Was it actually in your registry, or just an entry in the registry under the search agent? If you did a windows search beforehand it would show up there.Originally Posted by Tadghostal
Was it actually in your registry, or just an entry in the registry under the search agent? If you did a windows search beforehand it would show up there.Originally Posted by Tadghostal
I'm too computer illiterate to know the difference, though I did search all files and folders beforehand so that may be it.Originally Posted by Xanthe
Yep, that sounds about right.Originally Posted by Tadghostal
Just some more info:
I have the luxury of a separate machine with clean images on it, meaning they have nothing but the OS and all current Windows Update updates installed. The machine has never installed RealPlayer, or browsed any sites outside of Windows Update and graphics driver sites. This machine is an AMD something or other, running Windows XP SP2 w/all Windows Updates, no extra programs of any sort on it.
- I browsed the infamous word-filtered site, and a popup was blocked.
- Closed the browser, searched for relevant suspect files listed in the other post
- Nothing was found on the machine or in the registry
- I browsed the infamous word-filtered site, and a popup was blocked.
- I enabled pop-ups, refreshed the page.
- Closed the browser, searched for relevant suspect files listed in the other post
- Nothing was found on the machine or in the registry
- Browsed the word-filtered site, nothing was blocked
- Closed the browser, searched for relevant suspect files listed in the other post
- Nothing was found on the machine or in the registry
- Went to RealPlayer's site, installed the free RealPlayer with all the default settings.
- Browsed the word-filtered site, ActiveX control was blocked from being downloaded
- Closed the browser, searched for relevant suspect files listed in the other post
- Nothing was found on the machine or in the registry
- Browsed the word-filtered site, ActiveX control was blocked from being downloaded
- Clicked OK to install the control
- Closed the browser, searched for relevant suspect files listed in the other post
- Nothing was found on the machine or in the registry
- Restarted the machine
- Searched for relevant suspect files listed in the other post
- Nothing was found on the machine or in the registry
So it appears that you really have to go through some extraordinary steps to wind up with this. With all the updates on an XP SP2 machine, I wasn't able to get infected, even after installing their control. I must have missed something, but I couldn't think of anything else that would get me to the point where the files would be installed on my machine. Apparently if you have all the current Windows Update patches installed, you may be safe. I would still recommend that people not visit the site until we hear it from them that it's been cleaned up, and there's no longer a request for an ActiveX control to be installed when visiting the site. To be honest I was a little surprised that I didn't get the files, considering that I went all the way with allowing the control to be added.
P.S. The machine I have is a test machine, and has nothing of consequence on it. I've already formatted it, so unless you want to run the risk of getting a trojan installed, I'd advise against running these test scenarios.
It was mentioned in another thread that the RealPlayer bug the malware exploited was patched in October. So it appears only people with old versions are in the danger zone.Originally Posted by Fhqwghads
Yeah, was just talking in IRC and someone explained that too. Moral of the story is: keep your machines updated. What a horrible reminder though.
I suppose on a good note, the tests I conducted confirms that people are secure with all the updates in place.
Yeah, I just went to check for updates on my Realplayer and there is one listed as the "October 2007 Security Update". Everyone who currently uses Realplayer should do this immediately as it only took one minute of my time.
I have Firefox with Windows Vista and AVG Free Edition, and Realplayer is not installed on my system. I still got the exploit and lost my account about an hour after I typed my foll POL ID and password into FFXI Linkshell Community.
Hmm. Well it's possible that the exploit could be transferred through multiple ways because although Aviator did not have Real player, it's most likely that ALL 50+ people who got hacked have not used the community LS (which is just a personal guess).
No, it's a high-tech way of saying I deobfuscated the javascript. Perhaps I should have clarified and said that it's ONLY a realplayer exploit and not anything else in addition.Originally Posted by souleman
Originally Posted by Fhqwghads
The first accounts started disappearing in September. Realnetworks patched their software in October. Those infected before October who were using IE were screwed either way. Malicious code like this relies on the slow turnaround on software patches.
I'm wondering why accounts are still being hacked, especially in the month of December, when people got infected in September. It's strange for RMT to delay their hacking.
I'll add that someone in my linkshell went to the site and his AV (Kaspersky) popped up and told him it blocked a trojan from infecting his computer. He later found out about this thread on here after that popped up on him.
Oh wow. Thank you so much Taj for being so concerned about players accounts getting hacked. Now that I know how you feel you could return the 25M in gear you stole from me. Kthankx.
Originally Posted by Gordie
![]()
Originally Posted by Gordie
Ahahaha, thanks for the laugh.
:bagel:
lolvalefor
Could the virus be found in any other folder in theory? I dont see why they would be anywhere else but system32, but I'm lazy and dont feel like doing a whole scan
It would make sense to delay stealing accounts until Christmas as they sell a bit of gil around that time of year. If they hacked the toons earlier they ran the risk of SE deleting their banks before the Christmas rush.
I pulled up somepage to look up something there before I knew about the problem
Zonealarm found this trojan as soon I opened the page
Virus Name: Trojan-Downloader.JS.Agent.akd
Date Detected: 11 Dec 2007 12:10:00 +0300
Date Modified: 11 Dec 2007 16:29:56 +0300