Remove Sdbot.add. Description and removal instructions

 
Title: Sdbot.add

Type: Worms
Severity scale:Sdbot.add severity is 75  (75 / 100)
 
Sdbot.add is a dangerous widely spread worm that propagates mostly through unprotected network shares found on a local network. Once executed, the parasite drops a rootkit that allows the remote intruder to break into the infected system. Sdbot.add also runs a backdoor controlled through the IRC network. This backdoor gives the attacker unauthorized remote access to a compromised computer and allows to control it. Sdbot.add secretly runs on every Windows startup.


Sdbot.add properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Sdbot.add removal:

remover for Sdbot.add

Sdbot.add manual removal:

Kill processes:
lockx.exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\stratas=lockx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\stratas=lockx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\stratas=lockx.exe
Delete files:
lockx.exe, xz.bat, msdirectx.sys
Misc:
Sdbot.add files should be located in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32, C:\Winnt\System32.

Other programs to remove Sdbot.add:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 19/10/05
Information updated: 27/11/06

Additional resources related to Sdbot.add:

Attention: If you know or you have a website or page about Sdbot.add removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Sdbot.add parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Guest. 2006-03-31 17:03:04
Goodsite-recpect! Webmaster recpect! Good work.buy phentermine

2. by Guest. 2006-01-17 23:01:25
I really appreciate your website. All important details are included. Fine design!


Related news:
Similar parasites: