I've tracked a trojan on my server after I noticed some warez being uploaded in an upload folder + they removed a couple of maps in order to create space for their own stuff.
The trojan works as a backdoor and opens a port. Then it runs an ftp like server that enables the user to delete, create and upload/download files and maps. At the same time it tries to connect to irc as a bot.
I have their irc channel and I can see other hacked servers in there. Is there anyway some higher authorities can be informed of this? If possible i would like the ''hackers'' to be tracked down and possibly prosecuted..
A note: C:\WIN\system32\rpcxserv.exe is the backdoor trojan file and is run as a service listed under RPC Interface. When I try to find this file it simply doesn't exist, but It does run and does open the port again after enabling the service.
I've set view all hidden files etc in the map options of windows 2003. Is there anyway this file can be deleted? I've searched google, but non of the virus scanning companies list this file, nor does norton corporate antivirus find this trojan. I've seen around three other cases of infected servers on google, but they didn't mention any of this that could help me out.
For now I've just disabled the service, and the open port is gone...but i do want to delete these malicious files.
Edited by Badaboem