Computing.Net > Forums > Security and Virus > Malicious use of Mirc?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Malicious use of Mirc?

Reply to Message Icon

Name: Ryan
Date: June 7, 2003 at 15:02:23 Pacific
OS: win2000
CPU/Ram: 2.2Gig/512
Comment:

Hello,
I found a folder in my WINNT/System32 called RCTCFG, containing MIrc. The problem is, I've never installed MIrc in the first place! The scary part is, there's a txt file in this folder named "blah.txt" containing a fairly large list of Ips, with their respective User and Pass! Norton found a trojan called Backdoor-IRC-ZCrew, which I removed, but someone keeps reinstalling it! Obviously, someone is on my back... Anyone know a good way to mess with him, or tell him to stop? I figure if he's leaving so much behind, he's probably not the smartest of the bunch...
Thank you,
Ryan



Sponsored Link
Ads by Google

Response Number 1
Name: Abnormal
Date: June 7, 2003 at 16:41:55 Pacific

Response Number 2
Name: Ryan
Date: June 7, 2003 at 16:47:24 Pacific
Reply:

Yes, that's the natural thing to do for whatever Norton finds, but this is the fourth time that I've removed it completely from my system...


0

Response Number 3
Name: capt
Date: June 7, 2003 at 17:17:42 Pacific
Reply:

What firewall are you using? Have you checked the settings, and any open ports by using the scans at PC Flank and Nanoprobe from Gibson Research websites?


0

Response Number 4
Name: wawadave
Date: June 8, 2003 at 10:16:33 Pacific
Reply:

free trojin scan
http://www.trojanscan.com/trojanscan/scanner.htm
panda scan
http://www.pandasoftware.es/activescan/
housecall
http://housecall.trendmicro.com/housecall/start_corp.asp
d/l mcafee,s stinger
http://vil.nai.com/vil/stinger/
test my sheilds grc
https://nanoprobe.grc.com/x/ne.dll?bh0bkyd2
and d/l trojin remover
http://www.simplysup.com/tremover/details.html


0

Response Number 5
Name: Ryan
Date: June 8, 2003 at 14:39:23 Pacific
Reply:

Ok, I've run them all. Shields Up! graded me as trustealth (thanks to Zonealarm). Housecall found two files in my "Recycled" folder, belonging to the ZCrew Trojan, which I took care of. Thing is, being the fourth time that this has happened, is there anyway to go back to the source? I mean, I could wait for the next time this person does it, and then compare the "date and time created" in the trojans' file properties with the date and time of intrusions detected through Zonealarm, use Neotrace, and call their ISP... But I would like to do something back to them, for all the time I wasted on this f---er... Like Dameware and LC4, or something like that?


0

Related Posts

See More



Response Number 6
Name: Togg
Date: June 9, 2003 at 12:29:06 Pacific
Reply:

I'm not an expert on these things but, if you keep getting reinfected with this thing, it suggests that your previous removals have been incomplete or you are letting something through your firewall on a regular basis.

Did you try Trojan Remover www.simplysup.com
I understand it is pretty good.

Have you got a chat client like Trillian on your computer or do you file share. Lots of stuff can 'spoof' the identity of popular programs.

As for getting back at whoever is doing this, don't waste the time and effort. Unless they are really dumb they will be doing this via one or more compromised machines whose owners probably don't even realise that its happening.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Malicious use of Mirc?

cant get rid of klone/winantivirus www.computing.net/answers/security/cant-get-rid-of-klonewinantivirus/19694.html

Bunch of viruses! www.computing.net/answers/security/bunch-of-viruses/21884.html

Mind of it's own....... www.computing.net/answers/security/mind-of-its-own/20927.html