A friend’s pc was infected with the irc/backdoor.sdbot trojan recently and I cleaned it out – eventually.
This is a tricky little trojan which hides in the System Volume folder (where the System Restore info is held) as well as the Windows/Winnt folder.
Killing the trojan using anti-virus software only gets rid of it until the next re-start. The way to get rid of this one is to turn off the System Restore service by opening the Services MMC in the Administrative Tools folder, right-clicking the System Restore service and selecting stop.
Having stopped the System Restore service, it is now possible to kill this virus permanently using your favourite anti-virus software or preferably a combination of av software. In this case, I used AVG and Stinger to be sure all infections were gone.
Don’t forget to re-start this service once you are done!