![]() |
|
#1
|
||||
|
||||
|
Hi all,
I have two viruses which i need to know some more information about, i can't find much though, i have read about the sdbot.AFN in the archives in this site. SDBOT.AFN and Rbot.YZ anyone got any links to sites where info on these viruses that nod has picked up? Or has anyone had any experience with these viruses before. cheers |
|
#2
|
||||
|
||||
|
What files are NOD32 alarming on that it says are infected with these?
__________________
Best regards, Kent AX64 Time Machine - Travel in Time Current Version 1.1.0.996 |
|
#3
|
|||
|
|||
|
SDBOT.AFN try:
Also known as: W32.Randex.gen (Symantec), Backdoor/SDBot, IRC/SdBot.AFN (Eset), Backdoor.SdBot.jg (Kaspersky), W32/Sdbot.worm.gen.h (McAfee) Gerard
__________________
25 forum posting etiquette tips |
|
#4
|
||||
|
||||
|
Rbot.YZ look here here are the different variations
__________________
The Only Safe Computer Is Unplugged ![]() MEMBER ASAP since 2004 Alliance of Security Analysis Professionals |
|
#5
|
||||
|
||||
|
thanks for the quick repsonse, the files infected are:
msconfg.exe - sdbot.afn atiphexx.exe - rbot.yz |
|
#6
|
||||
|
||||
|
I would run a scan with Nod32 in Safe Mode, if you find there are problems with System Files affected, then after this you can place your Windows CD in the drive, click start > run, type in CMD, type in "sfc /scannow".
SFC (System File Checker, a part of Windows File Protection) will replace any changed/damaged system files with a clean copy. SFC may not solve every problem, but it's a good start that anyone can do... Hope this helps... Cheers ![]()
__________________
"Illegitimis non carborundum"
translation: "Don't let the bastards grind you down" U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946) Two Photographers Last edited by Blackspear : November 10th, 2004 at 10:00 PM. Reason: Spelling and Grammer, just the usual :) |
|
#7
|
|||
|
|||
|
__________________
25 forum posting etiquette tips |
|
#8
|
||||
|
||||
|
Quote:
Where abouts did you get that information Gerard? |
|
#9
|
||||
|
||||
|
Try here: https://www.virusbtn.com/perlbin/vgr....AFN&product=0
www.virusbtn.com > Resources> Vgrep Cheers ![]()
__________________
"Illegitimis non carborundum"
translation: "Don't let the bastards grind you down" U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946) Two Photographers |
|
#10
|
||||
|
||||
|
Quote:
__________________
Best regards, Kent AX64 Time Machine - Travel in Time Current Version 1.1.0.996 |
|
#11
|
||||
|
||||
|
Quote:
Win32.Rbot.H Quote:
__________________
Wilders - Terms of Service · Site FAQ · Searching the forum easier · The Art of Quoting in Posts |
|
#12
|
||||
|
||||
|
i have removed both viruses now, computer is virus free, now i just have a problem with the OS, i will run the sfc and if not better i may try a win repair.
|
|
#13
|
|||
|
|||
|
Another valuable resource for this kind of information :
Norman's searchable database of automatically generated virus descriptions (sandbox outputs). Here : http://sandbox.norman.no/live_5.html msconfg.exe --> http://sandbox.norman.no/live_5.html...9437&menulang= atiphexx --> http://sandbox.norman.no/live_5.html...x.exe&adv=true |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|