View Full Version : Trojan Horse??
126,7
1st October 2004, 14:20
C: \System Volume Information\_restore{5AEDC462-42BB-B59E-CC161DCC86C3}\PR31\A0004709.exe
Trojan Horse IRC/BackDoor.SdBot.45.AZ
Anybody have an idea what that is? I am using anti virus from grisoft and it tells me that the above mentioned virus is on my pc, but when you run virus scan, it comes up clean. Even tried the online scan from trendmicro. Clean too.
AdAware comes up with nothing new either.....
How good is the XP SP2 Firewall? Good enough to use on its own?
Cheers
Ausatco
1st October 2004, 14:28
Can't help you with the possible Trojan, sorry.
XP's firewall restricts inbound traffic, BUT doesn't stop unauthorised outbound traffic. So if your malware IS a Trojan and starts sending your personal stuff out, like passwords, keystrokes, etc, then XP's firewall will let it.
ZoneAlarm, Outpost and others protect in both directions, so your best bet is to disable XP's firewall and use a good alternative.
AA
robontweb
1st October 2004, 14:51
I had that a few days ago.I dont know what it is or does but ran Grisoft anti virus and it was corralled in avg vault to keep it from harming other stuff.
AVG still sends messages that its there but new scan fails to find it. to get rid go to accessories and disable restore system points and then reactivate and set up new restore point.
thgis should get rid of the b*gger!!!!
redsnail
1st October 2004, 22:02
Just after rebuilding FRED (effing ridiculous electronic device) after a HD crash I got zapped by a trojan.
Trojan Horse IRC/Backdoor.SdBot.47.J :mad:
It looks like I have finally got rid of the rotten thing after a lot of work.
Now have reinstalled and updated my antivirus software, firewalls, popup killers and cookie munchers.
Once again, this has made me appreciate Apple OS X Panther!
126,7
2nd October 2004, 08:20
Funny thing, I installed yet another Antivirus and a new firewall. Suddenly I dont get the virus warning anymore.....Is it still there? I get the feeling that its a hoax and that AVG wants me to buy their completet packet. 3 different antiviruses dont find anything and report the system clean.....??!
Incidentally, this was all after I installed my new hard disc! Virtually same day!
ORAC
2nd October 2004, 08:36
BackDoor.SdBot (http://securityresponse.symantec.com/avcenter/venc/data/backdoor.sdbot.html) Symantec
E-Liam
2nd October 2004, 09:15
Hi 126,7,
As Robontweb has said, that particular virus is safely tucked away in a restore point. By it's very nature a restore point is locked away from any program, in case you need to restore to a previous point in time. The only way to kill off the virus is to switch off System Restore, run your AV and then create a new restore point.
See here (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039) for info on how to do this.
Cheers
Liam
Naples Air Center, Inc.
2nd October 2004, 22:31
126,7,
I am with Liam, you need to switch off System Restore in order to be able to remove the Trojan.
Take Care,
Richard
126,7
3rd October 2004, 12:04
Tks for the help everyone. I couldn't get rid of it even by switching the system restore off. So I undertook the good old format.:{
Naples Air Center, Inc.
3rd October 2004, 14:27
126,7,
A format is not a bad thing. At least your system is clean and fast. :ok:
Take Care,
Richard