Fires of Heaven Guild Message Board  


Go Back   Fires of Heaven Guild Message Board > Fires of Heaven Related Forums > MMORPG General Discussion
User Name
Password
ForumSpy Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Share LinkBack Thread Tools Rate Thread Display Modes
Old 09-08-2006, 06:55 AM   #1 (permalink)
Cad
Registered User
 
Join Date: Jan 2005
Location: Dallas
Posts: 8,519
-38 Internets
Make sure you are using firefox on the WoW forums, ladies

Found this little gem on the warrior forums, apparently silently installs a keylogger via activex if you are using IE. They're looking for WoW passwords then D/E'ing all your stuff and deleting your characters, and sending shards/gold to farmers.

So use firefox.. or... be really really careful what you click on. There's lots of these links on the WoW forums right now.
Attached Images
 
Cad is offline   Reply With Quote
Old 09-08-2006, 06:58 AM   #2 (permalink)
Soygen
100% Pure Soy Monk
 
Soygen's Avatar
 
Join Date: Mar 2002
Location: Ft. Lauderdale, FL
Posts: 10,064
+208 Internets
Fucking ActiveX.
Soygen is offline   Reply With Quote
Old 09-08-2006, 07:04 AM   #3 (permalink)
Hardcore Cracka
Majestik Moose
 
Hardcore Cracka's Avatar
 
Join Date: Apr 2003
Posts: 1,614
edit: nm, who uses IE lol
__________________
Hardcore Cracka is offline   Reply With Quote
Old 09-08-2006, 07:13 AM   #4 (permalink)
WarderX
Registered User
 
WarderX's Avatar
 
Join Date: Oct 2002
Location: Atlanta, Georgia
Posts: 1,593
+2 Internets
Send a message via AIM to WarderX
I think you still have to be a retard who clicks "yes" on random install boxes for this to affect you.
I could be wrong, but I'm pretty sure all activex apps have digital signatures.
WarderX is offline   Reply With Quote
Old 09-08-2006, 07:16 AM   #5 (permalink)
Cad
Registered User
 
Join Date: Jan 2005
Location: Dallas
Posts: 8,519
-38 Internets
Quote:
Originally Posted by WarderX
I think you still have to be a retard who clicks "yes" on random install boxes for this to affect you.
I could be wrong, but I'm pretty sure all activex apps have digital signatures.
I don't think this actually "runs" anything, from the looks of it, I think it just saves the .exe on your box and adds it to your startup folder, so next time you reboot it'll run. That might be how they're getting around the install warnings?

No idea, my activex-fu is non-existant, never touched the stuff. The word I'm getting from people who did inadvertently install it though was that they didn't get any warnings.
Cad is offline   Reply With Quote
Old 09-08-2006, 07:25 AM   #6 (permalink)
MinionOfCthulhu
Registered User
 
Join Date: Oct 2002
Posts: 468
+3 Internets
Hey look, another reason to not go to the WoW forums.
__________________
Finally! Now is the time where my true might shines, like many angry sunbeams of rage!
MinionOfCthulhu is offline   Reply With Quote
Old 09-08-2006, 07:26 AM   #7 (permalink)
Cad
Registered User
 
Join Date: Jan 2005
Location: Dallas
Posts: 8,519
-38 Internets
Quote:
Originally Posted by MinionOfCthulhu
Hey look, another reason to not go to the WoW forums.
Indeed, but ironically most of the people I know who actually did download this got it from a mod website (not Curse) downloading some C'Thun warner mod.

It's certainly not limited to the WoW forums, this keylogger is making the rounds right now.
Cad is offline   Reply With Quote
Old 09-08-2006, 07:29 AM   #8 (permalink)
Soygen
100% Pure Soy Monk
 
Soygen's Avatar
 
Join Date: Mar 2002
Location: Ft. Lauderdale, FL
Posts: 10,064
+208 Internets
svchos.exe is the file?
Soygen is offline   Reply With Quote
Old 09-08-2006, 07:33 AM   #9 (permalink)
Cad
Registered User
 
Join Date: Jan 2005
Location: Dallas
Posts: 8,519
-38 Internets
Quote:
Originally Posted by Soygen
svchos.exe is the file?
Looks that way, although it could be named anything once it's actually running with admin powers.
Cad is offline   Reply With Quote
Old 09-08-2006, 07:57 AM   #10 (permalink)
Lefazz
DERE IS ONLY POWAH!
 
Lefazz's Avatar
 
Join Date: Aug 2002
Posts: 3,467
The average user is so stupid that they probably will click "YES" on everything. Especially if they've installed a firewall which essentially harrasses you constantly. People are being trained to click "YES" and "OK". I've seen on plenty of occasions valid processes being blocked out and fucking up the system because you click "NO".

Anyway, just use Firefox. That shit can't happen period with that (as long as you don't install the ActiveX plugin.)
Lefazz is offline   Reply With Quote
Old 09-08-2006, 08:02 AM   #11 (permalink)
Xurlitil
hola
 
Join Date: Sep 2002
Posts: 126
-7 Internets
Lynx is the only browser for the internet these days. In fact, I just made this post using it. c-line text only browsers for life
Xurlitil is offline   Reply With Quote
Old 09-08-2006, 11:09 AM   #12 (permalink)
Gauss
Registered User
 
Gauss's Avatar
 
Join Date: May 2005
Location: Atlanta, GA
Posts: 1,508
+18 Internets
Quote:
Originally Posted by WarderX
I think you still have to be a retard who clicks "yes" on random install boxes for this to affect you.
I could be wrong, but I'm pretty sure all activex apps have digital signatures.
You are wrong. Activex controls will automatically execute unless you change the default settings on my computer. I've had to wipe my hard drive on previous computers due to this kind of bullshit, so I take no chances on this computer and simply opt out of viewing sites outside of ones I trust.

Edit: And for the love of god can a mod reset my signature.
__________________
Gauss <Retribution>
Gauss is offline   Reply With Quote
Old 09-08-2006, 11:13 AM   #13 (permalink)
Goanad
Registered User
 
Goanad's Avatar
 
Join Date: Oct 2002
Location: Derka Allah Muhammad Jihad!
Posts: 350
-31 Internets
Why dont blizzard and the f-ing anti-gold farming zealots let them bastards go farm gold instead of banning them and then reaping shit like this when they(the farmers who got banned) get their buddies to write crap like this and put it out on the net.

Or lower repair costs....whatever you know.
Goanad is offline   Reply With Quote
Old 09-08-2006, 11:45 AM   #14 (permalink)
Nehrak
Registered User
 
Join Date: Nov 2005
Location: Home
Posts: 1,346
I'm not sure if I should be surprised what WHOIS returned for the domain address in question in that popup. (nihailai)
Nehrak is online now   Reply With Quote
Old 09-08-2006, 11:47 AM   #15 (permalink)
Talzar
Registered User
 
Join Date: May 2002
Posts: 149
-4 Internets
"Make sure to use Firefox"... Or you know, just run IE on a higher security setting that prompts you before running ActiveX code.
Talzar is offline   Reply With Quote
Reply


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

uberguilds network



All times are GMT -7. The time now is 09:50 PM.


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0 RC6