SGDB34.exe - What is it?

C

Carel

Today the SGDB34.exe program/process appeared in our Task Manager? Does
anyone know what it is?

Thanks for your help.

We are concerned since last two weeks it been different issues. Previous two
weeks had an infection of "mywife aka "WORM_GREW.A" CME-24, Win32.Blackmal.F
[Computer Associates], Email-Worm.Win32.Nyxem.e [F-Secure],
Email-Worm.Win32.Nyxem.e [Kaspersky], W32/MyWife.d@MM [McAfee],
W32/MyWife.d@MM!M24 [McAfee], Win32/Mywife.E@mm [Microsoft], W32/Small.KI@mm
[Norman], Tearec.A [Panda Software], W32/Nyxem-D [Sophos], WORM_GREW.{A, B}
[Trend Micro]...........)
 
W

Wesley Vogel

SGDB34.exe is probably some sort of malware.

Update your antivirus software and run a full system scan.

Do the same for whatever anti-spyware applications that you have.

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
 
C

Carel

Hi Frank,

Yes we have two Minotla Printers installed.

The Konica Magicolor 2300 DL & the KONICA MINOLTA PagePro 1350W. Last week
we ordered & installed the optional Printer server for the KONICA MINOLTA
PagePro 1350W.

Update on activity of the SGDB34.exe, when the computer restarts the file
name changes.

Thanks


Frank McCallister SBS MVP said:
Hi Carel

Do you have a Seiko or Minolta printer installed.

--
Frank McCallister SBS MVP
COMPUMAC
Carel said:
Today the SGDB34.exe program/process appeared in our Task Manager? Does
anyone know what it is?

Thanks for your help.

We are concerned since last two weeks it been different issues. Previous
two weeks had an infection of "mywife aka "WORM_GREW.A" CME-24,
Win32.Blackmal.F [Computer Associates], Email-Worm.Win32.Nyxem.e
[F-Secure], Email-Worm.Win32.Nyxem.e [Kaspersky], W32/MyWife.d@MM
[McAfee], W32/MyWife.d@MM!M24 [McAfee], Win32/Mywife.E@mm [Microsoft],
W32/Small.KI@mm [Norman], Tearec.A [Panda Software], W32/Nyxem-D
[Sophos], WORM_GREW.{A, B} [Trend Micro]...........)
 
F

Frank McCallister SBS MVP

The SGDB34.exe is normally associated with Minolta or Seiko but I would be
concerned with the name change on restart, Go to
http://safety.live.com/site/en-US/default.htm for MS help on this. If the
scan doesn't find anything I would call MS 1-866 pcsafety and ask for a
Windows online forensic analysis.

--
Frank McCallister SBS MVP
COMPUMAC
Carel said:
Hi Frank,

Yes we have two Minotla Printers installed.

The Konica Magicolor 2300 DL & the KONICA MINOLTA PagePro 1350W. Last week
we ordered & installed the optional Printer server for the KONICA MINOLTA
PagePro 1350W.

Update on activity of the SGDB34.exe, when the computer restarts the file
name changes.

Thanks


Frank McCallister SBS MVP said:
Hi Carel

Do you have a Seiko or Minolta printer installed.

--
Frank McCallister SBS MVP
COMPUMAC
Carel said:
Today the SGDB34.exe program/process appeared in our Task Manager? Does
anyone know what it is?

Thanks for your help.

We are concerned since last two weeks it been different issues. Previous
two weeks had an infection of "mywife aka "WORM_GREW.A" CME-24,
Win32.Blackmal.F [Computer Associates], Email-Worm.Win32.Nyxem.e
[F-Secure], Email-Worm.Win32.Nyxem.e [Kaspersky], W32/MyWife.d@MM
[McAfee], W32/MyWife.d@MM!M24 [McAfee], Win32/Mywife.E@mm [Microsoft],
W32/Small.KI@mm [Norman], Tearec.A [Panda Software], W32/Nyxem-D
[Sophos], WORM_GREW.{A, B} [Trend Micro]...........)
 
D

David H. Lipman

From: "Carel" <[email protected]>

| Hi Frank,
|
| Yes we have two Minotla Printers installed.
|
| The Konica Magicolor 2300 DL & the KONICA MINOLTA PagePro 1350W. Last week
| we ordered & installed the optional Printer server for the KONICA MINOLTA
| PagePro 1350W.
|
| Update on activity of the SGDB34.exe, when the computer restarts the file
| name changes.
|
| Thanks


Please submit a sample of "SGDB34.exe" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:[email protected]?subject=SCAN

When you get the report, please post back the exact results.

Please *AVOID* going to http://safety.live.com/ it is a Beta and is junk. As a so-called
anti virus site it has the poorest catch rate in the industry. In a recent ad-hoc test it
only caught 58% of samples given it to scan. If Virus Total indicates it to be malware you
can be provided with quality AV vendor web sites to scan your computer such as Kaspersky and
Trend Micro or be given tools to scan the PC locally.
 
C

Carel

Well the report came back from VirusTotal. Here it is. Thanks

Virustotal
Server response

--------------------------------------------------------------------------------

Results of a file scan
This is a report processed by VirusTotal on 02/08/2006 at 22:02:27 (CET)
after scanning the file "SGDB34.EXE" file.
Antivirus Version ! Upda te Result
AntiVir 6.33.0.81 02.08.2006 Heuristic/Backdoor.Generic
Avast 4.6.695.0 02.07.2006 no virus found
AVG 718 02.08.2006 no virus found
Avira 6.33.0.81 02.08.2006 Heuristic/Backdoor.Generic
BitDefender 7.2 02.08.2006 no virus found
CAT-QuickHeal 8.00 02.08.2006 no virus found
ClamAV devel-20060126 02.07.2006 no virus found
DrWeb 4.33 02.08.2006 BACKDOOR.Trojan
eTrust-InoculateIT 23.71.71 02.08.2006 no virus found
eTrust-Vet 12.4.2071 02.08.2006 no virus found
Ewido 3.5 02.07.2006 no virus found
Fortinet 2.54.0.0 02.08.2006 no virus found
F-Prot 3.16c 02.07.2006 no virus found
Ikarus 0.2.59.0 02.08.2006 no virus found
Kaspersky 4.0.2.24 02.08.2006 no virus found
McAfee 4692 02.08.2006 no virus found
NOD32v2 1.1400 02.08.2006 no virus found
Norman 5.70.10 02.08.2006 no virus found
Panda 9.0.0.4 02.08.2006 no virus found
Sophos 4.02.0 02.08.2006 no virus found
Symantec 8.0 02.08.2006 no virus found
TheHacker 5.9.4.093 02.08.2006 no virus found
UNA 1.83 02.08.2006 no virus found
VBA32 3.10.5 02.08.2006 no virus found



VirusTotal is a free service offered by Hispasec Sistemas. There are no!
guarant ees about the availability and continuity of this service. Do not
reply to this message. It has been generated by an automatic address that
will not handle any reply. Although the detection rate afforded by the use
of multiple antivirus engines is far superior to that offered by just one
product, these results DO NOT guarantee the harmlessness of a file.
Currently, there is not any solution that offers a 100% effectiveness rate
for detecting viruses and malware.

Terms of use©1998-2005 Hispasec Sistemas.
 
D

David H. Lipman

From: "Carel" <[email protected]>

| Well the report came back from VirusTotal. Here it is. Thanks
|
| Virustotal
| Server response
|
| --------------------------------------------------------------------------------
|
| Results of a file scan
| This is a report processed by VirusTotal on 02/08/2006 at 22:02:27 (CET)
| after scanning the file "SGDB34.EXE" file.
| Antivirus Version ! Upda te Result
| AntiVir 6.33.0.81 02.08.2006 Heuristic/Backdoor.Generic
| Avast 4.6.695.0 02.07.2006 no virus found
| AVG 718 02.08.2006 no virus found
| Avira 6.33.0.81 02.08.2006 Heuristic/Backdoor.Generic
| BitDefender 7.2 02.08.2006 no virus found
| CAT-QuickHeal 8.00 02.08.2006 no virus found
| ClamAV devel-20060126 02.07.2006 no virus found
| DrWeb 4.33 02.08.2006 BACKDOOR.Trojan
| eTrust-InoculateIT 23.71.71 02.08.2006 no virus found
| eTrust-Vet 12.4.2071 02.08.2006 no virus found
| Ewido 3.5 02.07.2006 no virus found
| Fortinet 2.54.0.0 02.08.2006 no virus found
| F-Prot 3.16c 02.07.2006 no virus found
| Ikarus 0.2.59.0 02.08.2006 no virus found
| Kaspersky 4.0.2.24 02.08.2006 no virus found
| McAfee 4692 02.08.2006 no virus found
| NOD32v2 1.1400 02.08.2006 no virus found
| Norman 5.70.10 02.08.2006 no virus found
| Panda 9.0.0.4 02.08.2006 no virus found
| Sophos 4.02.0 02.08.2006 no virus found
| Symantec 8.0 02.08.2006 no virus found
| TheHacker 5.9.4.093 02.08.2006 no virus found
| UNA 1.83 02.08.2006 no virus found
| VBA32 3.10.5 02.08.2006 no virus found
|

OK thanx ! Only AntiVir/Avira (same AV engine) and DrWeb seem see that is a Backdoor
Trojan.

What I'd like you to do is re-name the file if possible, from; SGDB34.EXE to;
SGDB34.EXE.BAK

Then reboot the PC and submit it to Kaspersky. They are VERY quick to analyze the suspect
file and put out signatures for a given infector.
mailto:[email protected]

The following is a Multi AV Scanning tool that contains AV scanners from; McAfee, Sophos,
Trend Micro and Kaspersky. None of which have to pre-exist on your PC. Even though none of
these are presently recognizing this suspect Backdoor Trojan, it would be a good idea to
scan the PC.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm


* * * Please report back your results * * *
 
L

Les Connor [SBS Community Member - SBS MVP]

What A/V application do you have installed?

Note that Trend (for one) renames executables as a counter measure to
infections that may try and kill a statically named exe.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top