Forum Home
Press F1
 
Thread ID: 47827 2004-08-06 22:48:00 trojan horse backdoor.hacdef.c lpaint (5949) Press F1
Post ID Timestamp Content User
259031 2004-08-08 11:16:00 Maybe a far off guess...............are you running WindowsME or WindowsXP. Both have a System Restore. While a AV Program will scan inside the system restore folder, it will not remove or delete from within this folder unless the System Restore has been disabled.

If you have system restore enabled, assuming you have ME or XP of course, then the virus may be recreating from within this folder.
Gordon. (2217)
259032 2004-08-08 12:52:00 I see Norton is still installed, Run it.
When a virus checker checks your computer for virus's and finds some it cannot delete it will incript them and leave them on your computer untill you tell it to delete them. AVG uses a virus valut so I would say Norton has something simmilar, You need to get Norton to remove these files.
Rob99 (151)
259033 2004-08-13 02:26:00 Thank you all for your help and tips. I think I have finally managed to get rid of it. The program that was successful was 'rkdetector.exe. This program runs in a dos window and it showed that the Hxdef was hooked into the system. It managed to remove it (I think) but I also put 'net stop hackerdefender100' in the run command. Anyway it has not loaded the last two days.

After a lot of effort I managed to get Spybot down loaded and running this removed some of the affected registry keys.

The virus put something is the system to stop you down loading spybot. I even sent the program via e-mail but I could not extract it from the e-mail. I changed the name of the file and I e-mailed and opened it without any problems.

Watch out for this back door virus. I am sure I will not be the only one who catches it.
lpaint (5949)
259034 2004-08-13 05:42:00 Glad to hear that you got it sorted, Len. I have been wondering how you were getting on - thanks for letting us know. :-)

Whereabouts did you hear about 'rkdetector.exe'? That is a new one to me.
Susan B (19)
259035 2004-08-13 07:00:00 Susan, your Google skills must have declined with age?

www.noidea.us
godfather (25)
259036 2004-08-13 09:25:00 I did not get from Godfather's link it came from here, bagpuss.swan.ac.uk all I did from this site was to down load the file and run it.

Maybe a good one to put into the old memory bank.
lpaint (5949)
259037 2004-08-13 10:49:00 Thanks Len, that one might come in handy someday. :-) Susan B (19)
1 2