From: "David K" <
[email protected]>
| The reference is to:
| HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run system
| uptime sysentry.exe
| David.
|
A little research indicated McAfee "may" call this the
"W32/Sdbot.worm.gen.x"
And Mcafee DAT v4494 and above should handle it with Todays DAT being
v4496
The instructions I previously provided you should remove this SDbot
variant.
To be sure you can submit "sysentry.exe" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against 18 different AV vendor's
scanners.
Please post back the EXACT results.
-------------
Here are the directions once again to remove the SDbot variant.
Dump the contents of the IE Temporary Internet Folder cache (TIF)
Start --> Settings --> Control Panel --> Internet Options --> Delete Files
Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear
Download CLEAN.EXE from the URL --
http://www.ik-cs.com/programs/virtools/clean.exe
It is a self-extracting ZIP file that contains the Kixtart Script
Interpreter
{
http://kixtart.org Kixtart is CareWare } three batch files, two Kixtart
scripts, two Link
(.lnk) files and a PDF instruction file.
GETFILES.BAT -- For downloading (FTP) the files needed to run the McAfee
Command Line
Scanner. You may have to disable your FireWall or allow FTP.EXE to go
through your FireWall
to allow the FTP utility to download the needed files
CLEAN.BAT -- For running within Windows after running
c:\mcafee\GetFiles.BAT. If you choose
to scan again at a future date, run this batch file. It will
automatically check the date
of the McAfee DAT files and if it is a couple of days old, it will
download (FTP) the latest
signature files and install them before performing the scan.
DOSCLEAN.BAT -- For use on a Win9x/ME PC or on a Win2K/WinXP PC that is
using FAT32 after
you have booted from an Emergency Boot Disk or DOS disk and have already
executed;
c:\mcafee\GetFiles.BAT from within Windows. DOS disk boot images can be
obtained from;
http://www.bootdisk.com/bootdisk.htm
I need you to perform the following...
Execute; CLEAN.EXE
Choose; Unzip
Choose; Close
Execute; c:\mcafee\GetFiles.BAT
{ or Double-click on 'GetFiles Link' in c:\mcafee }
Reboot the PC into Safe Mode [F8 key during boot]
Shutdown as many applications as possible !
It would also help for you to read - "How to perform a clean boot in
Windows XP"
http://support.microsoft.com/kb/310353
Execute; c:\mcafee\CLEAN.BAT
{ or Double-click on 'Clean Link' in c:\mcafee }
A final report in HTML format called C:\mcafee\ScanReport.HTML will be
generated. At the
end of the scan, it will be displayed in your browser (Opera, FireFox or
Internet Explorer).
It is suggested that you move the report out of c:\mcafee before
performing another scan.
It would be a good idea to scan in Safe Mode and in Normal Mode and save a
copy of the HTML
report for each session.
* * * Please report back your results * * *