PDA

View Full Version : How to get rid of Srizbi Bot?


Czarman
08-28-2008, 04:24 AM
We used Kaspersky and Trend Micro and it didn't work. Have any of you run in to this one before? I appreciate any suggestions.


Thanks,

Czarman

ootuoyetahi
08-28-2008, 01:56 PM
I would scan the infected computer with HijackThis (http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html) and analyze the log filefor suspicious entries.

pcgeek
10-10-2008, 11:59 AM
Hey Mate

:Ye I have had a couple of problems with it myself. I found the following pretty useful:If you locate and then proceed to delete these specific registry entries (regedit):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\RcpApi\"MachineNum" and also HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\windbg48.
You then need to make sure you block these urls:(replace [dot] in brackets with real dot)
www[dot]swinmaster[dot]com
www[dot]ebobuilt[dot]com
bu[dot]srizhopa[dot]biz,
www[dot]konskyvolos[dot]com
www[dot]zaibek[dot]com
208[dot]72.169.22,
208.72.168.143,
abr[dot]srizhopa[dot]biz

I think that prehaps you should find and delete these files 2.
%systemdir%\windbg48.sys
%profiledir%\scchost.exe
\scchost.exe

And you can proceed to restart your system.Hopefully this should help.The biggest irritation is that it just tends to keep on changing the file names ahhhh annoying!
I found that info here: http://www.pc1news.com/news/0236/srizbi-bot-how-to-remove-it-from-your-pc.html Srizbi Bot: How To Remove It From Your PC
and it may help you to also read http://www.pcworld.com/businesscenter/article/146017/srizbi_becomes_worlds_largest_botnet.html this pc article on
Srizbi Becomes world's largest Botnet.

I would also suggest the basics as well such as antivirus that is up to date , a decent firewall and prehaps reputable spyware software.
Good Luck Mate-hope this helps.:p