These entries below are SDBot variants:
O4 - HKLM\..\Run: [Microsoft Updates] svdhost.exe
O4 - HKLM\..\RunServices: [Microsoft Updates] svdhost.exe
1. Download SDFix and save it to your desktop.
http://downloads.andymanch
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.
* Open the extracted folder and double click "RunThis.bat" to start the script.
* Type "Y" to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back
Also run this tool afterwards.
2. Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforu
http://download.bleepingco
Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Main Topics
Browse All Topics





by: rindiPosted on 2007-08-26 at 04:04:46ID: 19770647
Get rid of the following, if they are still there after you have tried removing them with hijakthis after a reboot, use a liveCD like the UBCD4WIN and search for the file svdhost.exe and rename it or move it away:
32B190E9B0 7} - C:\Program Files\Skype\Toolbars\Inter net Explorer\SkypeIEPlugin.dll (file missing)
89413833-7 55988637-1 003\..\Run : [Power2GoExpress] NA (User '?') 89413833-7 55988637-1 003\..\Run : [Aim6] (User '?')
http://ubcd4win.com
O4 - HKLM\..\Run: [Microsoft Updates] svdhost.exe
O4 - HKLM\..\RunServices: [Microsoft Updates] svdhost.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D
If you know the below software and trust it, then leave it, if not use hijackthis to remove them:
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKUS\S-1-5-21-2491041210-6
O4 - HKUS\S-1-5-21-2491041210-6
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User '?')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')