CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Onlinegames keyloggers and fake Software for Worldofwarcraft
Goto page Previous  1, 2, 3, 4  Next
 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Tadrith

Guest
IP: 130.85.*.*






PostPosted: Sat Aug 04, 2007 3:53 pm    Post subject:
Reply with quote

Please edit the links I posted to keep them from being clickable Embarassed I realized after I clicked submit that I should have done that, and being a guest I can't edit my post.

Back to top
solcroft

MIRT Hunter


Joined: Apr 01, 2007
Posts: 188

MIRT

PostPosted: Sat Aug 04, 2007 8:19 pm    Post subject:
Reply with quote

Thanks for the links Tadrith. The first one used a ANI and exploit combo to drop a trojan (10% detection @ VT), which I've tossed into the Listserv.

Incidentally, I wasn't able to visit the second and subsequent links; looks like I've probably been IP-banned? I'll leave them to someone else, I guess.

Back to top
View users profile Send private message
Tadrith

Guest
IP: 130.85.*.*






PostPosted: Sun Aug 05, 2007 9:11 am    Post subject:
Reply with quote

You're welcome. I have a question though if you don't mind. I did click on the first link before posting them here, but I have scanned with multiple antivirus softwares including Avast!, which you listed in the Listserv as being one of the ones that actually detects this (Assuming that lese.exe is thhe correct entry to look at), but nothing has turned up on my computer from the scans.

I use Firefox to browse, so is the exploit that it uses an IE exploit or something that is known and already has a security fix? Should I still be worried that I might have this trojan?

Back to top
solcroft

MIRT Hunter


Joined: Apr 01, 2007
Posts: 188

MIRT

PostPosted: Sun Aug 05, 2007 11:45 am    Post subject:
Reply with quote

Using a browser that doesn't use the IE engine (such as Firefox and Opera) is one of the surer ways to avoid Internet trojans that exploit browser vulnerabilities. If your copy of avast! (which detects this trojan, according to VT) is up to date and reports nothing, then it's safe to say you're clean.

Back to top
View users profile Send private message
Dommer

Cadet
Cadet


Joined: Aug 06, 2007
Posts: 1
Location: USA

PostPosted: Mon Aug 06, 2007 4:03 am    Post subject:
Reply with quote

I got a hold of the same forum post as Tadrith. However I did not have any anti-virus programs installed. I downloaded spybot, and Avast, but I don't have AVG because I lost my free key.

Spybot came up positive for an old trojan, and avast came up with nothing during a start up scan, a thorough with archives, and a standard scan after spybot removed the other trojan.

I use firefox and don't even have IE installed on my computer any more, is there anything else I should do in hopes of taking care of a potential trojan?

Back to top
View users profile Send private message
blindmice

Guest
IP: 65.175.*.*






PostPosted: Mon Aug 06, 2007 11:05 pm    Post subject:
Reply with quote

Wow thank you guys so much for your work. I clicked on the same link from the rogue forums and I have been freaking out for the past 8 hours scanning my computer with multiple things.

I use Firefox so I was pretty sure I hadn't been keylogged, but I didn't want to take any chances. I'm scanning my computer right now with the F-Secure.

Thanks again!

Back to top
grah

Guest
IP: 24.168.*.*






PostPosted: Mon Sep 10, 2007 7:56 pm    Post subject:
Reply with quote

Tadrith wrote:

Code:

http://world0fwarcraft.net/my.php?image=wowscrnshot015505zh5.jpg

http://world0fwarcraft.net/my.php?image=wowscrnshot014736pm9.jpg

http://world0fwarcraft.net/my.php?image=wowscrnshot014751fb6.jpg

http://world0fwarcraft.net/my.php?image=wowscrnshot062407014649iz8.jpg

Links disabled by moderator


Yes, I clicked on one of these as well.. I think i'm clear, kaspersky identified a file similar to that shown above by the OP as one they commonly use, but i'm still unsure if i'm clear. It was identified and I deleted it, kaspersky has found no other files. Should be fine, right?

Back to top
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5864

MIRT Premium

PostPosted: Tue Sep 11, 2007 10:40 pm    Post subject:
Reply with quote

Just to be sure I suggest you update Kaspersky and scan your entire HD.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
IP: 89.114.*.*

Guest






PostPosted: Sun Sep 16, 2007 11:04 pm    Post subject:
Reply with quote

Popped up yesterday, 16th August on the EU Moonglade realm forums. Same deal, raid on Halaa. A friend of mine actualy saw a max-level player completely naked next to a vendor and was thinking "Hacked".

Thread in question:

Quote:
http://forums.wow-europe.com/thread.html?topicId=771320095&sid=1

Back to top
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5864

MIRT Premium

PostPosted: Mon Sep 17, 2007 12:56 am    Post subject:
Reply with quote

I tried to download the files but I wasn't able to.

If you find any other on the WOW forums please post them here.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
kittikat

Cadet
Cadet


Joined: Oct 04, 2007
Posts: 2
Location: USA

PostPosted: Thu Oct 04, 2007 9:44 pm    Post subject:
Reply with quote

I found this:
\\
DON'T CLICK LINKS




i have nfc how to make them unclickable!!!!!





Shapeshifting proposals (Again, with pics)

...okay, so by a disgusting stroke of bad luck, I had typed out this HUGE post with

intricate detail in everything I had to say... but... my computer died... so I lost it.

I'll make this short and sweet.

I'm posting this now only because I've noticed the abundance of blue posts lately. I'm just

hoping this thread will get some attention. I haven't finished fleshing out all of my ideas

or my sketches, but this should be enough to run with for now.

Bear form:
The size needs to be addressed. We're the same size at level 10 as we are at level 70.

That's just wrong.

Personally, I think, like hunter pets, bear form should scale up as we level.

http://www.vhgen.cn/albums/x1/seymourseesmore/currentbearformsize.jpg

This is the about the size we are, proportionally, to our characters (height wise,

obviously male tauren are wider and whatnot). I think at level ten we should start out

really small (like hunter pets):
http://www.vhgen.cn/albums/x1/seymourseesmore/proposalbearformlevel10size.jpg
And eventually grow to be a lot bigger:
http://www.vhgen.cn/albums/x1/seymourseesmore/proposalbearformlevel70size.jpg

That's all there is to that. Okay, so on with dire bear form.

It's ridiculous that dire bear form looks the EXACT SAME as bear form. A lot of ideas have

been suggested, but in my opinion, the most prominent one is to give dire bears armor and

charms and whatnot all over the place, similarly to epic flight form.

Well, I'm not the best at designing armor, but this is what I came up with:
http://www.vhgen.cn/albums/x1/seymourseesmore/shoulderarmor.jpg

They're weird, druidic kind of shoulder pads, basically. It's a claw with vines and whatnot

hanging down from it, and a bushel of leaves above it. (I swear the original post had a way

better description, but that's what I've got now.) Also, I think dire bear should have...

battlemarks, so to speak, or scars, implying that they're more experienced than wimpy

little level 10 bears. I also thought it might be cool to go on some kind of quest chain at

40 for dire bear form, but I dunno what it would entail, or I'd go into more detail.

Well, that's all there is to that. Let me move on.

Tauren Cat Form

There's no denying that tauren kitties look retarded. The most obvious thing that NEEDS to

be addressed is to CLOSE OUR FREAKING MOUTHS! PLEASE!

Aside from that, I think there needs to be a differentiation between male and female.

FEMALE LIONS DO NOT HAVE MANES. END OF STORY. I'm tired of looking butch in cat form. I'm a

girl, dammit! (The same applies, in my opinion, for moonkin: give us curves or something. I

didn't get a chance to sketch moonkin this time though, I'll update the post if I do.)

So here's a picture go go along with my ideas:
http://www.vhgen.cn/albums/x1/seymourseesmore/kittymalevs.female.jpg

As you can see, I also made the horns facing backwards. It looks better, in my opinion,

than front-facing horns, which are just awkward, but I don't expect blizz to change this.

(I'd also like to state for the record that I wouldn't at all mind removing them

altogether.)

Also, tauren kitties are just a bit plain. They need markings. The weird druidic symbol

present in bear form, I think, should also be in kitty form, on the shoulder. Just because

I think it looks cool.

Okay, last item I need to deal with:

Customization!!

ALL DRUIDS LOOK THE SAME. That's just wrong.

When you first create your character, you change their skin color, their hair color, their

face, horns/face markings, hair styles, all of that good stuff. Why not apply the same

principal to shapeshifting? The colors and whatnot would correlate with what your actual

toon looks like. Example: I'm a brown-and-white spotted cow.
(http://www.vhgen.cn/albums/x1/seymourseesmore/?action=view&current=dyani.jpg, for

reference.)
SO, why not make me a brown-and-white spotted bear? Black "mane" thing? Same style and

color horns? It would make me ME, and not just another druid bear. Same applies for night

elves: if you're a lavender-skinned night elf with dark blue hair and face stripes, why not

be a lavender-skinned bear with a dark blue mane and face stripes? I'm sure the druid

community would appreciate a little individuality, don't you?

Anyway, that's all I have for now. Like I said, I didn't get to sketch moonkin or make any

decent color references, but I wanted to get this post in before the blues went away.

Suggestions on improvements are open, of course.

And in conclusion, friends, I give you this:

http://www.vhgen.cn/albums/x1/seymourseesmore/loldruid.jpg

(Disclaimer: You can use my images all you want, but please, PLEASE do not claim them as

your own. Credit to me is always nice, but not necessary. Plagiarism is a crime, fol[/u][/i][/b]

Back to top
View users profile Send private message
kittikat

Cadet
Cadet


Joined: Oct 04, 2007
Posts: 2
Location: USA

PostPosted: Thu Oct 04, 2007 10:20 pm    Post subject:
Reply with quote

oh ya, and i had clicked on one of the links above in the original post.

I use Firefox so was wondering if I'm still screwed?

Back to top
View users profile Send private message
xJSTx

Captain
Captain


Joined: Apr 02, 2007
Posts: 691
Location: UK
MIRT

PostPosted: Fri Oct 05, 2007 12:23 am    Post subject:
Reply with quote

I disabled the links for you. I suggest you read this http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
And this http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview

Then follow all the instructions and post your HJT log here CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5864

MIRT Premium

PostPosted: Fri Oct 05, 2007 4:49 am    Post subject:
Reply with quote

Code:
vhgen.cn
appears to be offline so I can't grab any samples from it.

If you find any more possible malware files please post them in this forum.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
JJJJJJJ

Cadet
Cadet


Joined: Oct 06, 2007
Posts: 1
Location: USA

PostPosted: Sat Oct 06, 2007 8:26 pm    Post subject:
Reply with quote

What exploit are they using to infect people? Who are vulnerable to it?

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Goto page Previous  1, 2, 3, 4  Next
Page 2 of 4

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer