Another keylogger detected on the forums
![[If you see this, your computer is seriously hosed. Order pizza. You'll be there a while.]](http://www.blogcdn.com/wow.joystiq.com/media/2007/05/virus.jpg)
More specifically, a keylogger was caught on the Icecrown boards early this morning. This particular keylogger, like many others before it, attempts to exploit the ANI cursor vulnerability in Windows. As user Madhava on the forums explains:
[The link is] not meant to fool the interceptor, Its meant to fool people. It disguises what website you are actually going to by using those escape functions. Firefox refuses to follow those links (for good reason), but I'm not sure about IE... The hijacked site has an embedded link to malicious javascript hosted on a Chinese server. That javascript attempts to exploit the ANI exploit and the Iframe exploit to load a trojan named 'test.exe'.
'Test.exe' is detected by most antivirus as a trojan: Trojan-PSW.Win32.Agent.im or Trojan.Agent.im -- Basically a password stealer for WoW and maybe a backdoor.
Between more keyloggers popping up on the WoW forums, and reports from the LJ WoW community about people's accounts being hacked and characters being transferred to other accounts and/or servers... (Ostensibly to get a large sum of gold to another server so it can be sold, or to set up the character on a new account for sale.) Now is a good time to make sure you've got all your updates for your operating system, virus scanner, and browser, as well as any other scanners you may have. Then set your machine up to do some additional maintenance while you're asleep or AFK -- like a nice deep system scan. And of course, don't ever follow a link from the forums that you don't recognize as being from a legitimate webhost.
In the case of your machine's safety, there is no such thing as being too careful. For those curious, more information is available in Blizzard's customer service FAQ.
[via the WoW forums and the LJ WoW community]
Filed under: News items






Reader Comments (Page 1 of 1)
Savok May 7th 2007 5:38AM
https://addons.mozilla.org/en-US/firefox/addon/722
Javascript can lick my blinky diodes.
ibcfreak May 7th 2007 6:10AM
I've said it before, and i'll say it again...Firefox ftmfw!
Akuma May 7th 2007 6:36AM
A keylogger on the O boards? >.<
I'm just so paraniod that I try not to go to any WoW sites at all except the official one *sigh* (But I'm not the only WoW player here... So there's still the chance that one of us gets a keylogger >.< )
I'm sick of hackers, I wish they'd all die in a fire...
Akuma May 7th 2007 6:37AM
Oh, and yse I use FireFox, but the roommate doesn't... *sigh*
dafire May 7th 2007 8:18AM
google ads are just great.. while reading this news in a rss reader I get the ad to buy an undetectable keylogger...
**** is the best keylogger because it lets you remotely:
It let's you capture every single keystroke they type on their keyboard (including passwords & usernames)
dotSeed May 7th 2007 8:54AM
Solution: Get a better OS/browser.
Curly May 7th 2007 10:18AM
OSX ftw. God bless blizz for releasing a mac client.
Charlie May 7th 2007 10:19AM
OSX ftw. God bless blizz for releasing a mac client.
Charlie May 7th 2007 10:20AM
Oops. Apologies about the double post.
Renagade242 May 7th 2007 12:18PM
@3: No, you're sick of malicious crackers:
http://en.wikipedia.org/wiki/Hacker_definition_controversy
Your skill in reading will increase by at LEAST one point!
rysc May 7th 2007 12:28PM
I know its not supported by Blizz, but Linux ftw.
Kaey May 7th 2007 12:48PM
Yeah, I was stupid enough to click on a keylogger near the end of March on the General Forums. I was reading a topic I can't remember and clicked on a link about 40 posts in. It took me to a small picture of a car (which was totally unrelated to the topic). I didn't think much of it at the time, but a few days later I was pvping in STV and was disconnected 4-5 times. After several times of that my password became invalid. That's when I knew I was hacked (my fiancee checking on her account on her computer and seeing me logging in various alts confirmed it). I was able to act quickly and reset my password, then reset it again after logging in on her comp. I lost thousands in gold and mats, but luckily my main wasn't harmed (having DCed in the middle of the ocean during a pvp battle in STV, I was dead and it took much too long for them to spirit rez and port and try to head to a bank).
It took three weeks of sending multiple emails to Blizzard's staff, but I finally got all of my stuff back down to the last potion and copper piece. Now I don't click on forum links, and I run virus scans, adaware (it was originally the program to find the keylogger) and spybot daily before logging in.
Mike May 7th 2007 2:57PM
I still don't see a problem. As for me it was easy enough to go to anti-keylogger.org or any other site dedicated to anti-keylogging tools, and download one of the anti-keyloggers. Such a strange people.......
FireStar May 8th 2007 10:30AM
I'm pretty safe. I only download mods and view forums on my laptop, and only play on my desktop. i never look up anything on my desktop whatsoever.
multikast May 9th 2007 8:34AM
@10
Thank you!
I always want to post stuff like that when i see people misuse the term 'hacker', but i always just give up hope that people will never understand. at least there's some people out there that understand there is a HUGE difference.