1. DLP Flash Christmas Competition + Writing Marathon 2024!

    Competition topic: Magical New Year!

    Marathon goal? Crank out words!

    Check the marathon thread or competition thread for details.

    Dismiss Notice
  2. Hi there, Guest

    Only registered users can really experience what DLP has to offer. Many forums are only accessible if you have an account. Why don't you register?
    Dismiss Notice
  3. Introducing for your Perusing Pleasure

    New Thread Thursday
    +
    Shit Post Sunday

    READ ME
    Dismiss Notice

Backdoor.Win32 IRCbot Problem

Discussion in 'Tech Support' started by Knox, Feb 23, 2009.

  1. Knox

    Knox The Last Remnant DLP Supporter

    Joined:
    Aug 11, 2006
    Messages:
    1,087
    Location:
    At the crossroad where the demon lies. Waiting to
    Apparently I have aquired a virus called Backdoor.Win32 IRCbot. I have been able to find little info on it and it keeps coming back no matter what I do. A little help would be most welcome.

    Scanned with AVG- Nothing found.
    Scanned with Avira- Nothing found.
    Scanned with COMODO- Found
    Scanned with Malwarebytes- Found
    Scanned with SUPERAntiSpyware- Found.

    Scanned and deleted the infected file. But about an hour later it came back again. I traced the original infection back to mIRC and then it moved into my System Volume information.
     
  2. KrzaQ

    KrzaQ Denarii Host DLP Supporter

    Joined:
    May 9, 2008
    Messages:
    1,404
    Location:
    Poland
    Get a bootable linux distribution, boot it, delete all instances of your malicious file, restart computer.
     
  3. Shezza

    Shezza Renegade 4 Life DLP Supporter

    Joined:
    Dec 12, 2005
    Messages:
    1,342
    Location:
    Australia
    ...or, if you have no idea how to do that, I suggest that you delete your system restore volumes. A lot of trojans/viruses/whatever do hide in there and it can be a pain in the arse to get out. Besides, if your restore points have a virus in them then you can't really restore to them, can you?


    Deleting System Restore points can be done through the standard Windows Clean Up tool. After that, I'd do the whole run of scans again in Safe mode.

    Twice.

    If that fails as well, then maybe you should just consider formatting if it's an option.
     
  4. nonjon

    nonjon Alumni Retired Staff

    Joined:
    Dec 1, 2005
    Messages:
    2,129
    I had to clean up an infected computer recently and found the geekpolice forums extremely helpful. Had a mod type guy replying and walking me through getting rid of a nasty rootkit. They've got some good tools and guides for detecting and removing stuff.

    A quick search on that particular problem sounds like it's four years old. I'd think that one could be removed relatively easily by now.
     
  5. Knox

    Knox The Last Remnant DLP Supporter

    Joined:
    Aug 11, 2006
    Messages:
    1,087
    Location:
    At the crossroad where the demon lies. Waiting to
    Well, After the 1337 skillz of KrzaQ failed to help my computer retarded ass delete it. I just formated. >_> Lost Photoshop and Watchmen again, for the third time ;_; But on a happy note. It seems to have gone. Hopefully for good. Knock on wood.
     
  6. Jamven

    Jamven Headmaster DLP Supporter

    Joined:
    Nov 2, 2006
    Messages:
    1,120
    Location:
    Hunting Bullwinkle's assassin
    3rd time? No external drive?
     
  7. jts360

    jts360 Second Year

    Joined:
    Apr 26, 2007
    Messages:
    74
    Sigh, most people regardless of advise just end up doing that.

    Yeah this sort of thing is a pain to fix, some more than others and it is only too easy to just say screw it and reformat the drives.

    While most infections can be purged without formating the drives, usually only tech support, computer shops or users of some skill will bother.
     
  8. Rain

    Rain Pirate Navigator of the 7 Seas

    Joined:
    Jun 5, 2005
    Messages:
    597
    Location:
    Adirondack Park, NY
    Eh, I got that virus/trojan plenty of times. Actually, always 'cause of mIRC so I just decided not to have the program. Since then, I was able to remove it and use java. It never seemed to do much, but I figured leaving it was a bad idea.

    Reformatting the drives wasn't exactly the best idea. I only do that when I have absolutely no options left. >_> Like it not allowing me to connect to the internet or something.
     
  9. Knox

    Knox The Last Remnant DLP Supporter

    Joined:
    Aug 11, 2006
    Messages:
    1,087
    Location:
    At the crossroad where the demon lies. Waiting to
    Eh, I don't really have anything on my computer that is important, Don't shop online, don't have any important family pictures. Most of what I have is Sigs, Comics, Manga, Shit like that. Can get that all again anyways so oh well. It's kind of liberating formatting. :| I get to do everything again, Kind of like going back in time.
     
  10. Midknight

    Midknight Middy is SPAI! DLP Supporter Retired Staff

    Joined:
    Apr 11, 2005
    Messages:
    8,958
    Location:
    NC
    OMFG you got Comodo antivirus to work? lol fucking things locks up my pc everytime I try to use it.
     
  11. Oz

    Oz For Zombie. Moderator DLP Supporter

    Joined:
    Jan 31, 2008
    Messages:
    9,028
    Gender:
    Female
    Location:
    Baile Átha Cliath
    Where the fuck did you download mIRC from? o_o
     
  12. Knox

    Knox The Last Remnant DLP Supporter

    Joined:
    Aug 11, 2006
    Messages:
    1,087
    Location:
    At the crossroad where the demon lies. Waiting to
    Middy: O_O Really? Works great on my laptop. Finds Adware and tracking cookies. Is awesome.

    Oz: Think I got it when I went to go download UPP, Vash claimed the site was legit, then BAM! Download it and has a trojan ;-; Should have listened to Syao.
     
  13. Oz

    Oz For Zombie. Moderator DLP Supporter

    Joined:
    Jan 31, 2008
    Messages:
    9,028
    Gender:
    Female
    Location:
    Baile Átha Cliath
    Lawl? NNS > UPP. @_@

    Also, when did you have the gender change?
     
  14. Knox

    Knox The Last Remnant DLP Supporter

    Joined:
    Aug 11, 2006
    Messages:
    1,087
    Location:
    At the crossroad where the demon lies. Waiting to
    CZ > NNS ;)

    And what are you talking about? o_O
     
  15. Snarf

    Snarf Squanchin' Party Bro! ~ Prestige ~ DLP Supporter

    Joined:
    Apr 27, 2007
    Messages:
    18
    Gender:
    Male
    Location:
    Forty-Six & 2
    High Score:
    1,832
    Location: At the crossroad where the demon lies. Waiting to make a deal
    Age: 18
    Gender: Female

    I think he's talking about that you vagina twat.
     
  16. Knox

    Knox The Last Remnant DLP Supporter

    Joined:
    Aug 11, 2006
    Messages:
    1,087
    Location:
    At the crossroad where the demon lies. Waiting to
    D: Wtf?! When did that happen?
     
  17. Jamven

    Jamven Headmaster DLP Supporter

    Joined:
    Nov 2, 2006
    Messages:
    1,120
    Location:
    Hunting Bullwinkle's assassin
    rofl, I would have thought that you would have been the first to notice that type of change :)
     
  18. nonjon

    nonjon Alumni Retired Staff

    Joined:
    Dec 1, 2005
    Messages:
    2,129
    I'm gonna go out on a limb here and say it probably happened around the time you blamed Vash for downloading a virus.

    Then again, you might have just been born that way and your parents flipped a coin.
     
  19. Midknight

    Midknight Middy is SPAI! DLP Supporter Retired Staff

    Joined:
    Apr 11, 2005
    Messages:
    8,958
    Location:
    NC
    Yeah, maybe it just doesn't like Vista 64, it's scan maybe half the system quick, but it'll choke the system on the bigger files. Avast, Kaspersky, etc, don't have the same problem.