PDA

View Full Version : I trust TDS, but yet.....


Generix
March 9th, 2003, 01:39 PM
Having recently updated my Norton anti-virus definitions, I recieved an alert about a so called IRC trojan called 'nHTMLn.dll' located in my mIRC directory. This file isn't by any means new, and TDS does have any sort of idetification on the file. I've talked to a few people that have also gotten the same alert from Norton recently. Any ideas on if this is a virus/trojan or if it's harmful?

DolfTraanberg
March 9th, 2003, 02:42 PM
hmm, did a search on Google on that one. Looks quite clean to me.
Dolf

xor
March 9th, 2003, 04:06 PM
mIRC Explorer Trojan - generic detection needed - open source - popular versions are 2.9 and 2.92 ;D

Gavin - DiamondCS
March 10th, 2003, 02:02 AM
Hi Generix,

Please email me the file, gavin@diamondcs.com.au

I'll get back to you as soon as I can

Generix
March 23rd, 2003, 02:29 AM
Sorry for the delays....ISP problems :(. Anyways, someone from Gladiator AV contacted me and requested the file. He claims that this is a genuine IRC backdoor, and GAV detects it as one. However, over the course of the next several days, I updated my Norton AV definitions again, rescanned, and came up negative. Also, I found that this file came from the zipped version of eXtreme for mIRC (a popular script), therefore making it less likely to be malicious. I also spoke with a reputable IRCop who stated that this file was completely harmless and had to do with the eXtreme script and browser integration. I've taken the file from quarantine and monitored it, yet found nothing. It looks like this was a false positive (hopefully).

Paul Wilders
March 23rd, 2003, 02:45 AM
Generix,

Did you supply a copy to DCS as requested by Gavin (see above?) - better to hear a comment from the horses mouth (not personal, Gavin ;).

regards.

paul

Gavin - DiamondCS
March 23rd, 2003, 12:11 PM
No problems Paul ;D

The only information I could find on this one was also that it seemed to be available in a few scripts and was probably a benign type of file - ok it could be used as a support file for a trojan but not be a trojan itself.. no sample yet but this was the thought at the time :)

Paul Wilders
March 25th, 2003, 06:41 AM
Thanks Gavin - good news ;).

regards.

paul

Generix
March 25th, 2003, 12:20 PM
Paul,
Yes, I was able to send Gavin a copy of the dll and he verified that it was trojan free :)

Paul Wilders
March 25th, 2003, 01:54 PM
Nice job, Generix ;)

regards.

paul