<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://my.curse.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Taking up the fight against key-loggers</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx</link><description>Recently, there has been an increase in the amount of reported key-loggers in various websites tailored to WoW. For those of you who are unaware of what a key-logger is, it is a malicious program that installs itself in the memory of your computer and</description><dc:language>en-US</dc:language><generator>CommunityServer 2008 SP1 (Build: 30619.63)</generator><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41761</link><pubDate>Thu, 21 Dec 2006 06:02:19 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41761</guid><dc:creator>Ghwrin</dc:creator><description>&lt;p&gt;ui.worldofwar.net currently has a keylogger on their website. If you've visited their website recently search your computer for "NTLDR.exe" (not to be confused with NTLDR.dll) and delete it immediately. I would also recommend scanning your computer for viruses.
&lt;/p&gt;&lt;p&gt;The keylogger is downloaded via JavaScript, which you can block or enable for website of your choice with the following FireFox plug-in:
https://addons.mozilla.org/firefox/722/
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41761" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41760</link><pubDate>Thu, 21 Dec 2006 06:02:18 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41760</guid><dc:creator>XShadowXKingX</dc:creator><description>&lt;p&gt;Thank You Ghwrin And Nimloth for the info!! 
&lt;/p&gt;&lt;p&gt;-
XShadowXKingX
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41760" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41759</link><pubDate>Thu, 21 Dec 2006 06:02:17 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41759</guid><dc:creator>dhask</dc:creator><description>&lt;p&gt;Also, NoScript:
&lt;/p&gt;&lt;p&gt;https://addons.mozilla.org/firefox/722/
&lt;/p&gt;&lt;p&gt;For those things that FF is vulnerable to, almost all of them are Javascript related.  Browse with JS off by default, one-click to permanently allow scripts from trusted domains.  Protects you from JS attacks such as the worldofwar one, or the occasional hacked advertising server ones.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41759" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41758</link><pubDate>Thu, 21 Dec 2006 06:02:16 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41758</guid><dc:creator>smurfy</dc:creator><description>&lt;p&gt;Problem with the "65.98.12.xxx" ip javascript and css links.
is that a good idea to have this stuff on a ip based url?
&lt;/p&gt;&lt;p&gt;another problem is that the url will changes.
&lt;/p&gt;&lt;p&gt;More infos about keyloggers:
&lt;/p&gt;&lt;p&gt;http://www.worldofraids.com/forum/viewtopic.php?t=2487
&lt;/p&gt;&lt;p&gt;its also a keylogger on curse ( refering to worldofraids and its sources)
&lt;/p&gt;&lt;p&gt;bye smurfy
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41758" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41757</link><pubDate>Thu, 21 Dec 2006 06:02:15 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41757</guid><dc:creator>Nimloth</dc:creator><description>&lt;p&gt;World of Raids is slow to update its news apparently. The key logger you are referring to was removed shortly after its discovery and security restrictions have been put in place to prevent repetition.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41757" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41756</link><pubDate>Thu, 21 Dec 2006 06:02:14 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41756</guid><dc:creator>vatosky</dc:creator><description>&lt;p&gt;Please whipe this member out of C-G database.
&lt;/p&gt;&lt;p&gt;http://www.curse-gaming.com/en/accounts/details/cedricbensonbrunson/
&lt;/p&gt;&lt;p&gt;Check his posts, it will clarify why.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41756" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41755</link><pubDate>Thu, 21 Dec 2006 06:02:13 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41755</guid><dc:creator>Rupilius</dc:creator><description>&lt;p&gt;Good to see you guys reacting quickly. GL.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41755" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41754</link><pubDate>Thu, 21 Dec 2006 06:02:12 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41754</guid><dc:creator>lAce</dc:creator><description>&lt;p&gt;Nimloth, they might be not up to date to your current situation, but it was worth mentioning, because ppl might have been infected from your site in the time period before you discovered the problem.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41754" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41753</link><pubDate>Thu, 21 Dec 2006 06:02:11 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41753</guid><dc:creator>Nimloth</dc:creator><description>&lt;p&gt;@lAce
Right you are! However, it is equally important to mention that the situation has been dealt with, don't you think?&amp;nbsp;:)
&lt;/p&gt;&lt;p&gt;@vatosky
The entire range of accounts from @exploitsrus have been banned, and all 520 spam comments have been deleted.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41753" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41752</link><pubDate>Thu, 21 Dec 2006 06:02:10 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41752</guid><dc:creator>ThorsLiebling</dc:creator><description>&lt;p&gt;GHWRIN: "ui.worldofwar.net currently has a keylogger on their website. If you've visited their website recently search your computer for "NTLDR.exe" (not to be confused with NTLDR.dll) and delete it immediately. I would also recommend scanning your computer for viruses.
The keylogger is downloaded via JavaScript, which you can block or enable for website of your choice with the following FireFox plug-in:
https://addons.mozilla.org/firefox/722/"
&lt;/p&gt;&lt;p&gt;I have this NTDLR.EXE on my computer and I have deleted it already a couple of times, it keeps coming back on my harddrive C. I have already checked my whole system several times daily with various security tools and programs, and also manually. But still it is not possible to find the cause why this file is being renewed everytime on startup. Off course ma secutity tools and programs are up to date. What can I do?
&lt;/p&gt;&lt;p&gt;I also have another file in my task manager since about a week. It's name is NSCSRVCE.EXE. Is it possible, that this file is also a keylogger? My firewall always reports, that it is trying to act as a server as soon as I try to log on into WoW. It shuts down WoW as soon as I forbid it to do so oO
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41752" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41751</link><pubDate>Thu, 21 Dec 2006 06:02:09 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41751</guid><dc:creator>smurfy</dc:creator><description>&lt;p&gt;try:
&lt;/p&gt;&lt;p&gt;http://www.microsoft.com/technet/sysinternals/utilities/filemon.mspx
&lt;/p&gt;&lt;p&gt;with this tool you could see which process is doing what on your filesystem
&lt;/p&gt;&lt;p&gt;bye smurfy
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41751" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41750</link><pubDate>Thu, 21 Dec 2006 06:02:08 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41750</guid><dc:creator>Fendryl</dc:creator><description>&lt;p&gt;NoScript is nice &amp; all when you know the site is secure.  However since most people have curse-gaming.com listed as ok, stuff coming from media1.curse-gaming.com will get through as well.
&lt;/p&gt;&lt;p&gt;And ya, what's the deal with the "65.98.12.xxx" ip, I had to allow that for the beta tab on some addons to work.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41750" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41749</link><pubDate>Thu, 21 Dec 2006 06:02:07 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41749</guid><dc:creator>Sikkwolf</dc:creator><description>&lt;p&gt;ThorsLiebling, no, NSCSRVCE.EXE is an executable attatched to Norton. And it is shutting your WoW windows down because when you tell it that it can not run, it is executing the program it was monitoring for you.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41749" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41748</link><pubDate>Thu, 21 Dec 2006 06:02:06 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41748</guid><dc:creator>Ghwrin</dc:creator><description>&lt;p&gt;@ThorsLiebling,
&lt;/p&gt;&lt;p&gt;If your computer automatically creates system restore points, you can try restoring from a point before you believe you were infected.
&lt;/p&gt;&lt;p&gt;Also, make sure you delete all of your temporary internet files. There may be a process running that automatically restore the keylogger, so try running an anti-virus/other security programs that can scan before Windows and other processes fully boot.
&lt;/p&gt;&lt;p&gt;If all else fails, you may have to format. I myself wasn't infected, so I am not 100% sure of the steps you need to follow to remove the virus.
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41748" width="1" height="1"&gt;</description></item><item><title>None</title><link>http://my.curse.com/blogs/wow-en-news/archive/2008/09/17/N212Id.aspx#41747</link><pubDate>Thu, 21 Dec 2006 06:02:05 GMT</pubDate><guid isPermaLink="false">045f8e2a-3b25-43b2-9769-9c60de2974e3:41747</guid><dc:creator>Regulator</dc:creator><description>&lt;p&gt;Another tip!
&lt;/p&gt;&lt;p&gt;Go to www.firefox.com , head over to the AddOns section of their's and search for the AddOn called NoScript.
&lt;/p&gt;&lt;p&gt;Install NoScript for Firefox (done in 1 min tops).
&lt;/p&gt;&lt;p&gt;This makes you in charge of what scripts that you allow to run in your firefox.
&lt;/p&gt;&lt;p&gt;Cheers, merry christmas!
&lt;/p&gt;&lt;div class="cb"&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://my.curse.com/aggbug.aspx?PostID=41747" width="1" height="1"&gt;</description></item></channel></rss>