SdBot variant

G

Guest

Hi, Several coworkers and myself seem to have picked up a tough version of
SdBot, which is detected by WD (and little else - thank you WD!!). Although
WD removes the primary SdBot file, winmon.exe from WINDOWS/system32, the file
is replaced upon the next boot. We're aware of the usual instructions for
removing associated registry keys that reinstall winmon.exe, but those don't
seem to exist in our registry - yet the file reappears without fail upon
rebooting. If it was just one or two of us, we'd reinstall Windows, but
several of us (and some servers too) have this monster. Any suggestions?
 
B

Bill Sanderson MVP

Have you tried cleaning in safe mode, with both Windows Defender (check in
help, about to see if you are on 1347--(top version number) If not, do a
new download from the download center and run it--it will upgrade.

After the upgrade, check that you are on the latest definitions--I'd go by
Windows Update.

Then update your antivirus application as well, restart windows in safe
mode, and scan with both the antivirus app and Windows Defender
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top