tried packet sniffing it before it goes out, and on its way in? It really looks like a NAT/router dcc adjustment failing to work correctly.

You have done your homework on the report, but I would assume if it was just mirc, it would be appearing on a huge number of systems, are these friends and your self all on one ISP ?

PS: im not giving you the brush off, just saying it "maybe" external to mirc.