mIRC Home    About    Download    Register    News    Help

Print Thread
#157672 27/08/06 09:53 AM
_
_GMAC_
_GMAC_
_
I've managed to pick up a nasty, and it is advertising itself to all channels. it came from the bogus website http://www.steam2powered.com (BOGUS SITE. DO NOT CLICK).

its using the /amsg command somehow... And ive run through adaware, spybot, av scans, trend micro online scanner etc etc pretty much everything.

I think its attached to the actual mIRC.exe or possibly slipped itself in a script. Is anyone familiar with this particular nasty and knows the specific removal procedures? Everything else has turned up clean.

Just tried hijack this, got the log looked at. also clean. help appreciated!

GMAC

#157673 27/08/06 12:50 PM
Joined: Feb 2005
Posts: 342
R
Fjord artisan
Offline
Fjord artisan
R
Joined: Feb 2005
Posts: 342
If you don't know any scripting or, it would possibly be difficult for you to remove it. Your best option is to just delete it and reinstall mIRC. Chances are it's just a script that is running, which isn't a big deal. Just delete mIRC (the entire folder with all it's contents), and reinstall.

Let this be a lesson, do not download scripts unless you're positive that the source can be trusted.

#157674 27/08/06 01:09 PM
Joined: Sep 2003
Posts: 168
M
Vogon poet
Offline
Vogon poet
M
Joined: Sep 2003
Posts: 168
In addition to what Rand has just stated, always download mIRC from one of the mirrors in this site. Chances are, most of those links "out there" come with a pre-installed script, which is most likely to be your case.

Hope it helps wink

#157675 28/08/06 12:17 AM
Joined: Mar 2004
Posts: 208
F
Fjord artisan
Offline
Fjord artisan
F
Joined: Mar 2004
Posts: 208
Type /remote off

If it's a script, this will probably stop it. Then you can look at all loaded files for the offending code.

If it still runs, it's not in a script, so follow the other suggestions about downloading, reinstalling, etc.


Link Copied to Clipboard