DaniWeb IT Discussion Community

DaniWeb IT Discussion Community (http://www.daniweb.com/forums/index.php)
-   Viruses, Spyware and other Nasties (http://www.daniweb.com/forums/forum64.html)
-   -   Trojan: IRC/SdBot.AFN (http://www.daniweb.com/forums/thread6435.html)

webtor May 30th, 2004 6:08 am
Trojan: IRC/SdBot.AFN
 
This is a moving target.

Have observed morphing.

SYS32 item that seemingly does not have
an identifiable fixtool that I can find with
my resources.

Have discovered a remedy that 'tricks' this
SYS32 problem with non-hacking.

Have yet to fully identify the original exposure
date of this critter.http://www.daniweb.com/techtalkforum...cons/icon4.gif

Feed back from within this domain is invited

Catweazle May 30th, 2004 7:03 am
Re: Trojan: IRC/SdBot.AFN
 
NOD32 AntiVirus should be able to clean that one - it's included in the signature file for it!

webtor May 30th, 2004 7:52 am
Re: Trojan: IRC/SdBot.AFN
 
Quote:

Originally Posted by Catweazle
NOD32 AntiVirus should be able to clean that one - it's included in the signature file for it!

A very embarassing response for me to recieve.
I rely on NOD32.

SIT: as reported
File C:\WINDOWS\System32\navmgrd.exe is infected with a trojan
IRC/SdBot.AFN.
SIT: Newly reinstalled Zonelabs 4.0 reports that navmgrd.exe is
attempting to act as a server.
SIT: NOD32 reports that it cannot clean this infiltration.
SIT: This is kind of tough!!
SIT: NOD32 has allready recieved a pointed comm from
me on this sit ( allways polite ).

Spent time with other issues this past week that seem to point back to
this same item. http://www.daniweb.com/techtalkforum...cons/icon4.gif

Catweazle May 30th, 2004 8:00 am
Re: Trojan: IRC/SdBot.AFN
 
NOD32 can't clean it because it's a trojan. Delete instead! There's quite a few other AntiVirus packages which should be able to deal with it, as far as I can determine. I doubt if any of them would clean rather than delete, though.

webtor May 30th, 2004 8:19 am
Re: Trojan: IRC/SdBot.AFN
 
Quote:

Originally Posted by Catweazle
NOD32 can't clean it because it's a trojan. Delete instead! There's quite a few other AntiVirus packages which should be able to deal with it, as far as I can determine. I doubt if any of them would clean rather than delete, though.

I trust that we are not both moving too fast for each other.
I repeat, this is a moving target.
Is a morphing item.
Have scanned and observed how quickly it has taken on other
nuances.

Catweazle May 30th, 2004 8:28 am
Re: Trojan: IRC/SdBot.AFN
 
heh heh..... Looks like it's me standing still, I reckon. I'll leave this to others more knowledgeable than myself. All I know is NOD32 has never let me down, and I've seen reference to its signature files including mention of this particular trojan.

**** whistles and wanders off, awaiting developments......

:D

caperjack May 30th, 2004 8:38 am
Re: Trojan: IRC/SdBot.AFN
 
A goolgle search of navmgrd.exe ,show these , http://www.google.com/search?sourcei...=navmgrd%2Eexe ,

Catweazle May 30th, 2004 8:54 am
Re: Trojan: IRC/SdBot.AFN
 
That's what I did caperjack.

The Google results indicate NOD32 has included this trojan in their signature files since version V.1.730

webtor Jun 1st, 2004 3:25 am
Re: Trojan: IRC/SdBot.AFN
 
Quote:

Originally Posted by Catweazle
NOD32 AntiVirus should be able to clean that one - it's included in the signature file for it!

Traded emails with "SOURCE".
"Source" gave me advices.
Decided to go my own way and had a VERY,VERY,VERY successful resolution
without future compromises.
This was a GREAT learning experience and has given me
a whole new *^killer*^ marketing approach / perspective
on the AV industry. BIGTIME!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!:cool: :cool: :cool: :cool: :cool: :cool:

webtor Jun 1st, 2004 3:32 am
Re: Trojan: IRC/SdBot.AFN
 
Quote:

Originally Posted by Catweazle
NOD32 can't clean it because it's a trojan. Delete instead! There's quite a few other AntiVirus packages which should be able to deal with it, as far as I can determine. I doubt if any of them would clean rather than delete, though.

My path of travel on this whole manouver was creative without hacking skills.
Had to tell 'others' how to do their job as part of the remedy.
We accomplished our 'mission'.:cool: :cool: :cool: :cool: :cool: :cool:


All times are GMT -4. The time now is 7:33 am.

Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC