PPRuNe Forums - View Single Post - Trojan Horse IRC/BackDoor.SdBot.MYX
View Single Post
Old 11th November 2005 | 10:27
  #2 (permalink)  
Spinflight
 
Joined: Jul 2005
Posts: 82
Likes: 0
From: Lv426
I've had a similar one MTOW, an IRC.backdoor.sdbot anyway . It is pretty nasty, basically allows someone to control your computer through IRC. Generally its used to launch DOS attacks or similar.

It was a while back but I finally nailed it in safe mode by sifting through recently modified files. None of the anti-virus packages I used picked it up. It would launch from system32/dllcache though if you deleted that then it would re-appear a couple of boots later. I'm afraid I can't remember where I found the 'mothership' virus if you like, in all it took me over a month I reckon.
Spinflight is offline