Are you looking for SCRIPT.INI worms?

How DMSETUP viruses work

Someone sends you an EXE file with an enticing name. You run the file and it checks for mIRC. If mIRC isn't found, most of them create many folders with strange names. It creates a new INI file in your mIRC directory that tells mIRC to spread the virus. Then it makes a backup of your MIRC.INI file and overwrites it with a MIRC.INI file that will load the new INI file. The virus will then copy itself to several directories on the hard drive. Then they will add themselves to AUTOEXEC.BAT. Then they display some simple graphics, print some fake error messages and exit. Now if someone joins a channel you are on you will send the EXE file to them. To get rid of the DMSETUP virus under Windows 95/98:
  1. Close mIRC if it is open.
  2. Get an antivirus program. AVP and F-Prot are the best at removing mIRC viruses. Deleting is the proper way to remove the Dmsetup virus files. The reason that I recommend using an antivirus program is that conventional viruses sometimes attach to Dmsetup viruses. I have seen Die-Hard.4000 and Spanska.4250 attached to Dmsetup viruses.
  3. Navigate to your Mirc folder.
  4. Choose Folder Options from the View menu, click the View tab, then click "Show all files".
  5. Select either BAKUPWRKS.INI or BACKUP0412.INI.
  6. Rename it to MIRC.INI.
  7. Navigate to the root directory of drive C:.
  8. Delete CONFIGG.SYS (not CONFIG.SYS) if it exists.
  9. Delete LOGOX.SYS if it exists.
  10. Delete TAGED.LMR if it exists.
  11. Right-click AUTOEXEC.BAT
  12. Choose edit.
  13. Delete the very last line if it loads the virus that you have.
  14. Also delete the second last line if it refers to the virus that you have.
  15. Save and Exit AUTOEXEC.BAT.
  16. The rest are only if there are many strangely-named directories you want to delete
  17. If there are strangely named directories, go to the DOS Prompt.
  18. Type
    CD\
  19. If there are only a few strange directories, you can replace the strange character with "?" For example
    DELTREE SUCK?IT

    DELTREE ?DM2?YF
  20. Otherwise, type
    DELTREE *[ALT-255]*
    Hold down ALT and type 255 on the numeric keypad to make the [ALT-255] character. The stars should be typed in but not the square brackets.
  21. Only answer yes to directories you are sure you want to delete.
  22. When done, type
    EXIT
You should also never accept DCCs that you didn't request.

Please e-mail me if you have any questions, virus samples, suggestions, or comments. Let me know if you find this page useful.

So far, there are at least 6 DMSETUP viruses. None of the Dmsetup viruses I have seen modify the registry or CONFIG.SYS, or delete any files. There are other Dmsetup viruses, but I don't have samples of them. If you have a sample of a Dmsetup vrus not on this list, please send it to me. The names are based on AVP names. The first part of the name is the type(Worm) the second is Dmsetup. The third part is lettering them A,B,C...

Virus Page