Welcome, Guest. Please login or register.
October 06, 2008, 06:51:03 AM

Login with username, password and session length

197533 Posts
22748 Topics
54661 Members

Latest Member: ahmadaakhan01

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo BOClean Anti-Malware
| | |-+  COMODO BOC thinks MIRC is a trojan?[Resolved]
« previous next »
Pages: [1] Go Down Print
Author Topic: COMODO BOC thinks MIRC is a trojan?[Resolved]  (Read 4512 times)
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« on: April 22, 2007, 11:32:32 PM »

I just had a strange situation. When I launched MIRC, BOC popped up to state it was a Trojan. At that point Process Guard kicked in and terminated BOC, as it hasn't yet been given Terminate privileges.

Any thoughts?

Toggie
« Last Edit: September 09, 2007, 11:58:50 AM by ~cat~ » Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Kevin McAleavey
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 303


Snag a nasty? NO problem! =)


« Reply #1 on: April 22, 2007, 11:39:35 PM »

Yep ... that's correct. MIRC is *the* most frequently used core for what we call "pseudo-rootkits" to control bot networks because it's "legit" and therefore ignored by just about every anti-everything on the planet. Since you're deliberately using it, open BOClean's excluder and drag the icon for it to the excluder box (if you're not using Vista, you can drag a shortcut) and once it appears in there, close the excluder, close BOClean and restart it so it will pick up the fact that you want MIRC ignored and BOClean will leave you alone. Should *another* copy show up somewhere that you don't know about it, BOClean will let you know.

 But that, and a few other "legit tools" were included because of their frequent use as the core of many exploits and malwares. Sorry, but absolutely necessary to do that ...
Logged

"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #2 on: April 22, 2007, 11:42:11 PM »

This is the default action of BOC, if you use Mirc you must exclude it.

Edit: Found the reference (needs to be included in the FAQ/support documents).

MIRC DETECTION INFO, for users of BOClean

Whoops, link is out of date.

IMPORTANT CHANGE in BOClean engine as of this update. Many previous "pseudo-rootkits" have used a popular "chat program" called "MIRC" as the core of their "botnet" core. In almost every case, these rogue usages of the popular MIRC program have had unique factors which allowed us to detect those without interfering with legitimately-used MIRC chat software.
« Last Edit: April 22, 2007, 11:46:30 PM by ~cat~ » Logged

Parched dry and thirsty, knee deep in the river of life.
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #3 on: April 23, 2007, 12:52:21 AM »

Thanks for the replies, I hadn't come across that before.

Toggie

Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #4 on: April 26, 2007, 10:31:47 PM »

Unfortunately, adding MIRC to the 'exclude' list doesn't seem to be working.

I have the app listed in 'exclude' but BOC still wants to close the app when I launch it.

Toggie
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Bluesman
Comodo's Hero
*****
Offline Offline

Posts: 550


Only Amiga Makes It Possible


« Reply #5 on: April 27, 2007, 04:45:21 AM »

Unfortunately, adding MIRC to the 'exclude' list doesn't seem to be working.

I have the app listed in 'exclude' but BOC still wants to close the app when I launch it.

Toggie

I had the same problem, but I just closed BOC and restarted it, and now everything works just fine.
Logged

"The blues are the roots, everything else is the fruits" -Willie Dixon
malva00
Newbie
*
Offline Offline

Posts: 12


« Reply #6 on: April 27, 2007, 12:22:04 PM »

When I opened up my mirc v6.21 for the first time after installing BOC, it worked fine and it's not in my excludes.

Is this normal?
Logged
malva00
Newbie
*
Offline Offline

Posts: 12


« Reply #7 on: April 30, 2007, 06:57:46 PM »

is this the answer to my question?

"IMPORTANT CHANGE in BOClean engine as of this update. Many previous "pseudo-rootkits" have used a popular "chat program" called "MIRC" as the core of their "botnet" core. In almost every case, these rogue usages of the popular MIRC program have had unique factors which allowed us to detect those without interfering with legitimately-used MIRC chat software."
« Last Edit: April 30, 2007, 07:01:50 PM by malva00 » Logged
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #8 on: April 30, 2007, 10:49:44 PM »

I have to add MIRC to excludes, otherwise it's terminated...
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Scott B.
Comodo Family Member
***
Offline Offline

Posts: 66


« Reply #9 on: May 04, 2007, 09:09:27 PM »

Then you probably really do have a Trojan. Because MiRC works fine with BOClean here... I do not have to exclude it or anything.

Uninstall MiRC, delete the entire directory, and use CCleaner or so to securely delete all traces of that directory. Reboot, Reinstall MiRC and see if that helps.

Logged
sojo
Newbie
*
Offline Offline

Posts: 4


« Reply #10 on: August 08, 2007, 02:36:19 PM »

Then you probably really do have a Trojan. Because MiRC works fine with BOClean here... I do not have to exclude it or anything.

Uninstall MiRC, delete the entire directory, and use CCleaner or so to securely delete all traces of that directory. Reboot, Reinstall MiRC and see if that helps.



I tried all that as I was having the same problem as Toggle and mIRC still doesn't work unless I exclude it.  So I excluded it and now when I turn on my computer instead of going to the desktop it goes to the mIRC file.  Anyway to fix that?  Huh
Logged
stradivariuus
Newbie
*
Offline Offline

Posts: 4


« Reply #11 on: September 08, 2007, 05:40:07 PM »

It happened to me too. The Bo ate my Mirc. 1st time i thought something was there like a trojan and i reinstalled mirc. It's the official Mirc form http://www.mirc.com/

So I installed it . I reopende it and imediately Bo ate it again. LOL  Laugh

Then I went to Bo and red all the program . I found out the Exclude Area. Just took the mirc into it and now the 2 programs work wonderfully  Bounce
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 964


CBO "...there is nothing better."


« Reply #12 on: September 09, 2007, 11:58:12 AM »

I'm going to lock the gate on this dead horse.
OP knows the drill.
Logged

Parched dry and thirsty, knee deep in the river of life.
Tags: mirc excluder 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.101 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com