Computing.Net > Forums > Security and Virus > Backdoor.IRC.RPCBot or recycler

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Backdoor.IRC.RPCBot or recycler

Reply to Message Icon

Name: blinki2000
Date: July 14, 2005 at 05:48:21 Pacific
OS: window xp home
CPU/Ram: 2.6GHz
Comment:

i think the name of this virus is Backdoor.IRC.RPCBot

i'm told it does this:

1. Creates the folder, C:\RECYCLER\S-1-5-21-57989841-1715567821-725345543-1004\LOGS, and copies Bot.rar into this folder.

2. Runs WinOLE.exe as a service. WinOLE.exe is a patched mIRC client program, and hooks the IRC file extensions in HKEY_LOCAL_MACHIN\Software\Classes, which call WinOLE.exe when chat files are opened.

3. Runs the file, Dhcpp.exe, which is a TFTP server.

4. Runs the file, Nctl.exe, which is an FTP server.

5. Runs the file, Events.exe, which is an IRC proxying server.

6. Sets the following values:

"BaseDirectory"="C:\RECYCLER\S-1-5-21-57989841-1715567821-725345543-1004\LOGS"
"TftpPort"="00000045"
"Hide"="00000001"
"WinSize"="00000000"
"Negociate"="00000000"
"DirText"="00000000"
"ShowProgressBar"="00000000"
"Timeout"="00000003"
"MaxRetransmit"="00000006"
"SecurityLevel"="00000000"
"UnixStrings"="00000000"
"LocalIP"=""
"Beep"="00000000"
"VirtualRoot"="00000000"
"Services"="00000003"
"TftpLogFile"=""
"SaveSyslogFile"=""

in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\TFTPD32

7. Sets the value:

"DisableWebDAV"="00000001"

in the registry key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters

8. Sets the values:

"EnableDCOM"="N"
"EnableRemoteConnect"="N"

in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole

9. Connects to specified IRC servers and joins a channel to listen for commands from the Trojan's creator.

One such command is to exploit the DCOM RPC vulnerability: The Trojan connects to some randomly generated IP addresses to find computers that are listening at TCP port 135. Once the computer is found, it sends specially formed data, which exploits the DCOM RPC vulnerability, to that computer.

If the Trojan is successful, it may create a folder:

C:\RECYCLER\S-1-5-21-57989841-1715567821-725345543-1004\LOGS

and TFTP its components, bot.rar, unrar.bat, and unrar.exe, to the computer, and then runs itself there.


I have no idea what half of this means, can anyone me with that and how to get rid of it.

i've got the recycler file, new folders are appearing all over the place
like this sort of transparent like one that i get a denied access message to when i try to open it called "system volume information"
and i got these "desktop.ini" files turning up all over the place

no virus scanner has picked it up i got avg free, spybot s&d and ad aware

also how to i get xp into ms dos

any help would be much appreiated



Sponsored Link
Ads by Google

Response Number 1
Name: andy1
Date: July 14, 2005 at 08:17:21 Pacific
Reply:

agobot removal instructions. these should help you, Backdoor.IRC.RPCBot.exe is a part of this spyware.


0

Response Number 2
Name: blinki2000
Date: July 14, 2005 at 08:56:09 Pacific
Reply:

appologise for being an idiot but does
"Kill the following processes"
mean delete the files and i also can't find most of them even with search

and where are DLLs so i can delete them


0

Response Number 3
Name: blinki2000
Date: July 14, 2005 at 09:03:22 Pacific
Reply:

just noticed in C:\Documents and Settings i have networkService, LocalService and DefaultUser

i don't think they were there before, it was just the folders with the names of the users, are they part of the virus


0

Response Number 4
Name: blinki2000
Date: July 14, 2005 at 11:01:04 Pacific
Reply:

ignore response2 and 3
is there a fast way to fnd files in the registers


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Search problem spike.exe trojan



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Backdoor.IRC.RPCBot or recycler

Backdoor.IRC.Cloner virus www.computing.net/answers/security/backdoorirccloner-virus/4531.html

Backdoor.Sdbot removing problem www.computing.net/answers/security/backdoorsdbot-removing-problem/1184.html

Virus reappearing!!! www.computing.net/answers/security/virus-reappearing/12370.html