Link to home
Start Free TrialLog in
Avatar of wtolmie
wtolmie

asked on

Is SYSCFG32.exe a valid Windows 2000 File ?

InoculateIT is telling me I have a Backdoor/SDBot.05.A.Server trojan within the syscfg32.exe file contained within teh C:\winnt\system32 Folder.     Can I delete it ??  I cannot repair it, Trojan Remover doesnt even detect it..

Any thoughts ???
Avatar of CrazyOne
CrazyOne
Flag of United States of America image

F-Secure Virus Descriptions
http://www.f-secure.com/v-descs/lolol.shtml

While installing the worm copies itself to Windows system directory with the "syscfg32.exe" name and registers that file in two system registry auto-run keys:


 HKLM\Software\Microsoft\Windows\CurrentVersion\Run
   Configuration Loader = syscfg32.exe


 HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
   Configuration Loader = syscfg32.exe

ASKER CERTIFIED SOLUTION
Avatar of CrazyOne
CrazyOne
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
You may have to reboot after removing the entries from the registry before you can delete the file.
Avatar of wtolmie
wtolmie

ASKER

Thankyou Crazyone..  Always fast to respond..!!!!
You are welcome. :>)