I know where the Trojan came from.
I'd advise everyone to steer clear of the EQEmu IRC channel if they wish to avoid this.
Here's a li'l link to help you out. See that `ServerOp - Forever Hacking' in Shawn319's sig? That is also the IRC Channel that the Codeflood.Backdoor connects to whenever an internet connection is established.
Call me a newb, but do not insult my intelligence. It's a lamer type trick and easy enough to remove.
|