And there were 3 files planted on my sys, as follows;
BFTAWUL.DLL
GIYGFQM.DLL
GIYGFQM.EXE
All of the above were created on 28/07/03 and their naming is entirely random. Residing in \Windows\System32 the EXE is called from the registery on startup.
As previously stated, these did NOT originate from the EQEMU source, but from a malicious (as yet unidentified) IRC user.
Now, is it just a coincidence that the same channel that this joins upon finding a connection is the `Forever Hacking' as featured in Shawn319's sig?
I'm getting a sense that you guys are shielding someone.
Dog......meet .....Bone......
I'm sure you're aware of the phrase and the implication.
|