Server **** Already???

sirnogard
sirnogard Posts: 4 Arc User
edited August 2008 in General Discussion
Wow just now, as soon as auto patch kicked on, Window's Defender went into action and caught TrojanDownloader:Win32/Agent coming from the perfect world site. :mad: This is new since I logged in when servers first went up with no problems.

More info at: http://www.microsoft.com/security/portal/Entry.aspx?name=TrojanDownloader%3aWin32%2fAgent&threatid=14992
Post edited by sirnogard on

Comments

  • roxy
    roxy Posts: 0 Arc User
    edited August 2008
    Hmm really? I use Avast and it didn't detect anything.
    6to4uv.jpg

    To the world, you may be one person
    But to one person, you may be the world
  • zoefox
    zoefox Posts: 225
    edited August 2008
    I seriously don't think there would be a problem here. Compaines are too good to have things like that happen.
  • kgbist
    kgbist Posts: 1 Arc User
    edited August 2008
    I seriously believe not...
  • esc0rz
    esc0rz Posts: 0 Arc User
    edited August 2008
    Kaspersky tells me nothing. It might just be you.
  • sirnogard
    sirnogard Posts: 4 Arc User
    edited August 2008
    I've got massive years in tech support, so I did a little looking around.

    When the Icon is click it goes to patch.exe to start the game, but if you use Xfire it goes straight to the main .exe to start the game.

    So either patch.exe is hiding the Trojan, or since Xfire bypasses it it reports the game starting as a "false positive".
  • ren
    ren Posts: 662 Arc User
    edited August 2008
    The patcher downloads things in a manner similar to how a virus might, so it's probably a false alert.
    [SIGPIC][/SIGPIC]
    Official PWI irc: (mirc command, opens in a new window and won't interfere with any servers you're already on) /server -m irc.deltaanime.net -j #pwint
  • esc0rz
    esc0rz Posts: 0 Arc User
    edited August 2008
    sirnogard wrote: »
    I've got massive years in tech support, so I did a little looking around.

    When the Icon is click it goes to patch.exe to start the game, but if you use Xfire it goes straight to the main .exe to start the game.

    So either patch.exe is hiding the Trojan, or since Xfire bypasses it it reports the game starting as a "false positive".

    Perhaps then you may assist those who can't update? Check this thread http://pwi-forum.perfectworld.com/showthread.php?t=17251 and share what you think the issue might be.
  • darthpanda16
    darthpanda16 Posts: 9,471 Arc User
    edited August 2008
    That is a general notification when a program does something an anti-virus doesn't like.

    PW uses a password protector partner app to help keep your password from being keylogged (such as like on a public computer), so your antivirus might flag it, when it really is just the game.

    Hope that helps some.

    But please be diligent on your antivirus programs! Try to keep everything up to date!

    :D
    Do you need help learning about patching the game, installing it, changing antivirus/firewall settings, changing network settings, learn how to use a computer, keeping your PC maintained and more?
    Visit our BRAND NEW Knowledge Base & Support Website! - Tech Support Flowchart - Panda Caught on Camera
  • callandor
    callandor Posts: 0 Arc User
    edited August 2008
    Omg and admin!!!! :O THEY ARE AWAKES!!!
  • roxy
    roxy Posts: 0 Arc User
    edited August 2008
    callandor wrote: »
    Omg and admin!!!! :O THEY ARE AWAKES!!!

    I heard they have at least 1 person for every shift. That means there's always one gm on 24/7.
    6to4uv.jpg

    To the world, you may be one person
    But to one person, you may be the world
  • magoo
    magoo Posts: 42 Arc User
    edited August 2008
    That is a general notification when a program does something an anti-virus doesn't like.

    PW uses a password protector partner app to help keep your password from being keylogged (such as like on a public computer), so your antivirus might flag it, when it really is just the game.

    Hope that helps some.

    But please be diligent on your antivirus programs! Try to keep everything up to date!

    :D

    Yah i was gonna mention the anti hax . Most likely uses some of the triggers that trojans etc use to catch the nasties out.
    All hail the adman.
    :eek: :eek: :eek:
    [SIGPIC][/SIGPIC]
  • sirnogard
    sirnogard Posts: 4 Arc User
    edited August 2008
    esc0rz wrote: »
    Perhaps then you may assist those who can't update? Check this thread http://pwi-forum.perfectworld.com/showthread.php?t=17251 and share what you think the issue might be.

    Wow 27 pages! A wee bit for me to read now, as my eyes are swimming.

    From what I've read it sounds like a router issue since one person had it happen on his desktop and laptop. Off hand I don't know the ports for this game, but I would try to port forward or port trigger.

    Here's a site that has about the best info on the Net. http://portforward.com/
  • sirnogard
    sirnogard Posts: 4 Arc User
    edited August 2008
    That is a general notification when a program does something an anti-virus doesn't like.

    PW uses a password protector partner app to help keep your password from being keylogged (such as like on a public computer), so your antivirus might flag it, when it really is just the game.

    Hope that helps some.

    But please be diligent on your antivirus programs! Try to keep everything up to date!

    :D

    I was thinking patch.exe was doing something that the other exes needed, and that's what triggered everything.

    I uploaded the report to Microsoft SpyNet, hopefully that'll prompt a fix on that false positive. :)
  • aquablade1980
    aquablade1980 Posts: 8 Arc User
    edited August 2008
    I seriously believe not...
  • severan
    severan Posts: 703 Arc User
    edited August 2008
    Perfectworld Element.exe also tries to monitor your "Memory usage" like data on your RAM and tries to modify it to optimize the game play, some old scanners using out-dated heuristics to detect cheap Trojans will show an error when it happens.

    I'm a CEH and i know this ;) PWI is clean
    Sever: Lost City
    Making players RageQuit since 2004

    [SIGPIC][/SIGPIC]

    Hello, You have reached Severan on The RQ carebear's automated phone system
    To tell me I've got no life and I live in my mom's basement, press 1. To tell me that you are logging on your level 90 character to kick the **** out of me, press 2. To tell me that your friend is a GM and you're getting me banned, press 3. To tell me RQ is going to fail and talk more **** about RunQuick press 4. If none of these options fit your need please hold the line for idiot assistance, they will be with you shortly...
  • ryuuzaki
    ryuuzaki Posts: 680 Arc User
    edited August 2008
    If it's detecting it as possible generic trojan, it's because it's realized "Hey, this program is automatically connecting to a remote site to download files onto the computer..." which is exactly what a trojan does. It's also exactly what a game patcher does. ^_^

    It's just flagging suspicious activity. It doesn't know it's a trojan or virus for sure, it's just exhibiting similar properties to one and alerting you in case you didn't know. It's should be safe to add to the ignore list.
    [SIGPIC][/SIGPIC]
  • desirai
    desirai Posts: 51 Arc User
    edited August 2008
    "That is a general notification when a program does something an anti-virus doesn't like."

    I lol'd and I dunno why. :3