Welcome to the 
undernet IRC network
HomeSitemapServicesWebchatForumCommitteesServersHelppollsProxy scannerNewsNews
*ALERT* mIRC virus spreading around undernet.
[ January 3, 2002 ]


As you may have seen, infected users on undernet are randomly sending out messages which look like this.
"Hey Simba-- to get OPs use this hack in the chan but SHH! //$decode(d3JpdGUGRE4t43"

This trojan installs a script into your mIRC remotes and sends it out to people on every channel you are on. It has also been known to install backdoors on your PC which enable people to "enter / hack" your machine.

If you have typed this command in any channel its possible you could be infected and should follow these steps to attempt to remove it.

step 1.
//var %a = 0 | while (%a != $script(0)) { inc %a | echo -a ( $+ %a $+ )
$nopath($script(%a)) }

step 2.
if you find any suspicious script files (like '-' or 'server.ini' or 'Ä' or
'trojan.ini' ...) then you can use this command to unload/remove them
if you're not sure if a script is suspicious or not join #dmsetup and we'll
take a look at it
replace with the scriptnumber of the suspicious file

//var %a = [Nr] | remove $script(%a) | unload -rs $script(%a)

step 3.
/sockclose *

step 4.
reboot your pc and check if your still infected, if you're still infected, try
reinstalling your script and reboot again, and if you're still
infected after that, join #dmsetup


Thanks to MusicIdea and Da_QuiK for help.





Copyright © 1994 - 2012 - Copyright notice and contacts. Please read our Acceptable use policy. There are 16663 users online