QUOTE(MonkeyFiend @ Mar 14 2008, 08:34 PM)
PB released a new server version the other day with a few major changes to it. Some Great changes - partially written by a skilled and quite probably handsome person (
)
As you may know you computer will run the processes pnkbsta and pnkbusterb -it also runs pnkbstrk as a windows service
The K service is executed from C:\WINDOWS\system32\drivers\PnkBstrK.sys
The packing of the file means that it can't be scanned by antivirus - this packing makes it harder for hack makers to tinker with the internal workings of the PB software.
Bitdefender is falsely identifying the K service as a virus.. see here:
http://forum.bitdefender.com/index.php?sho...amp;#entry23995The real virus however drops and execute a program that will install a second component (wincom32.sys) which is a rootkit component that will hide itself and its configuration file wincom32.ini. The following key (HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wincom32) is created in order ensure that the driver is loaded when Windows starts. The "ini" file (wincom32.ini) contains a white list (a peers list of infected machine) and a black list. Wincom32.sys contains a secondary executable file that updates wincom32.ini. This executable can also download and run different files. It uses port 7871 UDP to communicate with other hosts (similar with a P2P network). It may receive commands to download from one of this hosts.
Basically a false positive.
Haha Nice 1 Fiend, show them Punky boys how to do it properly...
Yeah I just wasn't sure what it was, what I ended doing was adding the Pb folder to the Exceptions list, and so far it seems perfect. Just a heads up about it, cos I rem that guy from your clan was having similar problems yesterday after he re-installed BF2 and everything, and he was still getting kicked immediately. Maybe it had something to do with this false-positive