trojan horse IRC/Backdoor.SdBot.???

Discussion in 'Malware Help (A Specialist Will Reply)' started by duster, Jan 21, 2006.

  1. duster

    duster Private E-2

    guys i have a virus in my C:\Windows\System32 folder just now. AVG detected it and it is causing my pc to function very slowly!

    by the way there are 2 of them named trojan horse IRC/Backdoor.SdBot.PVN!

    btw, i tried to run bitdefender and pandascan but they run sooo slow that it goes on for 3 hours and it isn't even halfway scanning! could be the virus affecting my connection.

    well here is a hijack log for you. Please find the time to help me! Thanks!

    ~ IN-LINE LOG ATTACHED ~ SPD

    any help would be greatly appreciated!
     

    Attached Files:

    • HJT.txt
      File size:
      5.7 KB
      Views:
      3
    Last edited by a moderator: Jan 21, 2006
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Do not copy & paste logs into your posts; always include them as attachments.

    You have 2 Antivirus applications installed and resident; AVG Free and AntiVir Personal. Pick one uninstall the other.

    You have no software firewall installed; this represents a serious security risk.

    Uninstall LimeWire.

    Welcome to MajorGeeks.com!

    Please follow forum guidelines and perform cleaning steps in the sticky thread before posting HijackThis logs.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:


    Downloading, Installing, and Running HijackThis
     
    Last edited: Jan 21, 2006
  3. duster

    duster Private E-2

    pls check my lhijack log!

    hi guys! sorry about my 1st post i wasn't paying attention to the rules.. again my apologies!

    ok so here is my problem! this started 3 days ago when i received an alert from AVG that i have a virus in my windows/stsem32 folder(some files like msapp32.exe and others). i did all the precautionary and diagnostic programs and deleted all found problems. well i just wanted to make sure that my hijack log is clean and good to go so please find the time to check it out! thanks!
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your operating System is extremely out-of-date. You reaaly need to install SP2 and then run Windows Update to bring your system current. As it is now represents a serious security risk.

    Do you now what program this is, REGVGA.EXE; and what it does?

    Scan with HijackThis and fix the following:
    Post a fresh HijackThis log, and post the other 2 logs from the tutorial.
     
  5. duster

    duster Private E-2

    REGVGA.EXE = no idea what this is!

    here's my bitdefender, pandascan and hijack logs:
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Locate REGVGA.EXE, right-click on the file select properties, click-on the Version button. Under Other version information, click-on the Company. Who makes teh file? This could be related to your video card.

    Locate D:\My Downloads\My Downloads\backups\backup-20050822-002936-690.inf and delete it.

    Follow the directions for Running Ewido Security Suite.

    Post the Ewido log.
     
  7. duster

    duster Private E-2

    i can't check the version of REGVGA.EXE. weird!

    ok here is my ewido scan result!
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    REGVGA.EXE is very likely related to your video card. Leave it on your system.

    Other that that you logs look pretty clean.

    Empty Firefox's cache and that will clear the cookies found by Panda.

    How is your computer running?
     
  9. duster

    duster Private E-2

    right now it's doing A-OK! if a problem surfaces within the next few days i'll let you know! so far no alerts from AVG. thanks man!
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds