Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Trojan Horse??

Old 1st October 2004 | 14:20
  #1 (permalink)  
Thread Starter
 
Joined: Jul 2002
Posts: 975
Likes: 0
From: The frequency jungle
Trojan Horse??

C: \System Volume Information\_restore{5AEDC462-42BB-B59E-CC161DCC86C3}\PR31\A0004709.exe

Trojan Horse IRC/BackDoor.SdBot.45.AZ


Anybody have an idea what that is? I am using anti virus from grisoft and it tells me that the above mentioned virus is on my pc, but when you run virus scan, it comes up clean. Even tried the online scan from trendmicro. Clean too.
AdAware comes up with nothing new either.....

How good is the XP SP2 Firewall? Good enough to use on its own?

Cheers
126,7 is offline  
Old 1st October 2004 | 14:28
  #2 (permalink)  
 
Joined: Sep 1998
Posts: 513
Likes: 0
From: Sydney, Australia
Can't help you with the possible Trojan, sorry.

XP's firewall restricts inbound traffic, BUT doesn't stop unauthorised outbound traffic. So if your malware IS a Trojan and starts sending your personal stuff out, like passwords, keystrokes, etc, then XP's firewall will let it.

ZoneAlarm, Outpost and others protect in both directions, so your best bet is to disable XP's firewall and use a good alternative.

AA
Ausatco is offline  
Old 1st October 2004 | 14:51
  #3 (permalink)  
 
Joined: Aug 2004
Posts: 2
Likes: 0
From: Ashton-U-Lyne
Trojan Horse Virus

I had that a few days ago.I dont know what it is or does but ran Grisoft anti virus and it was corralled in avg vault to keep it from harming other stuff.
AVG still sends messages that its there but new scan fails to find it. to get rid go to accessories and disable restore system points and then reactivate and set up new restore point.
thgis should get rid of the b*gger!!!!
robontweb is offline  
Old 1st October 2004 | 22:02
  #4 (permalink)  

PPRuNe Handmaiden
50 Countries Visited
25 Anniversary
 
Joined: Feb 1997
Posts: 4,913
Likes: 184
From: Duit On Mon Dei
Just after rebuilding FRED (effing ridiculous electronic device) after a HD crash I got zapped by a trojan.
Trojan Horse IRC/Backdoor.SdBot.47.J

It looks like I have finally got rid of the rotten thing after a lot of work.
Now have reinstalled and updated my antivirus software, firewalls, popup killers and cookie munchers.

Once again, this has made me appreciate Apple OS X Panther!
redsnail is offline  
Old 2nd October 2004 | 08:20
  #5 (permalink)  
Thread Starter
 
Joined: Jul 2002
Posts: 975
Likes: 0
From: The frequency jungle
Funny thing, I installed yet another Antivirus and a new firewall. Suddenly I dont get the virus warning anymore.....Is it still there? I get the feeling that its a hoax and that AVG wants me to buy their completet packet. 3 different antiviruses dont find anything and report the system clean.....??!
Incidentally, this was all after I installed my new hard disc! Virtually same day!
126,7 is offline  
Old 2nd October 2004 | 08:36
  #6 (permalink)  
Ecce Homo! Loquitur...
Community Influencer
 
Joined: Jul 2000
Aviation Qualifications: Spotter
Posts: 24,631
Likes: 7,338
From: Peripatetic
BackDoor.SdBot Symantec
ORAC is online now  
Old 2nd October 2004 | 09:15
  #7 (permalink)  
 
Joined: Jan 2004
Posts: 357
Likes: 0
From: Bracknell UK
Hi 126,7,

As Robontweb has said, that particular virus is safely tucked away in a restore point. By it's very nature a restore point is locked away from any program, in case you need to restore to a previous point in time. The only way to kill off the virus is to switch off System Restore, run your AV and then create a new restore point.

See here for info on how to do this.

Cheers

Liam
E-Liam is offline  
Old 2nd October 2004 | 22:31
  #8 (permalink)  
The Oracle
 
Joined: Aug 2001
Posts: 2,902
Likes: 0
From: Naples, Florida U.S.A.
126,7,

I am with Liam, you need to switch off System Restore in order to be able to remove the Trojan.

Take Care,

Richard
Naples Air Center, Inc. is offline  
Old 3rd October 2004 | 12:04
  #9 (permalink)  
Thread Starter
 
Joined: Jul 2002
Posts: 975
Likes: 0
From: The frequency jungle
Tks for the help everyone. I couldn't get rid of it even by switching the system restore off. So I undertook the good old format.
126,7 is offline  
Old 3rd October 2004 | 14:27
  #10 (permalink)  
The Oracle
 
Joined: Aug 2001
Posts: 2,902
Likes: 0
From: Naples, Florida U.S.A.
126,7,

A format is not a bad thing. At least your system is clean and fast.

Take Care,

Richard
Naples Air Center, Inc. is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Thread Tools
Search this Thread

Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.