Re: svchosting.exe -> Backdoor.Sdbot

From: Jurren Bouman (jurren_at_hotmail.com)
Date: 07/30/04


Date: Fri, 30 Jul 2004 10:22:13 +0200

Ken wrote:

> Got totally caught by this guy yesterday. Slammed most
> of my machines. Network came to a hault. Now many of my
> servers won't show their IPC$ shares. You can "net share
> ipc$" but that will only bring it back for a few minutes
> and then it goes away again. Still misterious dropped
> connections with servers even with good network response
> and ping times.

See:
http://vil.nai.com/vil/content/v_99410.htm
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html

Removal tool:
"McAfee AVERT Stinger"
http://vil.nai.com/vil/stinger/

-- 
Jurren Bouman
MVP Security - Windows
"Microsoft Trustworthy Computing: Security"
http://www.microsoft.com/security/default.mspx


Relevant Pages

  • svchosting.exe -> Backdoor.Sdbot
    ... Network came to a hault. ... servers won't show their IPC$ shares. ...
    (microsoft.public.security.virus)
  • Re: Dcidag errors
    ... Port blockage between servers ... Other sorts of networking issues (lack of connectivity between the points ... These errors are typically a result of a network connectivity issue of some ... > replicating this nc. ...
    (microsoft.public.windows.server.active_directory)
  • Re: I need Job Blobb
    ... > Windows and Network administratation. ... > In a job I would like to administrate servers, ... > Title: ISP Network Administrator ... > o Building, installation, configuration and tuning ...
    (microsoft.public.cert.exam.mcse)
  • Re: I need Job Blobb
    ... > Windows and Network administratation. ... > In a job I would like to administrate servers, ... > Title: ISP Network Administrator ... > o Building, installation, configuration and tuning ...
    (microsoft.public.cert.exam.mcse)
  • Event Viewer Networking Connectivity
    ... What we need is a very solid working network. ... Here's what lead up to this scenario of BDC replacement. ... On the corporate side I can see our servers. ... Registration of the DNS record ...
    (microsoft.public.windows.server.networking)

Loading