Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Kal Online
You last visited: Today at 03:58

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Kal Exenia Backdoored.

Discussion on Kal Exenia Backdoored. within the Kal Online forum part of the MMORPGs category.

Reply
 
Old   #1
 
elite*gold: 80
Join Date: Oct 2010
Posts: 2,238
Received Thanks: 1,271
Kal Exenia Backdoored. [+How to Remove!]

Well,no one realized it so far i think.

"Kal Exenia" is backdoored.

Well,After i downloaded the update and started Kal exenia,In my Task manager there appeared a process called "05.gtx" and the Description was something with "VirtualDub blabla"

That Virtualdub shit downloads a file on ure computer called "svchost.exe" which is in User->AppData->Roaming
(WHEN U CANT SEE APPDATA,PRESS ALT THEN THERE APPEARS A BAR ON TOP..Press folder options there and then "View" "View Hidden files and folders" tick it"


The "svchost.exe" from exenia:



Backdoor:Win32/Fynloski.A: is a trojan that allows unauthorized access and control of an affected computer.

Removal:
First end the process "05.gtx" and "svchost.exe".u will find svchost.exe in process list because the descrption is not "Hostprocess"..The Description is "Dubline blablabla" something like that.End that process then go to
User->AppData->Roaming and delete "svchost.exe"

Next..Go to RUN->regedit

Move to
hklm\software\microsoft\active setup\installed components\{yl429-e1848ab-s6zxn-1n2j88-cyg87qm5s}

And remove the "svchost.exe" there.

Then go to
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

And remove the "svchost.exe" there

Done,you removed the virus.

PS:
hklm\software\microsoft\active setup\installed components\{yl429-e1848ab-s6zxn-1n2j88-cyg87qm5s}

they key {yl429-e1848ab-s6zxn-1n2j88-cyg87qm5s}} is different,just check them!


FOR SAFETY CHANGE URE PASSES (Epvp,msn etc)

when you start exenia again the virus with probably come back.


Need any Support?: msn :



ANOTHER infected file:
"cd.scr" in KalExenia->Map

the format is .scr (Screensaver) And it opens up like a normal .exe file.


21kb sized with UPX

the engine.exe is binded with a file called "cd.scr",When you Start "KalExenia" the "cd.scr" will automatically run with the engine.exe and it drops svchost.exe in ure process and AppData Folder.

So Everytime you start kalexenia,The virus will come back.
Fremo. is offline  
Thanks
10 Users
Old 02/20/2011, 23:06   #2
 
*TheGhosT*'s Avatar
 
elite*gold: 0
Join Date: Feb 2011
Posts: 224
Received Thanks: 35
i saw 0.5 too but wasnt sure tnx bro;=)
*TheGhosT* is offline  
Old 02/20/2011, 23:25   #3
 
strik3r2k5's Avatar
 
elite*gold: 0
Join Date: Jun 2006
Posts: 1,203
Received Thanks: 366
Now I'll crash the server till I go sleep
strik3r2k5 is offline  
Thanks
6 Users
Old 02/20/2011, 23:58   #4
 
hoseta's Avatar
 
elite*gold: 0
Join Date: Jan 2008
Posts: 310
Received Thanks: 50
YA I did that but i still have cliend crash when open dll like b4. dbghelp wont work any idea? i fallow ur all step and svhost is no more run
hoseta is offline  
Old 02/21/2011, 00:10   #5
 
Dreckvieh's Avatar
 
elite*gold: 20
Join Date: Nov 2007
Posts: 1,380
Received Thanks: 147


Uploaded with
Dreckvieh is offline  
Thanks
3 Users
Old 02/21/2011, 00:15   #6
 
elite*gold: 0
Join Date: Feb 2010
Posts: 311
Received Thanks: 46
Mhhhh... I checked my PC with malwarebytes too, but he found nothing :O
LaithalDeen is offline  
Old 02/21/2011, 00:17   #7
 
elite*gold: 80
Join Date: Oct 2010
Posts: 2,238
Received Thanks: 1,271
probably ure antivirus deleted it before.
Fremo. is offline  
Old 02/21/2011, 00:18   #8
 
elite*gold: 0
Join Date: Feb 2010
Posts: 311
Received Thanks: 46
well, that would be good
LaithalDeen is offline  
Old 02/21/2011, 00:18   #9
 
Dreckvieh's Avatar
 
elite*gold: 20
Join Date: Nov 2007
Posts: 1,380
Received Thanks: 147
Quote:
Originally Posted by LaithalDeen View Post
Mhhhh... I checked my PC with malwarebytes too, but he found nothing :O
musst malewarebytes immer selber updaten -> update und check nochma
Boahr was wird nur aus den ganzen Kal Servern !
Dreckvieh is offline  
Old 02/21/2011, 00:23   #10
 
EddyGER's Avatar
 
elite*gold: 0
Join Date: Nov 2008
Posts: 1,181
Received Thanks: 254
Quote:
Originally Posted by LaithalDeen View Post
Mhhhh... I checked my PC with malwarebytes too, but he found nothing :O
try it with hijackthis
EddyGER is offline  
Old 02/21/2011, 00:28   #11
 
elite*gold: 0
Join Date: Jan 2008
Posts: 388
Received Thanks: 45
Quote:
Originally Posted by hoseta View Post
YA I did that but i still have cliend crash when open dll like b4. dbghelp wont work any idea? i fallow ur all step and svhost is no more run
this is not a tut to get dbgheelp to work lol..

Power_Stunner is offline  
Thanks
1 User
Old 02/21/2011, 00:34   #12
 
elite*gold: 0
Join Date: Feb 2010
Posts: 311
Received Thanks: 46
Quote:
Originally Posted by EddyGER View Post
ty it with hijackthis
ty found it

Quote:
Originally Posted by Dreckvieh View Post
musst malewarebytes immer selber updaten -> update und check nochma
Boahr was wird nur aus den ganzen Kal Servern !
findet immernoch nicht ^^
LaithalDeen is offline  
Old 02/21/2011, 00:34   #13
 
hoseta's Avatar
 
elite*gold: 0
Join Date: Jan 2008
Posts: 310
Received Thanks: 50
hmm ok but some1 shout on horns that is why dbghelp dont work xd my bad didnt read all now ok sorry for the question.
hoseta is offline  
Old 02/21/2011, 00:39   #14
 
elite*gold: 80
Join Date: Oct 2010
Posts: 2,238
Received Thanks: 1,271
Dude the server is backdoored and u still play?

150 people on..

after people read this thread

140 of 150 still playing..kids doesnt even know what a virus is o_o
Fremo. is offline  
Old 02/21/2011, 00:41   #15
 
elite*gold: 0
Join Date: Jan 2008
Posts: 388
Received Thanks: 45
Quote:
Originally Posted by hoseta View Post
hmm ok but some1 shout on horns that is why dbghelp dont work xd my bad didnt read all now ok sorry for the question.
this thread is about kal exenia having a virus why u still in game trying to get the hack to work xD





let me stop messing with u xDD
Power_Stunner is offline  
Reply


Similar Threads Similar Threads
Kal Exenia
02/22/2011 - Kal Online - 6 Replies
Plz any1 here know how u make to .dll hack work in Kla exenia ? Plz Help me :D:handsdown: Thx ^^
Frage: Ist der neue kukbot noch backdoored
04/23/2010 - Diablo 2 - 1 Replies
also verkauft der noch mein zeug??
any hack for exenia server?
11/25/2008 - Kal Online - 2 Replies
Hii... I am here to ask the server for some cd exenia server if you have someone please get me please. Thank you!
[QUESTION] - Old Backdoored Proxy
03/02/2008 - Conquer Online 2 - 8 Replies
Hey guys, Just a quick question - Does anyone still have a copy of the old backdoored proxy? I beleive it was net7 who put the backdoor in if that helps...? If you dont' want to post it publically could you PM me a link to it? My brother is starting to bug me so ima teach him a lesson for a week or so :p Would also be a good addition to my archive of ancient CO Hacks/Tools :D Thankyeww ;)



All times are GMT +2. The time now is 03:58.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.