1.)
http://www.microsoft.com/technet/sec.../MS05-039.mspx installieren, wenn Du Win2000 hast
2.) Zitat von
http://de.trendmicro-europe.com/ente...WORM_SDBOT.COH
Lösung:
Restarting in Safe Mode
• On Windows 2000
1. Restart your computer.
2. Press the F8 key, when you see the Starting Windows bar at the bottom of the screen.
3. Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
• On Windows XP
1. Restart your computer.
2. Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
3. Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
Editing the Registry
This malware modifies the system's registry. Users affected by this malware may need to modify or delete specific registry keys or entries. For detailed information regarding registry editing, please refer to the following articles from Microsoft:
1. HOW TO: Backup, Edit, and Restore the Registry in Windows 2000
2. HOW TO: Back Up, Edit, and Restore the Registry in Windows XP and Server 2003
Removing Autostart Key from the Registry
Removing autostart key from the registry prevents the malware from executing at startup.
If the registry key below is not found, the malware may not have executed as of detection. If so, proceed to the succeeding solution set.
1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
2. Still in the left panel, locate and delete the key: HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>
Services>ILT
Restoring Modified Entries from the Registry
1. Still in the Registry Editor, in the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Security Center
2. In the right panel, locate and delete the following entries:
* UpdatesDisableNotify = "dword:00000001"
* AntiVirusDisableNotify = "dword:00000001"
* FirewallDisableNotify = "dword:00000001"
* AntiVirusOverride = "dword:00000001"
* FirewallOverride = "dword:00000001"
3. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Policies>Microsoft>
WindowsFirewall>StandardProfile
4. In the right panel, locate and delete the following entry:
EnableFirewall = "dword:00000000"
5. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Policies>Microsoft>
WindowsFirewall>DomainProfile
6. In the right panel, locate and delete the following entry:
EnableFirewall = "dword:00000000"
7. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>
Services>Lanmanserver>parameters
8. In the right panel, locate the delete the following entries:
* AutoShareWks = "dword:00000000"
* AutoShareServer = "dword:00000000"
9. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>
Services>Lanmanworkstation>parameters
10. In the right panel, locate and delete the following entries:
* AutoShareWks = "dword:00000000"
* AutoShareServer = "dword:00000000"
11. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Policies>Microsoft>
Windows>WindowsUpdate
12. In the right panel, locate and delete the entry:
DoNotAllowXPSP2 = "dword:00000001"
13. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>
Services>Messenger
14. In the right panel, locate the entry:
Start = "dword:00000004"
,,,
...