mIRC Home    About    Download    Register    News    Help

Print Thread
#41276 12/08/03 01:08 PM
O
ozyvent
ozyvent
O
Not sure if this is related, but I'm running Windows XP Home.

Today when I was using mIRC I got disconnected from the server with the message "Software Caused Connection Abort" - this isn't so unusual, however as soon as I reconnected my ident changed from ~ozyvent (as it normally should be) to Brad## (## = 2 random numbers) When I go into the section to change the ident, it's all as it normally should appear to make my ident ~ozyvent. It also makes every client on my computer's ident Brad##

I did a reboot and the problem still persists but with two different numbers after the "Brad". I'm thinking perhaps its a virus/worm or something which VET (my anti-virus program) hasn't picked up. I just can't understand what or where the problem is, so if anyone can help it'd be greatly appreciated.

#41277 12/08/03 02:07 PM
Joined: Jun 2003
Posts: 4,670
M
Hoopy frood
Offline
Hoopy frood
M
Joined: Jun 2003
Posts: 4,670
Never heard of that particular identd before...the most logical explanation would be that, as you think, it's a virus.

If you've download any scripts/addons or anything lately, it could also be that.

Try some other virus scans, two is better than one (3>2 etc):

Useful security/virus websites:
McAffee
Trend Micro - Housecall
Symantec Security Check
DALnet #NoHack Homepage
Gibson Research Center

Hope you solve the prob smile

Regards,


#41278 12/08/03 07:55 PM
Joined: Dec 2002
Posts: 1,518
_
Hoopy frood
Offline
Hoopy frood
_
Joined: Dec 2002
Posts: 1,518
also check your email address wasnt changed ... since ur ident was preficed with a ~ it means that your ident isnt even being sent to the server properly... could be the xp firewall blocking it ... but check to make sure your email address hasnt been changed to brad## or whatever it is

#41279 13/08/03 06:14 AM
O
ozyvent
ozyvent
O
Ok, well as I said, nothing had changed, hence why I was confused.

It turns out it was some worm.. I found 2 on my computer:
W32\Spybot.worm.gen
W32\Sdbot.worm.gen

Symantec provided info about the Spybot one (http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html), and some searching on the net gave me some info about the others.

So if anyone else is having this problem, try this smile

Thanks for the help anyway smile

#41280 13/08/03 05:26 PM
Joined: Dec 2002
Posts: 3,015
P
Hoopy frood
Offline
Hoopy frood
P
Joined: Dec 2002
Posts: 3,015
Glad you solved the problem. There are more than a few that create probs with identd. I read there's an sdbot variant spreading about, some combo of msblast worm, sdbot and spybot thats causing some reboots, but dunno if it effects identd since i havent looked into it yet. You did the smart thing by researching what was found on yours. Good work!

#41281 13/08/03 05:32 PM
Joined: Dec 2002
Posts: 2,958
W
Hoopy frood
Offline
Hoopy frood
W
Joined: Dec 2002
Posts: 2,958
The SD Bot is still regularly attacking IRC networks too, defintely one to watch out for.


Link Copied to Clipboard