View Poll Results:
0%
Voters: 0. You may not vote on this poll

Thread Tools Display Modes
04-26-08, 02:27 PM   #1
aeriegirl2go
A Kobold Labourer
 
aeriegirl2go's Avatar
Join Date: Apr 2008
Posts: 1
WARNING! Trojan Win32 = account getting hacked!

I downloaded various mods from Wow Interface on Sunday, April 20. These mods included DamageMeters original and 2.4 updated versions, FuBar and Titan Panel, 2.4 versions plus some plugins for those mods. I also downloaded a mail mod, and lastly the preview Advanced Auctioneer Suite for 2.4. I played all day Sunday, all day Monday (virtually), and didn't log on at all on Tuesday. Wednesday morning I went to log in, only to discover that my account had been hacked.
I contacted Blizzard via their site form immediately, but their billing office wasn't open yet. I got an auto-response from them verifying that they had received my complaint. I checked out WowInterface forums for info on accounts getting hacked, and replaced the Panda trial I had with Comodo antivirus, and also got the SUPERAnitSpyware and Spybot Seach&Destroy that were recommended. These free programs still did not resolve the trojan that I am confident was used to hack my account. I noticed on Monday that when I started my computer, a Win32 application error was appearing and glitching, I'd have to hit close a dozen times before it'd finally go away. After getting all my new antivirus and spyware, Comodo recognized the win32 as a potential harmful program and kept asking if I wanted to allow or block, but I'd have to choose block a dozen times still before it'd go away. So I googled win32, discovered it's a trojan that gives evil people access to your passwords, and downloaded SpyHunter, which offered a "free" scan. During the scan it did find the win32 and a window popped up saying it got rid of it, but it refused to get rid of all the other viruses it found unless I paid $30. But after that, Comodo recognized it trying to connect to the internet via another program, which was suspicious behavior, so I uninstalled the SpyHunter. I am going to get Spyware Doctor for the $30 a year because for some reason I trust Dr. Phil.
Blizzard finally responded to my web form on Friday, April 25, they refused to communicate with me via e-mail, since my e-mail address was no longer linked to the account in question (DUH! the hacker changed that, along with all the other vitals to the account!). So I have to call their Billing, but they are closed today, have to wait until Monday. Meanwhile, some hacker is out their completely screwing up my account, probably selling my gold for real cash. I am happy I paid with PayPal, because I filed a complaint with them to get my month's subscription fee refunded, and at this point am dealing with the potential loss of my account that i had worked on and paid for for 9 months, my main was almost level 70, along with a 47, 39, two 29's, all maxed out on their professions. I hope to keep my account, getting it restored and having the month refunded (why should I be paying for someone to be violating my account?), but who knows?
Newsflash! While writing this, Cairenn at Wow Interface sent me a private message requesting that I "stop with all the unsubstantiated fear mongering everywhere", and says that they are looking into it, as I reported potential bugs with each of the mods that I downloaded warning that they might have the trojan. I am rather insulted, as I clearly stated in each bug report that I wasn't sure if that mod had the trojan, that it was one of about 7 which I had downloaded. I only care about others not getting hacked, hello I'm the victim here just wanting to prevent others getting victimized! It is VERY SUBSTANTIATED... Wow Interface is the ONLY site I've downloaded from since UI Central crashed, and I got hacked the next day. The only other program I downloaded was the WowInterface mod updater... EVERYONE BE CAREFUL!!!!!
  Reply With Quote
04-26-08, 02:42 PM   #2
Evolution85
A Black Drake
 
Evolution85's Avatar
Join Date: Nov 2007
Posts: 84
Keyloggers only happen from an .exe file.

Thus, never d/l a mod that has an executable.
  Reply With Quote
04-26-08, 02:46 PM   #3
Dolby
PPAP
 
Dolby's Avatar
WoWInterface Admin
Join Date: Feb 2004
Posts: 2,341
Fileing bug reports is not the route to go, its prob. the worst route. Creating a thread on the forums listing what you downloaded and asking for these files to be checked is the best route.

I've checked all the files you have listed and the only files that have exe's is the updater. I have checked the md5 and sha hash and it matches from when shirik uploaded it. I have also installed it in my sandbox (vmware) and everything looks good. Shirik the author of the updater has confirmed that everything is fine with the updater app.

How secure was your wow account password (password should have letters, numbers, symbols otherwise it can be brute forced quickly)? Are you a part of any forums or sites and you use the same login info there as your wow account? How up to date are your windows patches and do you have a firewall enabled or at least a router on your network?

Were you prompted to re-enter your username when you started the game in the past few days? If no, then it couldnt have been a keylogger as they need to reset that so they get your login name because just getting your password as you type it in isnt good enough.

Thank you for letting us know and as with any post we look into any files that are put in question. I ask that in the future any one just create a thread on the forum with a easy to read list of files you'd like us to check again. Reading what you posted above is difficult on the eyes.

Last edited by Dolby : 04-26-08 at 03:10 PM.
  Reply With Quote
04-26-08, 02:50 PM   #4
Cairenn
Credendo Vides
 
Cairenn's Avatar
Premium Member
WoWInterface Admin
Join Date: Mar 2004
Posts: 7,134
Threads merged, since multiple versions aren't necessary.
__________________
“Do what you feel in your heart to be right — for you’ll be criticized anyway.” ~ Eleanor Roosevelt
~~~~~~~~~~~~~~~~~~~
Co-Founder & Admin: MMOUI
FaceBook Profile, Page, Group
Avatar Image by RaffaeleMarinetti
  Reply With Quote
04-26-08, 03:13 PM   #5
Shirik
Blasphemer!
Premium Member
WoWInterface Super Mod
AddOn Author - Click to view addons
Join Date: Mar 2007
Posts: 818
To continue what Dolby said, I have personally verified all of the signatures on the updater and they match (for both the setup program and the JAR archive), thus indicating it is safe.

On another note, typically you wouldn't see such a strong correlation in time -- when your account details are keylogged they are sent off to another server where they sit in some sort of queue waiting for someone to use up the details. In my experiences, the users I have seen getting keylogged and then later having their account compromised had as much as a month or more in between the time they began using the trojan to the time they noticed their account to be compromised.

Correlation does not imply causation (but it does not imply its absence, either).

On yet another note, "win32" is not a virus. It is an application API. Using all of these "free" antiviral and antispyware programs is a very BAD idea because there are a LOT of fake free anti-malware programs which actually scare users into getting those programs, then infect your computer. Stick with the brand-name tools and you won't be disappointed.

Good luck,
-- Shirik
__________________
たしかにひとつのじだいがおわるのお
ぼくはこのめでみたよ
だけどつぎがじぶんおばんだってことわ
しりたくなかったんだ
It's my turn next.

Shakespeare liked regexes too!
/(bb|[^b]{2})/
  Reply With Quote
04-26-08, 08:24 PM   #6
mulesh
A Chromatic Dragonspawn
 
mulesh's Avatar
AddOn Author - Click to view addons
Join Date: Dec 2006
Posts: 193
Originally Posted by aeriegirl2go View Post
Wow Interface is the ONLY site I've downloaded from since UI Central crashed...
You have used UIC in the past? Wasnt it removed from circulation because it was infected with a trojan?
__________________
"Don"t tase me bro!" ~ Andrew Meyer
  Reply With Quote
04-26-08, 08:28 PM   #7
Cairenn
Credendo Vides
 
Cairenn's Avatar
Premium Member
WoWInterface Admin
Join Date: Mar 2004
Posts: 7,134
No, it was pulled because it violated copyright. But it did have keyloggers in it at least three times.
  Reply With Quote

WoWInterface » Site Forums » Site help, bugs, suggestions/questions » WARNING! Trojan Win32 = account getting hacked!


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off