Forum » Pomoč in nasveti » irc-virus??
irc-virus??
tx-z ::
zdele sm glih downloadu irca,,ga inštaliram in mi Sophosov antivirsuni program napiše da je v njem virus. Ok, probam kakšno starejšo verzijo k jo mam na cdju,,isto-virus.?
a vam tut to kakšen antivirusni program napiše? -probu sm tanovo 6.03 verzijo
a vam tut to kakšen antivirusni program napiše? -probu sm tanovo 6.03 verzijo
tx-z
tx-z ::
Troj/IRCBot-C
Type
Trojan
Detection
A virus identity file (IDE) file which provides protection is available now from the Latest virus identities section, and is incorporated into the July 2003 (3.71) release of Sophos Anti-Virus.
Sophos has received several reports of this Trojan from the wild.
Note: Detection for Troj/IRCBot-C was included in the June 2003 (3.70) release of Sophos Anti-Virus. This new IDE has been issued to improve detection.
Description
Troj/IRCBot-C is a backdoor Trojan which allows a remote intruder to access and control a computer via IRC channels.
The installation executable for Troj/IRCBot-C typically arrives via email or via IRC channels as a DCC send.
When run, the installation executable for Troj/IRCBot-C drops the files listed below to the C:\WINNT\SYSTEM32\ folder. If this folder does not exist (i.e. on Win9x), it will be created.
exe32.exe
MIRC.INI
REMOTE.INI
secure.bat
server.txt
win.dll
wind.bat
The following clean utility programs are also dropped to the C:\WINNT\SYSTEM32\ folder:
NB.EXE
bnc.exe
fnet.exe
libparse.exe
psexec.exe
rpcserv.exe
SYS32.EXE
wget.exe
The installation executable launches exe32.exe, a MS-DOS program which simply launches C:\WINNT\SYSTEM32\NB.EXE.
exe32.exe is copied to the folder
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
so that exe32.exe, and thus NB.EXE, are launched automatically each time Windows is started.
NB.EXE is a clean mIRC client which connects to a remote IRC server and joins a specific channel.
The remote intruder will then be able to gain access and control over the computer using a regular IRC client.
NB.EXE sets a number of IRC, mIRC and ChatFile registry entries, overriding any previous installations and making itself the default IRC client.
-no tole ta virus nardi
Type
Trojan
Detection
A virus identity file (IDE) file which provides protection is available now from the Latest virus identities section, and is incorporated into the July 2003 (3.71) release of Sophos Anti-Virus.
Sophos has received several reports of this Trojan from the wild.
Note: Detection for Troj/IRCBot-C was included in the June 2003 (3.70) release of Sophos Anti-Virus. This new IDE has been issued to improve detection.
Description
Troj/IRCBot-C is a backdoor Trojan which allows a remote intruder to access and control a computer via IRC channels.
The installation executable for Troj/IRCBot-C typically arrives via email or via IRC channels as a DCC send.
When run, the installation executable for Troj/IRCBot-C drops the files listed below to the C:\WINNT\SYSTEM32\ folder. If this folder does not exist (i.e. on Win9x), it will be created.
exe32.exe
MIRC.INI
REMOTE.INI
secure.bat
server.txt
win.dll
wind.bat
The following clean utility programs are also dropped to the C:\WINNT\SYSTEM32\ folder:
NB.EXE
bnc.exe
fnet.exe
libparse.exe
psexec.exe
rpcserv.exe
SYS32.EXE
wget.exe
The installation executable launches exe32.exe, a MS-DOS program which simply launches C:\WINNT\SYSTEM32\NB.EXE.
exe32.exe is copied to the folder
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
so that exe32.exe, and thus NB.EXE, are launched automatically each time Windows is started.
NB.EXE is a clean mIRC client which connects to a remote IRC server and joins a specific channel.
The remote intruder will then be able to gain access and control over the computer using a regular IRC client.
NB.EXE sets a number of IRC, mIRC and ChatFile registry entries, overriding any previous installations and making itself the default IRC client.
-no tole ta virus nardi
tx-z
Zgodovina sprememb…
- spremenilo: tx-z ()
Vredno ogleda ...
Tema | Ogledi | Zadnje sporočilo | |
---|---|---|---|
Tema | Ogledi | Zadnje sporočilo | |
» | POMOČ - ntdlr.exe - Troj/Feutel-CH TrojanOddelek: Pomoč in nasveti | 1281 (1177) | amigo_no1 |
⊘ | fajl ki se sam ustvarja.. kr nekOddelek: Pomoč in nasveti | 900 (771) | Myth |
» | Težave z računalnikomOddelek: Pomoč in nasveti | 2003 (1928) | mojsterleo |
» | Za glodanje: nek čuden virus ie/mirc virusOddelek: Omrežja in internet | 3415 (2526) | Predator |
» | nekdo mi vdira notr (strani: 1 2 )Oddelek: Omrežja in internet | 5546 (4551) | undefined |