Hello guys / galls. In response to a recent question about Zone Alarm I installed it and Hey presto, I have encountered the first virus to invade my computer. This despite the fact that I was assured Zone Alarm is far superior to Microsoft’s XP built in firewall. I Googled the virus name [ IRC/BackDoor.Flood] and discovered that numerous other suckers have been similarly invaded too. One of the answers pin pointed the virus as being in folder C:winntsystem32 so located and right clicked on it as directed then did an AVG scan but the report found nothing. I have taken screen shots of the various results but the file is too big so I will [if permitted] send it to one of you kind Moderators as an attachment on an email. If it is not too much trouble perhaps screen shots thought relevant can be copied to the lounge so if other readers encounter this problem they may know what to do. As a background to the problem May I suggest readers to whom this virus is new do a Google for IRC/BackDoor.Flood and see the various questions and remedies which explain it without me having to submit an unduly lengthy thread. Like some of the writers of the said questions on Google I too can’t find the infected file to delete it. Any help would be appreciated. regards. Dave.
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Backdoor.Flood [Virus]
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Backdoor.Flood [Virus]
- This topic has 28 replies, 9 voices, and was last updated 17 years, 5 months ago.
AuthorTopicWSSilver Fox
AskWoody LoungerNovember 3, 2007 at 9:10 pm #445877Viewing 3 reply threadsAuthorReplies-
WSHansV
AskWoody Lounger -
WSjscher2000
AskWoody LoungerNovember 3, 2007 at 10:17 pm #1082359ZoneAlarm is a firewall. The firewall’s function is to control connections into and out of your computer. However, once you approve your email software fetching your email and your browser fetching web pages and downloads, then ZoneAlarm stands aside. It does not, unless supplemented with additional features, concern itself with what is passing through a permitted connection. This is a crucial point that I hope all Loungers will keep in mind.
What program reported to you that it detected “IRC/BackDoor.Flood”? Does that program have the capability of cleaning it?
Added: Hey — while this tab was waiting for me to finish with another post, Hans already made these points.
-
WSDocWatson
AskWoody LoungerNovember 3, 2007 at 10:34 pm #1082362 -
WSHansV
AskWoody Lounger -
WSSilver Fox
AskWoody LoungerNovember 3, 2007 at 11:56 pm #1082368Hi. Responding to both replies; Just done as you said, a search for it but none was found yet I have since done a full scan with AVG and the Security Status report, though assuring me “All components are installed and fully working”, indicates the said virus is present. The prog. then tried to “Heal” the intruder but as on each of the previous occasions, failed. [Incidentally, this is what other victims of this attack claim as is seen if one Googles for this virus, some have had the virus showing twice but only one will delete.]
With a view to sending the report as an attachment I have taken a screen shot of it and using Microsoft Photo Editor, cropped it to reduce it’s size and saved it as a jpeg but, can’t seem to reduce it to less than less than 174 KB. though I have in the past sent a couple of attachments successfully using this method. Is there (as a one off), an email address I can sent the Word doc to with the three screen shots as an attachment? It would prove what seems to be a paradox to be true.
In anticipation regards Dave. -
WSJezza
AskWoody Lounger -
WSLeif
AskWoody LoungerNovember 4, 2007 at 2:37 pm #1082398As you emailed me the attachments, I thought I’d chime in…
Looking at the pathnames in the attachment below, the ‘script.ini’ file is either in your recycle bin, in a system restore file, or both – which I would surmise is why it can not be quarantined. You could try emptying your recycle bin and see if that clears it, or turn-off your system restore then back on again to delete the restore file. (Note: this will clear ALL previous restore points.) I don’t think it can do much harm where it is.
To reduce file sizes of jpg’s in Photo Editor, in the Save As window, click on ‘More >>’ and set the JPEG quality factor to 70 – this should be fine for posting here and will reduce the file size by perhaps a factor of 4.
-
WSSilver Fox
AskWoody LoungerNovember 6, 2007 at 10:47 pm #1082713Hello all. I’m sorry not to have responded earlier, had unexpected demands on my free time. I will try to answer the numerous points raised in this reply. If I miss some point made please forgive me but the drama has dragged on longer than I anticipated. More than one of you seemed to be puzzled by my comment that the AVG free prog was fully up to date and protecting my computer but that it was reporting that a virus was present. How I came to make this claim is based on the screen shot [which I hope is attached] confirming the same. As recommended, I performed a “Search” for the virus name [OCXDLL.EXE ] but nothing was found. In my naivety I thought that there may be some currency in performing a System Restore (which I have done several times in the past) but it failed three times with the warning that it was not successful, so maybe that will suggest a link with the virus which (on one report pane) is said to be located in On another report this information is given; C:RECYCLERS-1-5-21-6067471-1058031214-725345543=500script.ini . If that bamboozles you readers think of dummies like me who grew up with the ABACUS, when there was just one TV in the village & pocket calculators were science fiction. That’s why the likes of me ask you to tread slowly with your 21st century knowledge. The screen shot proves three things; 1 The Security status assurance me that the AVG package is fully up to date and functioning properly; 2 The IRC/BackDoor.Flood virus is present; 3 The “Threats Found” report shows the intruder was NOT healed, deleted or moved to the vault. So that is the dilemma friends, I hope the attachment explains the predicament & someone can point me in the right direction. Regards Dave.
-
WSSilver Fox
AskWoody Lounger -
WSSilver Fox
AskWoody Lounger -
WSjscher2000
AskWoody Lounger -
WSSilver Fox
AskWoody LoungerNovember 7, 2007 at 12:13 am #1082721Hello Scher, I’m sure you have reason from the information supplied (as have others) for deducing it is in the Recycle Bin but I can assure you there is nothing visible in there as I empty it after every session. Could it be it is there but as a Hidden file? The only other user is my daughter so are there perchance two Recycle Bins? Incidentally, the computer is not set up for two separate users with individual passwords, she simply has a folder on the desktop which I NEVER NEVER open. Regards & thanks again, Dave.
-
WSjscher2000
AskWoody Lounger -
WSJezza
AskWoody LoungerNovember 7, 2007 at 2:19 am #1082734Hi Dave
When you delete a file in Windows Explorer or My Computer, the file is stored in the Recycle Bin. The file remains in the Recycle Bin until you empty the Recycle Bin or restore the file.
The Recycler folder is used only on disk partitions. The Recycler folder contains a Recycle Bin for each user that logs on to the computer.
Can you log onto the PC as the other users, or get the other users to log on and empty their Recycle Bins and run the AVG again
-
WSSilver Fox
AskWoody LoungerNovember 7, 2007 at 1:15 pm #1082761Hello Jerry, As I mentioned in my reply of 6th Nov instant, Yes there are two users of the computer but my daughter only has a folder on my desktop so when either of us switches on, only my desktop appears. I have checked the Recycle Bin details / settings and as far as I understand, the attachment shows the one bin is where deleted files end up regardless of who has deleted them. From what jscher2000 says, it seems the intruder is nothing to really worry about so I feel a little more relaxed about it, however, I would be even more content if it could be eliminated altogether so any further advice would be appreciated. Regards Dave.
-
WSJezza
AskWoody LoungerNovember 7, 2007 at 1:26 pm #1082762OK, This is looking promising.
If you could endulge me, I just want to check something
Can you open My Computer on your desktop and navigate so you view C:Documents and Settings, don’t panic, nothing private will show but it will show us what other system users are presen, if anyt. If you could screendump that and attach it to the next post I would be grateful….I have a theory
-
WSSilver Fox
AskWoody LoungerNovember 7, 2007 at 3:54 pm #1082769Edited by Big Al to “crop” the graphic to a smaller size, i.e. get rid of unnecessary portion of the picture.
Hi Jerry, let’s hope that theory works. Here is the screen shot of what is in the C:Documents and Settings, folder. To assist in the investigation perhaps I can say what is in the folder. The untitled folder on the left has the following folders in it :- Applications Data; Cookies; Desktop; Favourites; My Documents; Start Menu; User Update; Windows; Default; NTUSER; the last two not being folders as such but look like CD discs with a right arrow in them. The folder to the right has these folders in it : – Desktop; Favourites; Shared Documents; Start Menu; ntuser, Incidentally, this is by the way but when I took a screen shot of the said folder, copied into Microsoft Photo Editor, clicked on the “Select” tab to choose only the relevant details of the shot then clicked on “Edit” again as instructed, I was told a re-sized image should be saved but I find that the original larger one saves instead. Result; one of my recent attachments was doctored by Hans to make it a reasonable size for the forum. What am I doing wrong if anything? Thanks Dave.
-
WSDuchess843
AskWoody LoungerNovember 7, 2007 at 4:52 pm #1082784 -
WSSilver Fox
AskWoody LoungerNovember 7, 2007 at 10:32 pm #1082839Hello Duchess843. Where have you been since I first posted my question? I seem to have been going round in ever decreasing circles yet ever wider fields of possibilities, searching for & without success but within minutes of searching for the folder named “Recycler” as you suggested, the offending folder was exposed. I deleted the contents of the folder and with great anticipation did a scan with AVG BUT as the attachment shows, the gremlin is still lurking somewhere in the bowels of the computer & seems to refuse to be deleted. Though jscher2000 seems to feel there is little to fear from this intruder I am still suspicious and would feel much happier if it went down the plug hole once and for all. PS note the report says it is not HEALABLE Dave.
-
joep517
AskWoody MVPNovember 7, 2007 at 10:45 pm #1082840The file is contained in one of your System Restore points. As mentioned by Leif in post 674,744, if you turn System Restore off for the C: drive and then back on it will get rid of the offending file(s0. NOTE: You will also lose all of your restore points. So, you may want to back up your system ASAP after getting rid of the files. To turn off System Restore right click My Computer and select Properties. Then click on the System Restore tab. Ensure the check box for ‘Turn off System Restore’ is checked. OK you way out. To turn System Restore back on reverse the process.
Joe
--Joe
-
WSJezza
AskWoody LoungerNovember 8, 2007 at 5:27 am #1082866(Edited by jscher2000 on 07-Nov-07 20:27. Repaired link.)
Hi Dave
After getting the information from you it was quite apparent what the issue was, it just needed us all to ask the right questions. I think the clue was that in your post 675,136 the image indicated that there was a folder called Recycler which was what we were alluding to.
It appears that the Anti-Virus software has been doing its job nicely and has been interacting with System Restore correctly
I think it prudent that before you take Joe’s advice but before doing so read up on How antivirus software and System Restore work together and go through the step-by-step instructions provided by Microsoft to eliminate it onceand for all.
-
WSSilver Fox
AskWoody LoungerNovember 8, 2007 at 2:37 pm #1082914A word of sincere personal thanks to all who responded to my numerous posts to the lounge as this thread has protracted to one of the longest I have seen though I did notice one by the Duchess843 which went to 22 posts. Incidentally, it was the Duchess that first pointed me to the folder called “Recycler” which I located in the first “Search” and which the folder when scanned with AVG pinpointed the (BackDoor.Flood) horror. I did a sweep with AVG late last night and got a clean bill of health SO, once more I express my sincere thanks for every contribution made on the lounge during this thread. Must tell all my friends about it, (as we say here in the UK) ….since Sliced Bread. Regards Dave.
-
WSSilver Fox
AskWoody LoungerNovember 8, 2007 at 8:37 pm #1082986…..please, I beg your pardon friends regarding the final half sentence which reads …..since sliced bread. This must have appeared as absolute gobble-de-gook especially to none UK readers being without any sense or reason for it should have read : – “This web site is the best thing since sliced bread.” …. which is a common saying here in the UK when something good happens. Finally thanks Dave.
-
WSviking33
AskWoody Lounger -
WSSilver Fox
AskWoody LoungerNovember 9, 2007 at 10:00 pm #1083124At last I learn that we do have something in common, though I expect there must be many things colloquial that we are poles apart on. One of your very common sayings which forever seems to niggle my tolerance level in the realm of [good English] is to hear Americans say something like….. [ he fell OFF OF his bicycle. ] I know this form of speech is particularly unique to the US of A but how it came to become so I cannot imagine. Have a nice day loungers….. Cheers Dave.
-
WSviking33
AskWoody Lounger -
WSSilver Fox
AskWoody LoungerNovember 9, 2007 at 11:47 pm #1083132Nope…. not had the pleasure of any banter with John though as time permits I am open for idea / threads. I suppose the Scuttlebutt section is the place to send posts for banter other than computer issues! Recently I got an email from a niece asking me if I knew any USA web sites that her son could log on to where he could learn about USA culture as he was researching the same as part of a project he was doing for school. Here is the brief email
[Hi Uncle David, Sorry I haven’t replied sooner but it’s not very often i come on line. I need a bit of help if you can.Nathan is doing a project on America have you got any web sites were i can get information on things such as phrases, numbers. greetings etc to help him with his project.It is very much appreciated.Hope to be in touch soon Love from Lynda and family.
Maybe this is a good place for “John” to jump on the bandwagon and give me some answers that can be forwarded to my niece. Over & out. Dave. -
WSDuchess843
AskWoody Lounger
-
-
-
-
Viewing 3 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Global data centers (AI) are driving a big increase in electricity demand
by
Kathy Stevens
2 hours, 12 minutes ago -
Office apps read-only for family members
by
b
1 hour, 16 minutes ago -
Defunct domain for Microsoft account
by
CWBillow
6 hours, 17 minutes ago -
24H2??
by
CWBillow
7 hours ago -
W11 23H2 April Updates threw ‘class not registered’
by
WindowsPersister
10 hours, 1 minute ago -
Master patch listing for April 8th, 2025
by
Susan Bradley
3 hours, 15 minutes ago -
TotalAV safety warning popup
by
Theodore Nicholson
9 hours, 42 minutes ago -
two pages side by side land scape
by
marc
1 day, 23 hours ago -
Deleting obsolete OneNote notebooks
by
afillat
2 days, 1 hour ago -
Word/Outlook 2024 vs Dragon Professional 16
by
Kathy Stevens
1 day, 4 hours ago -
Security Essentials or Defender?
by
MalcolmP
1 day, 6 hours ago -
April 2025 updates out
by
Susan Bradley
1 hour, 46 minutes ago -
Framework to stop selling some PCs in the US due to new tariffs
by
Alex5723
1 day ago -
WARNING about Nvidia driver version 572.83 and 4000/5000 series cards
by
Bob99
14 hours, 14 minutes ago -
Creating an Index in Word 365
by
CWBillow
1 day, 16 hours ago -
Coming at Word 365 and Table of Contents
by
CWBillow
4 hours, 48 minutes ago -
Windows 11 Insider Preview Build 22635.5170 (23H2) released to BETA
by
joep517
2 days, 20 hours ago -
Has the Microsoft Account Sharing Problem Been Fixed?
by
jknauth
2 days, 23 hours ago -
W11 24H2 – Susan Bradley
by
G Pickerell
3 days, 1 hour ago -
7 tips to get the most out of Windows 11
by
Alex5723
2 days, 23 hours ago -
Using Office apps with non-Microsoft cloud services
by
Peter Deegan
2 days, 16 hours ago -
I installed Windows 11 24H2
by
Will Fastie
23 hours, 5 minutes ago -
NotifyIcons — Put that System tray to work!
by
Deanna McElveen
3 days, 4 hours ago -
Decisions to be made before moving to Windows 11
by
Susan Bradley
3 hours, 44 minutes ago -
Port of Seattle says ransomware breach impacts 90,000 people
by
Nibbled To Death By Ducks
3 days, 13 hours ago -
Looking for personal finance software with budgeting capabilities
by
cellsee6
2 days, 21 hours ago -
ATT/Yahoo Secure Mail Key
by
Lil88reb
2 days, 21 hours ago -
Devices with apps using sprotect.sys driver might stop responding
by
Alex5723
4 days, 6 hours ago -
Neowin – 20 times computers embarrassed themselves with public BSODs and goofups
by
EP
4 days, 14 hours ago -
Slow Down in Windows 10 performance after March 2025 updates ??
by
arbrich
14 hours, 13 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.