SunQuest
           Windows Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Try It Free
Go Back   Dev Shed ForumsOperating SystemsWindows Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Be the architects of evolution and help create the mobile internet future. It’s your move---enter to win here!
  #1  
Old September 8th, 2003, 12:29 PM
jerromy jerromy is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2003
Location: Hillsboro, OR
Posts: 5 jerromy User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
rmtcfg

I posted earlier about my problems with IE6 and bandwidth but as I was investigating I found a new problem. I was running a virus scan with Norton and noticed it went through a file winnt\system32\rmtcfg. I couldn't find this file in windows explorer or total commander. I then assumed that the file was a system or hidden file so I although I am a total newbie I searched the net and figured out how to remove attributes etc. When I opened the file I noticed that it has these .bat and .exe files labelled hidden, hidden32, hiddenrun, mybot, ftp and host of other nasty sounding files. My questions are these:

(1) Do I just delete the whole file?

(2) How is this stuff getting through Norton Antivirus, Norton Internet Security, Ad Aware, and Spybot?

(3) If this got through, how deep does this problem go?

(4) Am I better off starting over from scratch?

Reply With Quote
  #2  
Old September 9th, 2003, 02:20 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 13
Seems to be an IRC based virus.

McAfee seems to detect it:

http://vil.mcafee.com/dispVirus.asp?virus_k=100427


Quote:
When the dropper is run on the victim machine, multiple files are installed to the following directory:
C:\WINNT\SYSTEM32\RMTCFG2

Other subdirectories are created within this, once the package is running (some are IRC client related):
c:\WINNT\SYSTEM32\RMTCFG2\DAT
c:\WINNT\SYSTEM32\RMTCFG2\DOWNLOAD
c:\WINNT\SYSTEM32\RMTCFG2\LOGS
c:\WINNT\SYSTEM32\RMTCFG2\PLUGIN
c:\WINNT\SYSTEM32\RMTCFG2\SOUNDS


Make sure you update McAfee and recsan. HTH

Reply With Quote
  #3  
Old September 9th, 2003, 02:25 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 13
Sotrry, I thought you had McAfee. I see you have Norton.

Maybe try a McAfee free scan at:

http://us.mcafee.com/default.asp

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsWindows Help > rmtcfg


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway