that anyone can do...

Hope this helps...

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers

Last edited by Blackspear : November 10th, 2004 at 10:00 PM. Reason: Spelling and Grammer, just the usual :)
  #7  
Old November 10th, 2004, 09:15 PM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Default Re: Virus information

maybe this works for YZ as well?

http://www.sophos.com/support/disinfection/rbotek.html
__________________
25 forum posting etiquette tips
  #8  
Old November 10th, 2004, 09:23 PM
arrowsmithmidwest's Avatar
arrowsmithmidwest arrowsmithmidwest is offline
Regular Poster
 
Join Date: May 2004
Location: Midwest
Posts: 165
Default Re: Virus information

Quote:
Originally Posted by gerardwil
SDBOT.AFN try:

Also known as:
W32.Randex.gen (Symantec), Backdoor/SDBot, IRC/SdBot.AFN (Eset), Backdoor.SdBot.jg (Kaspersky), W32/Sdbot.worm.gen.h (McAfee)

Gerard


Where abouts did you get that information Gerard?
  #9  
Old November 10th, 2004, 09:34 PM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Virus information

Try here: https://www.virusbtn.com/perlbin/vgr....AFN&product=0

www.virusbtn.com > Resources> Vgrep

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #10  
Old November 10th, 2004, 09:45 PM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,627
Default Re: Virus information

Quote:
Originally Posted by arrowsmithmidwest
thanks for the quick repsonse, the files infected are:

msconfg.exe - sdbot.afn

atiphexx.exe - rbot.yz
What are the locations of these files? Upload these 2 files to Jotti's site HERE for a second opinion.
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #11  
Old November 10th, 2004, 09:56 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Virus information

Quote:
Originally Posted by arrowsmithmidwest
anyone got any links to sites where info on these viruses that nod has picked up?

Win32.Rbot.H

Quote:
Method of infection

When first run, Rbot.H copies itself into the %System% directory as msconfg.exe.

It then adds entries to the following registry keys so that it is automatically run each time Windows starts:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Update = "msconfg.exe"
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Update = "msconfg.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Update = "msconfg.exe"
  #12  
Old November 10th, 2004, 10:16 PM
arrowsmithmidwest's Avatar
arrowsmithmidwest arrowsmithmidwest is offline
Regular Poster
 
Join Date: May 2004
Location: Midwest
Posts: 165
Default Re: Virus information

i have removed both viruses now, computer is virus free, now i just have a problem with the OS, i will run the sfc and if not better i may try a win repair.
  #13  
Old November 11th, 2004, 05:41 AM
Tweakie Tweakie is offline
Regular Poster
 
Join Date: Feb 2004
Location: E.U.
Posts: 90
Default Re: Virus information

Another valuable resource for this kind of information :
Norman's searchable database of automatically generated
virus descriptions (sandbox outputs). Here :
http://sandbox.norman.no/live_5.html

msconfg.exe -->
http://sandbox.norman.no/live_5.html...9437&menulang=

atiphexx -->
http://sandbox.norman.no/live_5.html...x.exe&adv=true
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:07 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums