Author Topic: Win32:SdBot-gen28 infected hiberfil.sys and pagefie.sys?  (Read 6681 times)

0 Members and 1 Guest are viewing this topic.

mariosalice

  • Guest
Win32:SdBot-gen28 infected hiberfil.sys and pagefie.sys?
« on: October 07, 2007, 09:11:40 AM »
I did a full Avast scan.
I have Windows Vista 64 installed twice on two hard drives.
The fist one is a two 250GB Sata RAID-0 array.
The second one is a single 250GB Sata drive.
I boot from the single drive and Avast detects the hiberfil.sys (6GB) and pagefie.sys (4GB) system files are infected with trojan Win32:SdBot-gen28
I delete both files.
When I boot from the raid array Vista recreates both files.
A full Avast scan reveals my system is clean on both hard disks (the hibefil.sys and pagefile.sys files on my single disk are both clean).
When I boot from the second (single) drive, the full scan reveals again that both files on the raid-0 array are infected with the same virus.

I do not know how I got this virus. I always keep a virus protection on and I have Avast for the last four years.
The error message about the virus found is always the same.

Could this be a fault alert because of the way raid-0 splits each file on two disks?
Then why two files seem to be infected with the same virus?
I have no more clues.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33891
  • malware fighter
Re: Win32:SdBot-gen28 infected hiberfil.sys and pagefie.sys?
« Reply #1 on: October 07, 2007, 03:20:42 PM »
Hi Mariosalice,

Download SDFix from the link below and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

    * Please then reboot your computer in Safe Mode by doing the following :
    * Restart your computer
    * After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    * Instead of Windows loading as normal, the Advanced Options Menu should appear;
    * Select the first option, to run Windows in Safe Mode, then press Enter. Choose your usual account.
    * Open the extracted SDFix folder and double click RunThis.bat to start the script.
    * Type Y to begin the cleanup process.
    * It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    * Press any Key and it will restart the PC.
    * When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    * (Report.txt will also be copied to Clipboard ready for posting back on the forum). Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

mariosalice

  • Guest
Re: Win32:SdBot-gen28 infected hiberfil.sys and pagefie.sys?
« Reply #2 on: October 08, 2007, 02:53:39 AM »
"sdfix" doesn't run under Vista.
As I said I had no viruses on the single disk.
It has a brand new clean Vista installation.
I had checked the pagefile.sys and it was OK.
Though after hibernation, Avast run from my old raid-0 installation, reports a different Virus (dialer-DW) on pagefile.sys file !
Hiberfil.sys is clean on this disk.
This is crazy.

Thank you.


Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67195
Re: Win32:SdBot-gen28 infected hiberfil.sys and pagefie.sys?
« Reply #3 on: October 08, 2007, 03:18:31 AM »
Though after hibernation, Avast run from my old raid-0 installation, reports a different Virus (dialer-DW) on pagefile.sys file! Hiberfil.sys is clean on this disk. This is crazy.
I don't think this is crazy... just a false positive... generally infections of pagefile.sys are false positives.
This file is 'discarded' each time the computer boots... so, quite some antivirus add this file to the exclusion lists.

Anyway, thanks for reporting. Hope they correct this detection soon.
The best things in life are free.

mariosalice

  • Guest
Re: Win32:SdBot-gen28 infected hiberfil.sys and pagefie.sys?
« Reply #4 on: October 08, 2007, 02:34:49 PM »
Thank you once again for your great job.
You really help ppl here in this forum and all around the world with your great Avast antivirus.