You may want to pick up a trial version of a Trojan scanner or another AV to catch the more common name for it and perhaps make sure it's properly removed.

The SdBot is an IRC bot (used for flooding and maybe even DOS-ing) as WCB mentioned.

For the time being, the website is suspending trades and withdrawals indefinitely until a solution to the problem is found, one of the options being to file for bankruptcy, letting users I scanned with TDS-3 and found nothing afterwards.The SdBot is an IRC bot (used for flooding and maybe even DOS-ing) as WCB mentioned. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP). https://www.bleepingcomputer.com/forums/t/251784/infected/?view=getnextunread I just thought I would add for future reference that most of the time you can go here:»vil.nai.com/VIL/default.aspAnd put in the virus name and it will come up with all of

I saw some postings that suggested to me iSkySoft Helper Compact should be removed.

The file will not be moved unless listed separately.) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek ) They were unchecked immediately! KAV deleted the one file (loadcfg32.exe), then I scanned my registry, and got rid of the the two instances which were the two I found previous (run/run as service). You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Removal Automatic action Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

It can also use the compromised computer, usually in a network of other compromised computers, called a botnet, to attack other targets.The malicious author may build a botnet for various reasons It is was in my Windows\System directory.•I couldn't find any (useful) information referring to loadcfg, loadcfg32, loadcfg32.exe, backdoor.irc.sdbot, irc.sdbot, nor sdbot on Google!•There were 11 matches for backdoor.irc found at VirusList, My Trend Micro was trying to block it. http://interasap.net/general/backdoor-bot-q.html Some IRC backdoors replace INI scripts of an IRC client (mostly mIRC).

As a backdoor, it operates as an IRC bot that connects to a specific server.

As a backdoor, it operates as an IRC bot that connects to a specific server.

Following the attack, Cryptsy discovered that the perpetrator stole around 13,000 Bitcoin and 300,000 Litecoin, amounting to roughly $5.7 million.

BKDR_VB.CTJ Alias:Backdoor.Win32.VB.apv (Kaspersky), Backdoor.IRC.Bot (Symantec), DR/VB.apv.2 (Avira), Troj/Zapchas-DX (Sophos), BKDR_IRCBOT.AQG Alias:Backdoor.Win32.IRCBot.acp (Kaspersky), W32/Sdbot.worm (McAfee), Backdoor.IRC.Bot (Symantec), Worm/IrcBot.81412 (Avira), W32/IRCBot-YD (Sophos), BKDR_POISONIV.CV Alias:Backdoor.Win32.PoisonIvy.dj (Kaspersky), W32/Sdbot.worm (McAfee), Backdoor.IRC.Bot (Symantec), BDS/Poisonivy.DJ (Avira), WORM_SDBOT.YZB

After discovering the theft, the website decided to use its reserves of those cryptocurrencies and to pull from its profits to fill the wallets back up over time. The notice said the culprit was found to be the developer of Lucky7Coin (LK7), who placed an IRC backdoor into the code of wallet, and that the malicious code acted as a backdoor. Cryptsy also notes that they alerted the Miami FBI, but were redirected to report the issue on the I3C website and that no reply was received so far.

