http://icanhascheezburger.files.word...heezburger.jpgOriginally Posted by Sonomaa
Happycat 4TMFW
http://icanhascheezburger.files.word...heezburger.jpgOriginally Posted by Sonomaa
Happycat 4TMFW
A thought occured to me, does this virus exploit a problem with the Real™ codec or the program?
I got RealPlayer-alternative here, which is just a codec pack so I didn't have to deal with the pos player the actual thing came with, for those extremely rare stubborn sites that haven't gotten with the times and went .flv.
I think they are exploiting a bug in Real Player's playlist support.
it's in the activex control itself i believe. if taj's information was correct, this is the exploit used: http://www.symantec.com/enterprise/secu ... _loos.html
and it mentions setting the kill bit on that control to prevent it from running. (instructions here: http://support.microsoft.com/kb/240797
set for CLSID: FDC7A535-4070-4B92-A0EA-D9994BCC0DC5 per the symantec article)
By the exploit that was on ffxiatlas no it is not. you are 100% ABSOLUTELY SAFE from that exploit in this post if your not using IE....Originally Posted by PrincessMinnet
Says so right in the source code: "if browser is NOT IE6 OR IE7, then exit function and dont run the exploit code"
CLICK HERE for a guide I wrote on protecting yourself from these attacks. Follow this guide and you will be at least 97% protected from all of these exploits.
Was just writing a PM on my Guildportal site when i noticed this on the screen:
http://i29.photobucket.com/albums/c2...bler/virus.jpg
I've never seen it before and I recalled you saying this was possibly the source from ffxi-atlas, sorry if it has nothing to do with this ;p
Post the deobfuscated javascript and we'll tell you what it is.Originally Posted by Theenabler
A buddy of mine got hit with this keylogger, it's name is cmdinst.exe if anyone needs to search their pc. Funny thing is he got back on his character and got his password changed before they stole all of his stuff. Went to the delivery box person and was able to cancel the last 4-5 items sent out, and got the name of the mule taking the stolen goods on Phoenix server. Claipod or something like that.
edit:
Oh he also found a file in his POL directory labeled cmdinst.txt and when he opened it, it was a log of everything that he has typed into POL and FFXI in the last few weeks.
Not good with computers, wanna break that down into something i can understand? ;pPost the deobfuscated javascript and we'll tell you what it is.
It's days like this I'm glad my net worth is something in the neighborhood of 2-3 million gil. I've never seen such maliciousness as these RMT have displayed, which probably just means I'm sheltered when it comes to the internet, but still.
more info on guildportal please, my ls uses that site.![]()
Also now that I've viewed guildportal, my windows messenger keeps loggin itself off and when i hit retry it says the password/username is incorrect, then when i retype in password it logs back on for like another 5 min
Can someone please change this title. I had a bit of a panic attack when I saw "ffxiatlas infected." Talk about false alarm since its been fixed.
Done.Originally Posted by Ryushii
GuildPortal is most likely safe. Their shitty PM/mail system uses a 1x1 iframe as a keepalive, it's been there for ages, and people have asked about it before.
Repeat after me: IFRAMES THEMSELVES ARE NOT KEYLOGGERS. There needs to be a piece of Javascript attached that actually exploits some vulnerability, without that, it's just a little 1x1 box on a web page that doesn't necessarily do anything.
If you find a suspicious iframe, select it and the text immediately around it, right click and click "View Selection Source", and paste THAT text for us to look at, so we can tell what it actually does. Pasting a pic of the iframe just tells us that... well, that it looks like a 1x1 iframe, which most 1x1 iframes do.
http://img292.imageshack.us/img292/2909/ogodaq5.th.png
Oh god Taj's site has a massive infection.
Originally Posted by Kiarax
![]()
watch happycat? i want to see right now >.>Originally Posted by Sonomaa
so... yesterday I was accidentally using IE and went on ffxiatlas... what do I look for when virus scanning/clearing registry?
cmdinst.exe was the one from FFXI-Atlas, or at least one of them... I posted this a few posts up. Also wouldn't hurt to check for RSBO.exe and any .txt files associated with these.so... yesterday I was accidentally using IE and went on ffxiatlas... what do I look for when virus scanning/clearing registry?