PDA

View Full Version : FFXI Japanese 2 English Software Translator IS A TROJAN


KiTA
05-15-2003, 10:59 AM
Get a free Virus scanner here if you got hit by that idiot.

http://www.grisoft.com

I'll go research a trojan removal tool for that specific backdoor next, watch this thread for more details.

KiTA
05-15-2003, 11:21 AM
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.optixpro.10.b.html
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.optixpro.11.html

This virus is also known as Backdoor.OptixPro.10b and .11. You can find removal instructions on those sites above.

iceroot
05-15-2003, 11:28 AM
yes but fucker made it undetectable through hex editing and exe compressing/scambling he hijacked mah glourious passwd

KiTA
05-16-2003, 07:13 AM
Ok, something you guys may have missed:

This trojan first installs itself, THEN it gives you a fake "This program has crashed error." So if the program crashed, you may still be infected. I will go ahead and summarize the removal instructions for the worm when I get a bit more time later today.

Basically, what you need to do is run "msconfig" and look in the startup tab. Then, look for something that "looks out of place." Might say something like "MSDOS722.EXE" or some weird random crap like that. Just click it off, reboot, and delete the file from your computer. If you can't delete it after a reboot, go into safe mode and delete it that way, or use a boot disk.

BUT MAKE SURE YOU'RE DELETING THE RIGHT FILE. Usually trojans put themselves in C:\ or C:\Windows to make most people think that they're legit programs... but there ARE legit programs that go in C:\windows and C:\windows\system32.

cactuar
05-16-2003, 07:24 AM
lol japanses knwo computers well you got schooled prolly because your a import player a lil american hater prolly made this up or really rude ass import player

Aeolus
05-16-2003, 07:53 AM
It wouldnt be on of the following would it

RUNDLL.32.EXE NvQTwk,NVcPlDaemin initialize

"C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /BACKGROUND

KiTA
05-16-2003, 08:46 AM
Originally posted by Aeolus
It wouldnt be on of the following would it

RUNDLL.32.EXE NvQTwk,NVcPlDaemin initialize

"C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /BACKGROUND

Those look legit, but I'd look in C:\program files\msn messenger\ and see if you can manually run that program.

TB_Iris
05-16-2003, 09:17 AM
RUNDLL32 is fine..those others, I dunno about.

tpstarcraft
05-16-2003, 09:27 AM
let me guess, you can download this crap in Kazaa right?

people never learn, DO NOT DOWNLOAD ANY EXCECUTABLE FILE IN KAZAA OR ANY OTHER FILE-SHARED PROGRAMS

KiTA
05-16-2003, 03:21 PM
Originally posted by tpstarcraft
let me guess, you can download this crap in Kazaa right?

people never learn, DO NOT DOWNLOAD ANY EXCECUTABLE FILE IN KAZAA OR ANY OTHER FILE-SHARED PROGRAMS

No, there was some jerk posting the file on about half a dozen different sites where importers hang out (guild sites, FFXIOnline, etc). Surprised he didn't hit gamefaqs.com too.

tpstarcraft
05-16-2003, 03:32 PM
oh well, you will see this file in Kazaa soon or later

Dont Bot Play Fair
05-16-2003, 03:48 PM
Can some one tell me the Name of the person who has made the names if i know who it is or any one does can a GM and the GM can Expell him for that...

Anubis87
05-18-2003, 12:36 AM
Good god I have'nt downloaded that.. Can you only get that virus by downloading it? Or does it use backdoors to your computer through internet? Then I'd have to use a firewall.

CliXx3r
05-18-2003, 12:45 AM
Originally posted by Anubis87
Good god I have'nt downloaded that.. Can you only get that virus by downloading it? Or does it use backdoors to your computer through internet? Then I'd have to use a firewall.

hmmm.. well it says that some firewalls doesnt work for this trojan ..i had no anti-virus prog or a firewall ...well a friend is gonna burn a cd with a firewall and a anti-virus prog for me, cause i dont dare to be on the internet because im INFECTED

and that means no ffxi for me :mad: :mad: :mad:

Anubis87
05-18-2003, 12:46 AM
So you can get the virus without downloading the acctual file?

CliXx3r
05-18-2003, 12:54 AM
hum, idunno ...i got the link from a friend...so i dl it ...why arent u on icq ...? is your icq still not working...?

Anubis87
05-18-2003, 12:58 AM
Yep not working at all >.<

CliXx3r
05-18-2003, 01:02 AM
is it the password, that your missing??

if anyone here is a 1337 haxxor, could u plz destroy the person computer that is responsible for the trojan??

Anubis87
05-18-2003, 01:05 AM
Yep the password and they say my mail is not the right one for that account.

CliXx3r
05-18-2003, 01:16 AM
make a new account then

sorry for the off-topic thingy

annihialtor
06-20-2003, 08:49 PM
every thing u need to know is right here i dont know if this is the same guy but if it is here is all the information about him. on this thread http://www.ffxionline.com/forums/showthread.php?s=&threadid=12331&highlight=firewall