Pretty Girls and SVCHOSTX.EXE or WORM_SDBOT.EW

  1. #1

    Angry Pretty Girls and SVCHOSTX.EXE or WORM_SDBOT.EW

    [Post detail removed at request of member]
    Last edited by D-A-L; 11-09-2008 at 07:49 PM.


  2. #2
    Things just got worse.... I thikn I got some bad advice and ran hijack to fix the following line form my log

    O4 - HKLM\..\Run: [svchost32] c:\WINDOWS\system32\Microsoft\security\svchostX.ex e


    Now no programs on my computer will run. Have I caused a major problem? Please HELP!

  3. #3
    HJThis is offline Senior Member
    Hello,coldstormrider & Welcome

    Before you do any of this here move HijackThis to a folder
    in C:\Dirve like so C:\HJT

    Press control-alt-delete to get into the task manager and end the follow processes if they exist:
    LTMSG.exe 7
    svchostX.ex e

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.

    Check the following items in HijackThis.
    Close all windows except HijackThis and click Fix checked:

    This item here if not using fix it
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://moneycentral.msn.com/investor/home.asp

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [svchost32] c:\WINDOWS\system32\Microsoft\security\svchostX.ex e
    [B]O4 - HKLM\..\RunOnce: [svchost32] c:\WINDOWS\system32\Microsoft\security\svchostX.ex e/RunOnce
    O4 - Startup: PowerReg Scheduler V3.exe

    This item here any idea what it is anyone
    O4 - HKLM\..\RunOnce: [HcTSC] C:\WINDOWS\TSC.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)

    Make sure you can view hidden and system files: Instructions here

    Then Boot to safe mode: Instructions here

    Delete the following files\folders IF still present:

    c:\WINDOWS\system32\Microsoft\security\svchostX.ex e<---This file

    HGD
    Last edited by HJThis; 14-06-2005 at 11:26 PM.

  4. #4
    HJThis is offline Senior Member
    Hi,

    As long as this is not what you fixed or deleted
    svchost.exe

    & when you did the fix with HijackThis it should
    have made a backup look for it where you had
    it installed to anyone looking at this that's

    why we keep asking that HijackThis is placed
    in a folder in C:\Drive

    HGD

  5. #5
    Looks like this thing beat me..... Suddenly I can access not a single program. I recovered the system and the virus is gone...I'm back in business

    One strange thing though, when the worm was on the computer I would occasionally receive a prompt to select a video source (ie my cam). Are there worms out there that will allow a user remote access or was this just a concidence?

    cold...

  6. #6
    HJThis is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    Hi,coldstormrider

    Yes that could be i have seen Trojans that can do this
    so why not a Virus/Worm but now that you are up & running
    this is the time to post a new HijackThis logfile so we may
    see if there are any problems to take care of now.

    so i would do this before you go running all
    over the net do now that the PC is clean
    & we have software you can install to keep
    you safe but need to see a HijackThis logfile

    HGD

+ Reply to Thread