subject: (Fwd) Re: New Trojan???? posted: Sun, 26 Nov 2000 05:20:10 -0000
on using someone else's computer to flood IRC channels..
------- Forwarded message follows -------
Date sent: Wed, 1 Nov 2000 14:50:06 +0000
Send reply to: Andrew McCall <[email protected]>
From: Andrew McCall <[email protected]>
Subject: Re: New Trojan????
Originally to: Dave Woods <[email protected]>
To: [email protected]
Dave,
Looks like a copy of mIRC. The ini files are some scripts for
cloning
and channel war things. The temp2.exe looks like an app for hiding
windows. So I'd say off hand, not having a copy of temp.exe in the
zip
that temp.exe would be a copy of the mirc.exe executable. The
gates.txt is a list of wingate / proxy hosts for cloning the client.
20139.txt I dont know could be a list botnet/clonenet hubs or
something similar. temp.src is a text file full of nicknames. I
haven't give much time to the scripts but from a glance it looks like
the client sets it's self up as a war bot. Then the temp2.exe hides
the mirc window so that you never know that it's running on your
computer. It has all the standard commands you'd expect in a bot
script, floods and the like, that can be accessed remotely by the
'bot
master'. Removing it should be as simple as deleting it.
Cheers,
Andrew McCall
on 31/10/00 7:28 pm, Dave Woods at [email protected] wrote:
> One of our computers here recently became infected with something I
> have never seen before.
>
> When the computer starts up (winME) it opens up 2 copies of the
> FreeExtractor prog that exctracts the following files: mirc.ini
> mirc2.ini mirc3.ini pri.ini 20139.txt gates.txt temp.exe temp2.exe
> whvlxd.dat temp.scr
>
> gates.txt contains a lot of ip's / domains in it that look to be
> possibly infected hosts that this "program" is creating as some of
> them are isp accounts ie port200.hs.ip.com temp.scr does not run
> (says not a valid win32 app)
>
> I have attached the files in a zip with a password of pass101
>
> If anyone has seen or knows what this is or how to remove it let me
> know.
>
> Sincerely,
> David Woods
> Techweavers Inc.
> [email protected]
> www.techweavers.net
> Phone: (780)-423-3952
> Fax: (780)-432-3220
>
>
------- End of forwarded message -------
--- [adminz]
* Origin: alerts, security, support (192.168.0.2)
generated by msg2page 0.06 on Jul 21, 2006 at 19:04:58