Spyware, Viruses, & Security forum

General discussion

sndmon32.exe ??

by hcweb / September 23, 2004 7:02 AM PDT

We have an issue with a file named sndmon32.exe. After exhaustive searches on the internet, we have found absolutely nothing on this file name.

It resides under \%windir%\system32\. A process of the same name also runs which seems to be maxxing out the processor. In some instances there are more than one instance of this process. It seems that certain infected machines will attempt a DOS attack on microsoft but is unable to get out from behind our firewall, which in turn, pretty much hammers the network. There are several instances of the same file name in the registry under sound manager, but we know this is not the true sound manager.

We have figured out how to stop it to a point, but I'm unsure of what it is, and how to properly clean this. If anyone has seen or heard of anything, I'd appreciate knowing about. We have already contacted several anti-virus companies in hopes of finding out what it is, but haven't received any responses yet.

Any help would be greatly appreciated!

Chris

Discussion is locked
You are posting a reply to: sndmon32.exe ??
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: sndmon32.exe ??
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Collapse -
Re: sndmon32.exe ??
by Marianna Schmudlach / September 23, 2004 7:28 AM PDT
In reply to: sndmon32.exe ??
Collapse -
Re: sndmon32.exe ??
by hcweb / September 23, 2004 8:17 AM PDT
In reply to: Re: sndmon32.exe ??

Thanks Marianna.

Kaspersky found and identified Backdoor.Win32.WootBot.Gen in the aforementioned file. Now I just need to gather some more info on it. Thanks a million!

Chris

Collapse -
Re: sndmon32.exe ??
by Marianna Schmudlach / September 23, 2004 8:44 AM PDT
In reply to: Re: sndmon32.exe ??

Hi Chris,

You're Welcome !

Manual disinfection for Wootbot backdoor requires renaming of an infected file, usually located in Windows or Windows System folder and restarting a system. Please note that the backdoor's file may have read-only, system and hidden attributes, so Windows Explorer has to be configured to show such files.

If the infection is in a local network, please follow the instructions on this webpage:

http://www.f-secure.com/v-descs/netdisinf.shtml

http://www.f-secure.com/v-descs/wootbot.shtml

Collapse -
Re: sndmon32.exe ??
by hcweb / September 23, 2004 9:46 AM PDT
In reply to: Re: sndmon32.exe ??

Marianna,
We've had really good luck with starting the machine in safe mode, then deleting the file. While in safe mode, we've done a search on sndmod32.exe in the registry and found roughly 6 instances. We then deleted all references in the registry, restarted the machine as admin, then applied all pertinent security updates.

I noticed this is new (i.e.: first sighting 9/17/2004) and that f-secure is the only site that has any real details on it. We use F-Prot as desktop anti-virus (tied in with f-secure somehow) but, f-prot only sees the file as suspicous and therefore will not delete it since it cannot identify it.

Thanks for your help!

Chris

Collapse -
Re: sndmon32.exe ??
by Marianna Schmudlach / September 23, 2004 9:51 AM PDT
In reply to: Re: sndmon32.exe ??

Chris,

You're Welcome - glad to hear everything went well and you got rid of it !

Collapse -
Re: sndmon32.exe ??
by viperone / September 24, 2004 3:31 PM PDT
In reply to: sndmon32.exe ??
Collapse -
Re: sndmon32.exe ?? how to remove Safely
by Excks / October 18, 2004 11:22 PM PDT
In reply to: sndmon32.exe ??

been running my system long time now and out of the blue had this thing show, didn't show up in task manager but connected to the net 15 times at once messed up my internet along with other things plus it likes to mask itself as a microsoft process
Steps Took
1 copied file to encrypted closed contain so
on reboot it couldn't connect to the net
(backup and testing reasons only)
2 There is an great free program called
moveonboot (http://gibinsoft.net/)install
that program its kb's in size works on xp
as well once installed right click that
little sucker and delete on boot
3 Now that its gone windows may complain
that its gone myself i used the free
regclean program from microsoft and ran
it bing badda boom problem solved (i tried
to find it on the microsoft site recently
with no luck (could have been removed?) or
you might have better luck but i also
recommend the ashampoo winoptimizer suite
(regcleaner in there is good)or use jv16
powertools but do manual search for the
the entries jv16 somtimes cleans too
well when automated)

P.S. Advice is good but Better Practice is to
Always backup system Files and important
Documents!!!!

Collapse -
Re: sndmon32.exe ??
by anncamp / December 7, 2004 12:15 PM PST
In reply to: sndmon32.exe ??

i have same problem, and nothing i have picks it up, not norton, ad aware. i cant get rid of it. have you got any responce yet

Popular Forums

icon
Computer Newbies 10,686 discussions
icon
Computer Help 54,365 discussions
icon
Laptops 21,181 discussions
icon
Networking & Wireless 16,313 discussions
icon
Phones 17,137 discussions
icon
Security 31,287 discussions
icon
TVs & Home Theaters 22,101 discussions
icon
Windows 7 8,164 discussions
icon
Windows 10 2,657 discussions

FALL TV PREMIERES

Your favorite shows are back!

Don’t miss your dramas, sitcoms and reality shows. Find out when and where they’re airing!