Firstly: The remote access tool would have to be embeddable within the precise 64 kb range available. I find this somewhat unlikely, especially after conversion to TGA.
Secondly: If it was done through Toribash, then the IP will be one of the Toribash servers. That is where Toribash gets its data. We'd have to look at where it got its data to figure out the true source.
Thirdly: If it is remote access, it is not something we can fix.
Fourthly: There should be no data dumping injections or ASM injections, if there are, they are hampa's fault. However, there likely AREN'T.
Fifthly: GET SOME EVIDENCE.
In fact, the fifth point is so important, I will do this:
GET SOME EVIDENCE.