mIRC Home    About    Download    Register    News    Help

Print Thread
#9123 31/01/03 09:32 PM
Joined: Jan 2003
Posts: 2
T
Tex Offline OP
Bowl of petunias
OP Offline
Bowl of petunias
T
Joined: Jan 2003
Posts: 2
It appears that mIRC 5.7 has been planted on one of my systems through a Trojan type hack. It is installed and functioning, but the program filenames must be altered so that I cannot find it to remove it.

Only the main exe file must be installed since all the help files and documentation files are absent. I tried installing mIRC 6.0 and then uninstalling which I thought would remove the 5.7 files. However, the 5.7 file(s) are installed under unknown name(s).

Perhaps there is a specific line of code in the 5.7 program files which I can search for on my system to find the location of the exe file.

Can anyone suggest a way to find the mIRC file(s) so that I can remove them? Help!

#9124 31/01/03 09:37 PM
Joined: Dec 2002
Posts: 843
P
Hoopy frood
Offline
Hoopy frood
P
Joined: Dec 2002
Posts: 843
There have been a few posts about this, so rather than repeating what has already been suggested, use the search feature at the top of the page, using the word 'trojan' as your search term, all dates, all forums. You should be able to see which ones are relevant to you from the thread titles. Good luck. smile


Never compare yourself to others - they're more screwed up than you think.
#9125 31/01/03 09:38 PM
Joined: Jan 2003
Posts: 11
T
Pikka bird
Offline
Pikka bird
T
Joined: Jan 2003
Posts: 11
sounds like some variant of gtbot.
look here for more info.


#9126 04/02/03 06:43 PM
Joined: Jan 2003
Posts: 2
T
Tex Offline OP
Bowl of petunias
OP Offline
Bowl of petunias
T
Joined: Jan 2003
Posts: 2
Using SWAT IT, and Symantec's web based scanner, I located three files associated with the Trojan use of mIRC. Independently, I identified mIRC 5.7 disguised under the filename taskmngr.exe which looked like the legitimate taskmgr.exe. I removed taskmnger.exe and the problem was solved.

#9127 04/02/03 08:36 PM
Joined: Dec 2002
Posts: 3,127
P
Hoopy frood
Offline
Hoopy frood
P
Joined: Dec 2002
Posts: 3,127
Read this thread please, to be sure you get rid of all the files in the payload.


ParaBrat @#mIRCAide DALnet

Link Copied to Clipboard