SDFix as IndiGenus suggested will remove all SDBot related nasties in the system,
IF problem persists after running SDFix, you might like to run Combofix as well or other scanners in addition to SDFix, in case SDFix won't remove some of the trojans below.
Troj/DllLoad-C
O23 - Service: Application that interactively manages NT services (svcmngr) - Unknown owner - C:\WINDOWS\config\config.e
O23 - Service: MsSecurity (MsSecurity1.203.2) - Unknown owner - C:\WINDOWS\wllv.exe
O23 - Service: Universal Serial Bus Control Control (UniSerialControlCNT) - Unknown owner - C:\WINDOWS\restore\host\ex
Please download ComboFix by sUBs:
http://download.bleepingco
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply along with a fresh HJT log
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Main Topics
Browse All Topics





by: IndiGenusPosted on 2008-05-12 at 16:09:49ID: 21551214
Hi,
esta.com/R emovalTool s/SDFix.ex e
Download SDFix (by Andy Machesta) and save it to your Desktop.
http://downloads.andymanch
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Open the SDFix folder and double click on RunThis.bat to start the script.
Type Y and press Enter to begin the script.
It will start cleaning your PC and then prompt you to press any key to Reboot.
Press any key to restart the PC.
Your system will take longer than normal to restart as the fixtool will be removing files.
When the desktop loads the Fixtool will complete the removal and display Finished.
Press any key to end the script and to load your desktop icons.
A text file should automatically open,
Please do not post the log into the comment window. Use "Attach File" under the comment window to post the log.
Please also upload a fresh HijackThis log.