What
is the Backdoor SDBot.H Trojan?
Backdoor Trojan Horse that
is a variant of Backdoor.Sdbot.
This Trojan allows for its author to control a
computer by using Internet Relay Chat (IRC).
The existence of the file,
%System%\I5Eexplore.exe (or a similar filename,
such as I3Explorer.exe), is an indication of a
possible infection. The trojan can update itself
over the Internet and causes a huge security
breach for the infected computer.
The trojan horse adds the
following information or similar lines to the
Windows registry.
Config Loadatiorin
= I5Eexplore.exe
Backdoor SDBot.H Trojan Automatic Removal:
Using Spyware Doctor
to detect and remove this trojan AUTOMATICALLY!
Backdoor SDBot.H Trojan Manual Removal:
1) Click on Start
2) Click on Find or Search (depending on Windows
version)
3) Click on Files or Folders or All Files and
Folders
4) Type in the name of the file such as
I5Eexplore and search the hard drive for it
5) Delete the file
6) Now click on Start, Run, type in REGEDIT and
click OK to open the Registry Editor
7) Delete the entry below in each of the
following locations in the Registry (However, do
this at your own risk - deleting the wrong keys
and cause the computer to not boot correctly or
operate correctly)
In the right pane, delete
any value that refers to the file
"Config Loadatiorin"="<I5Eexplore.exe>"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
8) Exit the Registry Editor
9) Restart the computer and check the Registry
again for the trojan.
Detection and Removal Instructions for Trojans
|
(If you can not see the issued comment, please enable your browser to support javascript and refresh this page.)