Recently, there has been an increase in the amount of reported key-loggers in various websites tailored to WoW. For those of you who are unaware of what a key-logger is, it is a malicious program that installs itself in the memory of your computer and reads your key-strokes as you log on to your game of choice, or website of choice, thus snapping up your login information and sending it back to the author of the program.
There are several ways in which these people attempt to catch you off guard. In regards to World of Warcraft, I will list the most common methods used.
- Addon Download:
A .exe file is either included in a compressed archive (such as a .zip or .rar) and the users then run the .exe file unknowing that the file is not what it is supposed to be.
- Addon Download:
The actual download is a .exe file (to be confused with a self-extracting compressed archive), to which the user runs thinking it will install the addon.
- Poor Website Security
Certain websites have poor security set up in regards to their site, thus allowing malicious users to seize control of the content the website delivers and input their own code in web pages, thus making the entire website compromised with the potential of running Java-script(*) to install/run applications on your computer.
- Masked/Fake URLs
Certain people will create urls and file-links that "appear" to be coming from legit content, while in fact they are hoax URLs that follow the same security breaches as mentioned above.
What can you do as a user to avoid falling in the trap?
- Install an updated and secure browser. (Our recommendation is Mozilla Firefox 2.0.1)
- Have up-to-date antivirus/security software installed on your computer.
- Use common sense. Don't visit URLs or Links spread on the internet that vary from the actual addresses you are used to. Don't run executables you download without running security checks on them first.
In closing, to supplement the already robust security we have here at Curse, as a precaution I advice you to be cautious about links to Curse URLs that begin with media1.curse-gaming.com. We will be going over the routines on our website over the next 24 hours to ensure we have the highest security possible and that you can continue to expect Curse to be free of malware.
As an addendum; Should you as a user at some point locate mal-ware on our website, please report it to either myself or Werik immediately and we will have the issue resolved.
Thanks, - The Curse Crew
Comments
Its not that hard to secure yourself..
DONT RUN .EXE (dont even download them) only use zip and unzip in interface\addon folder.
Again dont run .exe files (or .com, or any executable)
Use mozzilla and not Iexplorer. (the updated mozzilla)
and voila.. 98% risk gone
SOLUTION:
www.free-av.com (Antivir): Download this free antivirus. It's the best that comes free in internet.
NOD32: Find and download it full. I suggest a warez website or torrent.
Sygate personnal firewall Pro: Find it from warez or torrent.
Have the 2 antivirus fully updated and customized to scan every archive when read and writte in.
For the firewall, don't let anything pass except you trust it.
I strongly suggest downloading Firefox 2 and stop using IE.
If you have questiongs, my msn is: pmacromanolis@hotmail.com
I could even send you those files if you are bored to search for them.
The bigger threat that no one seems to talk about is that if you are a victim of this you have potentially way more information sent to these thieves. Any account that you have logged into they have the potential to steal information or worse from.
If your account was hacked. You need to change your logins and passwords from any and all accounts you access from your computer. It may also be wise to notify your financial accounts (Credit Cards, Bank Accounts, etc) and have them changed or monitored.
You should treat this as if your wallet + day planner with all your passwords was just stolen because it just was.
ui.worldofwar.net has recently had another (third time this year) malicious trojan which was spread by their advertisement program... really poor advertising for them tbh, many accounts were hacked yet again.
i was wondering if media1.curse-gaming.com is safe again. Cause i clicked on "auto select fastest mirror" while downloading ecasting bar latest version and it took this url. (im using IE7). I aborted the download & cleaned out my temp files just to be on the safe side. But can anyone of curse confirm it is safe again please. Dont wanna lose my 2yrs account ^^
gorgeth; NTLDR.EXE is not a windows system file, NTLDR *without an extansion* is
Also, the (virus/trojan) file talked about here is actually named NTDLR.EXE (mind the spelling!)
Also note; by default the real NTLDR file is marked as a protected operating system file and will not be seen in the root of your first harddrive (where it must reside for the system to be able to boot up, the name is short for NT LoaDeR)
A quick google search confirms this pretty good... Note; always look up the file on google before you delete it on just anyones recommendation...
Isn't this like the second time that ui.worldofwarcraft.net have had Trojans in their advertising?
FACT: NTLDR.EXE in the root of your system drive is a windows system file..
It processes Boot.ini and loads the OS of choice (either blindly on a single install of win2k/xp or with a menu presenting various choices if you are on a dualboot or otherwises "nonstandard" system)
You cannot get rid of NTLDR.EXE and get windows to load, having people who cannot run an antivirus program delete files is always a BAD IDEA.. especially when they are presented as the fix from clearly clueless individuals such as those who posted this information originally.
Another tip!
Go to www.firefox.com , head over to the AddOns section of their's and search for the AddOn called NoScript.
Install NoScript for Firefox (done in 1 min tops).
This makes you in charge of what scripts that you allow to run in your firefox.
Cheers, merry christmas!
@ThorsLiebling,
If your computer automatically creates system restore points, you can try restoring from a point before you believe you were infected.
Also, make sure you delete all of your temporary internet files. There may be a process running that automatically restore the keylogger, so try running an anti-virus/other security programs that can scan before Windows and other processes fully boot.
If all else fails, you may have to format. I myself wasn't infected, so I am not 100% sure of the steps you need to follow to remove the virus.
ThorsLiebling, no, NSCSRVCE.EXE is an executable attatched to Norton. And it is shutting your WoW windows down because when you tell it that it can not run, it is executing the program it was monitoring for you.
NoScript is nice & all when you know the site is secure. However since most people have curse-gaming.com listed as ok, stuff coming from media1.curse-gaming.com will get through as well.
And ya, what's the deal with the "65.98.12.xxx" ip, I had to allow that for the beta tab on some addons to work.
try:
http://www.microsoft.com/technet/sysinternals/utilities/filemon.mspx
with this tool you could see which process is doing what on your filesystem
bye smurfy
GHWRIN: "ui.worldofwar.net currently has a keylogger on their website. If you've visited their website recently search your computer for "NTLDR.exe" (not to be confused with NTLDR.dll) and delete it immediately. I would also recommend scanning your computer for viruses. The keylogger is downloaded via JavaScript, which you can block or enable for website of your choice with the following FireFox plug-in: https://addons.mozilla.org/firefox/722/"
I have this NTDLR.EXE on my computer and I have deleted it already a couple of times, it keeps coming back on my harddrive C. I have already checked my whole system several times daily with various security tools and programs, and also manually. But still it is not possible to find the cause why this file is being renewed everytime on startup. Off course ma secutity tools and programs are up to date. What can I do?
I also have another file in my task manager since about a week. It's name is NSCSRVCE.EXE. Is it possible, that this file is also a keylogger? My firewall always reports, that it is trying to act as a server as soon as I try to log on into WoW. It shuts down WoW as soon as I forbid it to do so oO
@lAce Right you are! However, it is equally important to mention that the situation has been dealt with, don't you think? :)
@vatosky The entire range of accounts from @exploitsrus have been banned, and all 520 spam comments have been deleted.