AVG keeps reporting to me that a Trojan horse exists named IRC/BackDoor.SdBot.ADM and to run the software to remove it. However this file is within the C:\System Volume Information folder presumably as a system restore file at a guess. Anyway the full path is: -
C:\System Volume Information\_restore{94FDA
FF8-0336-4
F8C-A406B3
D6DEF069D4
}\RP81\A00
05492.exe
If that helps :S
How the hell do i get rid of it ... have been browsing the net for ages and can not find anything useful about either the virus and what it could possibly be doing, or how to remove. I have recently removed the MyDoom virus which I managed to contract so dont know whether this has something to do with it.
Finally i have seen the following information everywhere related to virus removal solutions so thought i may as well give all the information i can, heres the Hijack log file for my current system : -
Logfile of HijackThis v1.97.7
Scan saved at 22:21:52, on 30/01/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\Grisoft\AVG6\a
vgserv.exe
C:\WINDOWS\System32\CTsvcC
DA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\No-IP\DUC20.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\PROGRA~1\NETWOR~1\ssh\c
ygrunsrv.e
xe
C:\PROGRA~1\Agnitum\OUTPOS
~1\outpost
.exe
C:\Program Files\NetworkSimplicity\ss
h\sshd.exe
C:\Program Files\RealVNC\WinVNC\WinVN
C.exe
C:\WINDOWS\System32\MsPMSP
Sv.exe
C:\WINDOWS\System32\Fast.e
xe
C:\WINDOWS\System32\tasksw
itch.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\System32\rundll
32.exe
C:\PROGRA~1\Grisoft\AVG6\a
vgcc32.exe
C:\Program Files\Java\j2re1.4.2_01\bi
n\jusched.
exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\RUNDLL
32.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Macromedia\Dreamweav
er MX 2004\Dreamweaver.exe
C:\DOCUME~1\nf1159\LOCALS~
1\Temp\~e5
d141.tmp
C:\DOCUME~1\nf1159\LOCALS~
1\Temp\~e5
d141.tmp
C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Macromedia\Fireworks
MX 2004\Fireworks.exe
C:\DOCUME~1\nf1159\LOCALS~
1\Temp\~e5
d141.tmp
C:\DOCUME~1\nf1159\LOCALS~
1\Temp\~e5
d141.tmp
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\nf1159\LOCALS~
1\Temp\Rar
$EX00.724\
HijackThis
.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.google.co.ukR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.google.co.ukR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://www.google.co.ukR1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.google.co.ukR1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://www.google.co.ukR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.google.co.ukR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.google.co.ukR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.google.co.ukR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://www.google.co.ukR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.google.co.ukO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIE
Helper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\tasksw
itch.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\SBAudigy\Pr
ogram\CTEa
xSpl.EXE /run
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVN
C.exe" -servicehelper
O4 - HKLM\..\Run: [Truefonts] C:\WINDOWS\Fonts\fonts.hta
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\a
vgcc32.exe
/STARTUP
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS
~1\outpost
.exe /waitservice
O4 - HKLM\..\Run: [uchiidf] "C:\WINDOWS\System32\uchii
df.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bi
n\jusched.
exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\manage
.exe
O4 - HKLM\..\RunServices: [windowsupdate] RPCX1sq234.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTR
AY.DLL,NvT
askbarInit
O4 - HKCU\..\Run: [regsrv32.exe] regsrv32.exe
O4 - Startup: Freeserve Broadband.lnk = ?
O4 - Global Startup: Freeserve Broadband.lnk = ?
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: Trashcan (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan (HKCU)
O12 - Plugin for .png: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n5.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://207.188.7.150/1631bbce564429d10622/netzip/RdxIE601.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E
099162EEEC
5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-0
0C04F9A3B6
1} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {A16E6189-A1DD-4696-9806-0
324C145D79
4} (KeyActivex Control) -
http://www.jraun.com/activex/src/KeyActivex.ocxO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {E0B795B4-FD95-4ABD-A375-2
7962EFCE8C
F} -
http://install.serviceurl.de/StarInstall.ocxO17 - HKLM\System\CCS\Services\T
cpip\..\{9
A6BF95C-29
19-4BF8-86
8C-79B888B
76A56}: NameServer = 195.92.195.94 195.92.195.95
Please help! :)
Start Free Trial