As many of you know already, there are several trojans and keyloggers on the loose stealing account information from World of Warcraft players. Considering the amount of players who are using addons, this is a very serious issue.
For this very reason, this morning a brand new anti-virus software was installed on the Curse Gaming website. The software is running in the background and checking all of the files including the newly uploaded ones without intermission.
We suggest for every addon user who downloaded and installed addons from other websites recently to check their computers with anti-virus software. Furthermore we recommend everyone to use Firefox, because there are various security holes in Internet Explorer which allows people to install keyloggers on the victim's computer without his/her knowledge. Also make sure to use WindowsUpdate for security fixes..
Be suspicious! When you extract an addon package check its content for executable files. They can appear to users to be useful or interesting programs. Avoid opening files with extensions such as .bat, .exe, .com.
Comments
(For the MAC users, I know... but that's only because there are less of you Heh Heh. For the technically minded, look up MS08-067: Vulnerability in Server Service Could Allow Remote Code Execution; look for a service running called BaseSvc)
______________________________________________________
"Redmond has acknowledged that criminals have for the past three weeks been using the vulnerability to conduct targeted attacks. The source said that so far, fewer than 100 targeted attacks leveraging this flaw have been spotted by Microsoft's security team, but that Microsoft was rushing out this patch because the number of attacks appears to be increasing of late." (Washington Post)
----------------------------------------
"At the time of this writing, there are 3,695 entries in that file. Every line contains an encrypted string, which could potentially conceal current victims' details, indirectly indicating how many victims have been compromised by this worm so far." Threat Expert Blog