Remove Sdbot-XK. Description and removal instructions

 
Title: Sdbot-XK
Also known as: W32/Sdbot-XK, Backdoor.Win32.Agent.iy
Type: Worms
Severity scale:Sdbot-XK severity is 28  (28 / 100)
 
Sdbot-XK is a network worm which provides backdoor access to the infected computer. Usually, it spreads by exploiting LSASS, RPC DCOM, WorKStation service, Microsoft SQL Server 2000 (pre service pack 3) vulnerabilities and Microsoft SQL servers with weak passwords. Once installed, Sdbot XK will move itself to the Windows system folder as b.exe. The worm will modify certain Registry values, so that it could run automatically each time you log on to Windows.

W32/Sdbot-XK stays resident in background and provided back door access to the infected computer over IRC channels. What is more, this worm will attempt to disable the Windows Internet Connection Firewall, Automatic Updates and Security Center. It may also modify your HOST file and block anti-virus websites. If you find, that your computer is infected with this worm, please use the removal guide below to remove Sdbot-XK from your computer.



Related files: b.exe, msdirectx.sys

Sdbot-XK properties:
• Allows remote user connection
• Hides from the user
• Stays resident in background

Automatic Sdbot-XK removal:

remover for Sdbot-XK

Sdbot-XK manual removal:

Kill processes:
b.exe
Delete registry values:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run b.exe b.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices b.exe b.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run b.exe b.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices b.exe b.exe
HKLM\SYSTEM\CurrentControlSet\Services\msdirectx
HKCU\SYSTEM\CurrentControlSet\Control\Lsa b.exe b.exe
HKCU\Software\Microsoft\OLE b.exe b.exe
HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1
Delete files:
b.exe MSDIRECTX.SYS

Other programs to remove Sdbot-XK:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 13/07/09
Information updated: 18/08/09

Additional resources related to Sdbot-XK:

Attention: If you know or you have a website or page about Sdbot-XK removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Sdbot-XK parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by . 2009-08-18 10:08:23
hope it works,


Latest spyware news:
Similar parasites:
Related discussions: