• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Virus Alert - Rbot variant

SagaLore

Elite Member
We got a few machines that showed up with a virus infection that Symantec will not detect. It's rather simple too. A process "Svhost.exe" runs from either c:\winnt\system32\Svhost.exe (or \windows\system32), or as a prefetch file (.pf extension). In the registry Run key, it just load Svhost.exe with the name "Windows Update".

It's very easy to remove - just end the process, delete the file, and delete the reg entry. Then run Windows Update and install all critical fixes.

What I can't figure out is why the major antivirus vendors are not detecting such a simple variant. I was able to upload a sample file to kaspersky and have it analyzed as Backdoor.Win32.Rbot.hf, but it's an incorrect analysis. The description of that variant does not match the characteristics of what we're seeing.

If any one else catches this please let me know what you find out.

I moved this notice to: sdbot variant - no detection? We found out that this thing is talking back to the same public server and possibly waiting for instructions. I contacted the owners of the server to see if they would remove it from the public.
 
Back
Top