Work test computers ...

iam29a

Member
Apr 24, 2003
101
0
0
Last night I got a little bored and in preparation for such no-action times I brought in some anti-virus software for one of the test computers. The dang PC had a company workstation image on the disk, which had a very locked-down Norton anti-virus installed and a virus definition file dated May, 2002. Jeez! BTW, this disk image was part of a VPN trial, which is over with.

Well, I had to literally rip the pre-existing Norton from the registry and make 3-4 install-uninstall attempts to get past the part of a managed server not being reachable, but in the end it worked. I did a scan of the disk and it found 334 files containing one or more virus. Dear god, I wonder how that happened? Most said something about 'irc' and were backdoor trojans. I think a program got installed that generated these files as a virus, and somehow that program got auto-booted at system boot.

Anyone hear of rmtcfg.exe? This file, and a bunch of other files were sitting in a directory of the same name, inside the system32 directory. I left work yesterday running a third scan with continued virus detection (its still detecting them) and each time I instruct NAVC to delete contaminated files (no quarentine, just deletion).
 

Scarpozzi

Lifer
Jun 13, 2000
26,389
1,778
126
I'm not sure what rmtcfg.exe is, but I couldn't find any results from doing a google search on it. That makes me think it was associated with a program and not a virus. Usually virus program files are indexed for searches. You might want to investigate what other software you have on your system and find out what program that file belongs to.
 

FoBoT

No Lifer
Apr 30, 2001
63,082
12
76
fobot.com
rmtcfg.exe sounds like "remote configuration" to me , which does sound like something associated with a trojan

trojan's are easy to deal with

pull the network cable out
reimage/reformat-reinstall the OS, problem solved
 

djheater

Lifer
Mar 19, 2001
14,637
2
0
Originally posted by: FoBoT
rmtcfg.exe sounds like "remote configuration" to me , which does sound like something associated with a trojan

trojan's are easy to deal with

pull the network cable out
reimage/reformat-reinstall the OS, problem solved


Agreed.

If in doubt, format.
 

guyver01

Lifer
Sep 25, 2000
22,135
5
61
Norton Doesn't handle 'irc trojans' for some reason.. neither does Mcafee..
the only program i found that CAN handle irc trojans is from Computer Associates..
http://www.my-etrust.com/

Get the free trial of Etrust EZ Armor
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |