Computing.Net > Forums > Security and Virus > mIRC virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

mIRC virus

Reply to Message Icon

Name: matt
Date: October 8, 2003 at 07:38:00 Pacific
OS: WinXP Pro SP1
CPU/Ram: Athlon 1.2/512
Comment:

Man oh man I hope you guys can help me on this one because Norton has not been any help. I downloaded a mIRC script and just let it run. When I woke up this morning I had all these problems. Let me break it down for you so it will be easier to follow along;

1. The first thing I noticed is that an entry called ms_rev_updates.exe was in the Task Manager and I ended that process.

2. I then immediately ran Norton Antivirus but it would not scan, instead it would close and my Norton icon was not in the tray.

3. I tried to run LiveUpdate, it would not run.

4. I ran task manager and saw that ms_rev_updates.exe was running again so I ended it again.

5. I ran msconfig.exe and unchecked an entry that was loading a file called "GISet1xx.exe" The "xx" stands for characters I do not remember.

6. I then found that ms_rev_updates.exe was in c:\windows\system32\ folder along with another file called ms-rev_updates.exe

7. I renamed both files by adding on ".bak" to the end of the files.

8. After doing that I tried to run Internet Explorer from the QuickLaunch bar, it would not run saying it cannot find the path. Then, I could not run Norton from the Start Menu either. Nor System Restore.

9. I took off the ".bak" of the files in my system32 folder and then everything was running fine but so was ms_rev_updates

10. I restarted in Safe Mode

11. When in safe mode, I only renamed ms-rev_updates.exe to "ms-rev_updates.exe.bak"
Keep in mind the file that appears in the task manager under Normal Mode is ms_rev_updates.exe

12. I restarted my computer in Normal Mode and everything was working and the Norton icon was back in the tray.

13. I was able to update my virus definition files and run a scan

14. The scan fixed a DLL and deleted "ms_rev_updates.exe" and ms-rev_updates.exe.bak"

15. I restarted the computer and now i'm back to nothing running at all from the Start menu, and no Norton icon in the tray.

16. I cannot even run regedit from the the Run Menu

17. The only way I can run programs is if I run them using command.com but if I try to run Norton from the command line it still does not work

Also, when Norton did find the virus it said it was Backdoor. Trojan and Backdoor.sdbot

I know this was long and tedious but I hope someone can help. If not, thanks for trying.

-Matt




Sponsored Link
Ads by Google

Response Number 1
Name: Tom41
Date: October 8, 2003 at 08:48:34 Pacific
Reply:

Go here and Click 'WinXP Fixes' and then 'File Association fixes'.
Download and run the .exe file association fix. http://www.dougknox.com

Then, Download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, click "Save Log", and copy and paste it in a reply.

HijackThis!


0

Response Number 2
Name: matt
Date: October 8, 2003 at 12:52:58 Pacific
Reply:

Logfile of HijackThis v1.97.2
Scan saved at 3:52:28 PM, on 10/8/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\Inf\Catalog\su\srunner.exe
c:\Windows\Inf\Catalog\su\explore.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
D:\apps\Norton AntiVirus\navapsvc.exe
D:\apps\Norton AntiVirus\AdvTools\NPROTECT.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\CURSORS\meta\oledac\backup\srunner.exe
c:\windows\cursors\meta\oledac\backup\repairx\SPOOLSVC.exe
d:\apps\RealVNC\WinVNC\WinVNC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ntvdm.exe
D:\apps\MICROS~1\Office10\OUTLOOK.exe
D:\Apps\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/defaults/*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\apps\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\apps\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [WinVNC] "d:\apps\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\apps\NORTON~1\AdvTools\ADVCHK.exe
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Apps\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: Save with Download Manager... - file://d:\apps\J River\Media Center\DMDownload.htm
O9 - Extra button: ATI TV (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37862.7230555556
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://pluginaccess.com/celebs-nude/Browser_Plugin.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beetit.com
O17 - HKLM\Software\..\Telephony: DomainName = beetit.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C75F3464-59D6-4447-AF7F-6966AFDE0949}: Domain = beetit.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beetit.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beetit.com


0

Response Number 3
Name: matt
Date: October 8, 2003 at 13:00:25 Pacific
Reply:

you know what Tom41 you helped me a lot. Thank you so very much because now everything is working perfectly like before. Thank you for taking the time to read my detailed problem. Thanks again for the reply.


0

Response Number 4
Name: Tom41
Date: October 8, 2003 at 16:28:03 Pacific
Reply:

Hi matt,
You have some suspicious processes running:
C:\WINDOWS\Inf\Catalog\su\srunner.exe
c:\Windows\Inf\Catalog\su\explore.exe
C:\WINDOWS\CURSORS\meta\oledac\backup\srunner.exe
c:\windows\cursors\meta\oledac\backup\repairx\SPOOLSVC.exe

Go here and run an online virus scan, Copy the report and paste it in a reply.

RAV


0

Response Number 5
Name: matt
Date: October 8, 2003 at 17:06:47 Pacific
Reply:

oh damn, I'll get right on it and post a reply.


0

Related Posts

See More



Response Number 6
Name: matt
Date: October 8, 2003 at 19:14:35 Pacific
Reply:

Scan started at 10/8/2003 10:02:41 PM

Scanning memory...
Scanning boot sectors...
Scanning files...
C:\Documents and Settings\matt\Local Settings\Application Data\Microsoft\Outlook\Microsoft\Outlook\Matt - ComcastMatt - Hotmail-00000004.pst->Attachment.555: "MyProfile.scr" - Win32/Yaha.L@mm -> Infected
C:\Documents and Settings\matt\Local Settings\Temp\Temporary Internet Files\Content.IE5\A5ZG5W7Q\pup[1].htm->(SCRIPT0000) - JS/Noclose* -> Infected

Scanned
============================
Objects: 6282
Directories: 731
Archives: 0
Size(Kb): -1924361
Infected files: 2

Found
============================
Viruses found: 2
Suspicious files: 0
Disinfected files: 0
Mail files: 658

Scanned
============================
Objects: 6284
Directories: 731
Archives: 0
Size(Kb): -1924358
Infected files: 2

Found
============================
Viruses found: 2
Suspicious files: 0
Disinfected files: 0
Mail files: 658


Well that's the report, you were right. This found viruses that norton did not. But it doesnt say which files.


0

Response Number 7
Name: Tom41
Date: October 9, 2003 at 00:37:17 Pacific
Reply:

Hi matt,
The Rav report is showing an infected email attachment Attachment.555: "MyProfile.scr" and a JS exploit in your Temporary Internet files.
Just delete the email and empty your TIF folder.

Can you copy the following files, zip them and email them to me to analyze? Click my name for the email addy.
C:\WINDOWS\Inf\Catalog\su\srunner.exe
c:\Windows\Inf\Catalog\su\explore.exe
C:\WINDOWS\CURSORS\meta\oledac\backup\srunner.exe
c:\windows\cursors\meta\oledac\backup\repairx\SPOOLSVC.exe



0

Response Number 8
Name: matt
Date: October 9, 2003 at 04:45:52 Pacific
Reply:

no problem, I'll send it.


0

Response Number 9
Name: TSmith
Date: October 15, 2003 at 01:30:29 Pacific
Reply:

hi, im not sure if this the place to ask this, but i've been having some troubles with my computer as well. when i open my task manager, i have a program called pup.exe. the process goes to 53205239.exe or something like that, it changes all the time though. i dont know what to do. i've run norton and ad-aware, and neither find anything, but i know theres something wrong. can you help me?


0

Response Number 10
Name: Jess C
Date: October 16, 2003 at 14:24:33 Pacific
Reply:

I have the same problem as Tsmith. It brings my cpu usage up to 100% even after i end task the program. It also slows down my internet or just flat out stops it. I'm pretty sure it's not suppose to be there and no firewall, anti virus software or adware can pick it up. Please help it's a very annoying problem.


0

Response Number 11
Name: Matt J
Date: October 19, 2003 at 02:52:22 Pacific
Reply:

I have had the same problem as matt and have followed the advice of Tom41 and run the rav virus scan and this is the report that i have recieved.

Scan started at 19/10/2003 17:58:46

Scanning memory...
Scanning boot sectors...
Scanning files...
C:\Documents and Settings\Matthew Jones\Local Settings\Temporary Internet Files\Content.IE5\2R23MTAN\99950320[1].exe->(JDPack) - Tool:PornDialer.BZ -> Infected
C:\Documents and Settings\Matthew Jones\Local Settings\Temporary Internet Files\Content.IE5\S54T6N81\winpup[1].exe - Trojan:Win32/StartPade.AE -> Infected
C:\Program Files\NvidStar\nvd32.exe - TrojanDownloader:Win32/Istbar.D -> Infected
C:\WINNT\Adult_Chat.exe->(JDPack) - Tool:PornDialer.BZ -> Infected
C:\WINNT\system32\15496462.exe - Trojan:Win32/StartPade.AE -> Infected
C:\WINNT\system32\69950503.exe - Trojan:Win32/StartPade.AE -> Infected

Scanned
============================
Objects: 64648
Directories: 5948
Archives: 6907
Size(Kb): -535482
Infected files: 6

Found
============================
Viruses found: 3
Suspicious files: 0
Disinfected files: 0
Mail files: 381

Can anyone help as this is really annoying while trying to use my machine.

Thanks



0

Response Number 12
Name: bigmotorfokker
Date: October 20, 2003 at 00:25:05 Pacific
Reply:

I am having the exact same problem as Jess and Matt! This is a real bugger. I really need help.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: mIRC virus

mirc virus help www.computing.net/answers/security/mirc-virus-help/20368.html

Trojan Virus in MIRC www.computing.net/answers/security/trojan-virus-in-mirc/5762.html

virus from Mirc www.computing.net/answers/security/virus-from-mirc/22443.html