Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Irc/backdoor.sdbot2.kye


  • Please log in to reply
2 replies to this topic

#1 DXT

DXT

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:14 AM

Posted 02 March 2007 - 09:34 AM

Hi everyone, I'm new here :thumbsup:

My OS (winxp sp2) has recently started to act very strange and I am suspecting that I have a trojan or a backdoor.

Every while and then AVG pops up with a message that it had found irc/backdoor.sdbot2.kye in an eraseme_58037.exe file located in C:\Windows (the number after eraseme_ keeps changing).

It returns again and again although I am deleting this file or moving it into vault.

S&D doesn't find anything, and nothing comes up in a full computer scan in AVG (only when it detects the eraseme file again).

What can I do?

Thanks, Michael.

BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,116 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:02:14 AM

Posted 02 March 2007 - 09:40 AM

Install Super Antispyware. Run it in safe mode. Allow it to quarantine whatever it finds.
http://www.superantispyware.com/

Run the online scan for Bit Defender in normal mode. Allow it to quarantine whatever it finds.
http://www.bitdefender.com/scan8/ie.html

Post a Hijack This log in the appropriate forum by following the directions in the link below.
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/
“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 DXT

DXT
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:14 AM

Posted 02 March 2007 - 01:47 PM

Thank you for your reply, I will follow these steps right away.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users