Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 30th, 2003, 06:46 AM
wintomato wintomato is offline
Infrequent Poster
 
Join Date: Jun 2003
Location: London
Posts: 1
Default whodunnit?

Hi, new to the forum,
anyone know if there's a way to find out if a EXPL32 mIRC virus has been used to control a certain pc.
ie the pc is infected and has been for a while, is there anyway of telling if the software has actually been used by someone remotely?
EXPL32 shows a UNIX username/logon
thanks
  #2  
Old June 30th, 2003, 07:40 AM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re:whodunnit?

Hi Wintomato, welcome to the forum!
Wait with deleting the nasty, or you might like to zip it so it can't run anymore.
Are you on a network using unix or??
How did you find the unix login name?

I would not think of a virus but a keylogger or a RAT, more in the trojans area, right?
Some descriptions say it opens a backdoor for SubSeven 22 so if you find that you can be sure it was used.
How is it possible your AV/AT scanners didn't see and disinfect your system?
You might like to send a sample to a trojan specialist to advice and if you want/need/like they can snipe it out to look for all there is and maybe where to look for logfiles if there are.
Try support@diamondcs.com.au and include the link to this thread.
Keep us informed please.
If i'm wrong and it would be a virus, i recommend sending it to the NOD32 guys at Eset, i can't recall their samples email addy at the moment.


Did you take any security measures since the discovery?
You might like to grab the Irclean and Mirclean from the www.diamondcs.com.au site in the free tools area to see if there are more IRC worms on your system.
And from there the AutoStartViewer to see if anything suspicious is starting with Windows, as the Expl32 does so, hidden and makes more changes to your registry.
You might like to install Port Explorer to look for suspicious connections real time and you can spy into datapackets from and to your system which might spread some more light.
TDS to scan with every option deep and thoroughly and look through the alerts list.
Also there in Network it has the traffic bridge and port listen options to look deeper in and communicate with datapackets and change them!
In the registered version of TDS (same as the evaluation you would just have installed but with a registration in it which unlocks a few extra options) is a script Screx with which you can do lots of extra to know about your intruder and euhmmm.. some more to get info.
WormGuard to block suspicious files and give you the option to look into the file in the save mode. All these have a free evaluation time.

Please keep us informed!
__________________
Jooske
"o_o"
  #3  
Old June 30th, 2003, 07:59 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,399
Default Re:whodunnit?

Quote:
quoting: Jooske link=board=31;threadid=10862;start=0#msg70662 date=1056973234]
sending it to the NOD32 guys at Eset, i can't recall their samples email addy at the moment.

Samples to Eset
__________________
Regards,

Pieter
It´s nice to be important, but it´s more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #4  
Old July 10th, 2003, 01:22 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re:whodunnit?

The EXPL32.EXE will have a HideWindow tool hiding it and lots of other scripts.. these mIRC based trojans are IRC bots, and connect to a specified IRC channel to wait for commands.

Email me gavin@diamondcs.com.au for more info, please let me know what folder you found the trojan file in - if it is a new folder which the trojan created such as

c:\Winnt\web\printers\images\

Then the entire folder contains trojan scripts, and I can tell you exactly what it does (albeit it complicated). Some of these bots have spreading capabilities, and scan for more open machines to infect (you would see a psexec.exe possibly renamed)

If the files are spread throughout a normal folder such as the Windows\system32 folder then they will be a lot harder to locate
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:45 AM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums