Computing.Net > Forums > Security and Virus > IRD\BackDoor. Flood

IRD\BackDoor. Flood

Reply to Message Icon

Original Message
Name: irispetra
Date: April 14, 2007 at 22:38:15 Pacific
Subject: IRD\BackDoor. Flood
OS: Windows2000 Pro
CPU/Ram: No idea
Model/Manufacturer: Dell
Comment:

Hi, I am new to the Forum.

An old plague turned up and will not be healed by AVG

The infected file is script.ini at
C:/WINDOWS/system/script.ini

I have scanned repeatedly with AVG with same error in healing.

I ran the scan in safe mode, but I am not sure it completed. At any rate, the file is again showing in AVG.

What advice do you have for me?

My self-help knowledge is limited, so layman's language would be helpful.

Thanks.

Iris ten Holder
Ottawa Photo
Bring New Life to Old Photos


Report Offensive Message For Removal


Response Number 1
Name: irispetra
Date: April 14, 2007 at 22:41:57 Pacific
Reply: (edit)

Correction:

It is IRC, not IRD

Iris ten Holder
Ottawa Photo
Bring New Life to Old Photos


Report Offensive Follow Up For Removal

Response Number 2
Name: XpUser4Real
Date: April 14, 2007 at 23:21:54 Pacific
Reply: (edit)

http://www.geocities.com/SiliconVal...
http://www.hackfix.org/ircfix/scrip...

They might show you insight into your problem.

Here's another one:
http://www.irchelp.org/irchelp/mirc...
Good luck

Hopefully my advice will help you...Please post back with your results....thanks


Report Offensive Follow Up For Removal

Response Number 3
Name: irispetra
Date: April 16, 2007 at 10:44:15 Pacific
Reply: (edit)

Thanks for the great help.

I looked at all the links and realized that
I don't use mIRC, so there is no need for me to keep these files.

I did a search and found two files: mIRC.ini and script.ini. I noticed that mIRC calls on script.ini.

I opened script.ini in notepad and got an immediate response from AVG that there was a virus threat. I moved it to the virus vault.
That was easy!

When I searched again it was gone.

Now I will watch AVG if there is a new infection.

My thanks again for your fast reaction to my post.


Iris ten Holder
Ottawa Photo
Bring New Life to Old Photos


Report Offensive Follow Up For Removal

Response Number 4
Name: XpUser4Real
Date: April 16, 2007 at 12:18:38 Pacific
Reply: (edit)

Thanks for posting back, glad you got it sorted out

Hopefully my advice will help you...Please post back with your results....thanks


Report Offensive Follow Up For Removal

Response Number 5
Name: irispetra
Date: April 17, 2007 at 05:04:59 Pacific
Reply: (edit)

May I now presume that the procedure of locating the file and opening it in notepad was a valid one?

AVG was unable to heal the file. But did identify the virus once the file was accessed and opened in notepad and offer the virus vault option.

Once acted upon this option, the problem was solved.

It seemed like a simple, effective solutioin.

Thanks for your contribution to the solving of this problem. I hope others will follow up on the links provided in the helpful post, which explain in detail the use and dangers if script.ini.

Cheers


Iris ten Holder
Ottawa Photo
Bring New Life to Old Photos


Report Offensive Follow Up For Removal


Response Number 6
Name: David P227
Date: April 17, 2007 at 16:54:52 Pacific
Reply: (edit)

I have a similar problem BUT my IRC/BackDoor.Flood virus is in win.exe. I'm running windows xp on a Dell 4700c. I blogged with Dell this afternoon and they told me NOT to delete or "vault" win.exe as that is my Windows program. I've tried to restore and although all my restore settings are there, and I've given myself the maximum space for restore, every date says that it can't be restored. I'm stymied. Help. I've got a trojan and can't delete win.exe. Or is win.exe really important as Dell said?
Thanks for any help.
David in Fort Worth


Report Offensive Follow Up For Removal

Response Number 7
Name: XpUser4Real
Date: April 17, 2007 at 17:49:01 Pacific
Reply: (edit)

Here's something on win.exe
http://www.bleepingcomputer.com/sta...

Hopefully my advice will help you...Please post back with your results....thanks


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: IRD\BackDoor. Flood

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge