EQInterface Forums

EQInterface Forums (http://www.eqinterface.com/forums/index.php)
-   Chit Chat (http://www.eqinterface.com/forums/forumdisplay.php?f=15)
-   -   *** Important Notice *** (http://www.eqinterface.com/forums/showthread.php?t=7415)

Cairenn 03-08-2003 01:09 PM

*** Important Notice ***
 
There was recently another case of a Trojan virus being spread around via a UI by the name of GlixUI. It is a keyboard recorder for "stealing" EQ accounts + passwords. Everyone needs to keep these things in mind:

1. NEVER run Remmy.exe unless it came from Remelio's site, the T.king Art site, the EQLive site or EQinterface.com (here).
2. NEVER run an .exe file provided by unknown sources.
3. If you think you have this Trojan on your system, please contact EverQuest Customer Service immediately.
4. T.King, Remelio, the EQinterface.com team, Sony Online Entertainment, and Federal Bureau of Investigation are all aware of this Trojan virus, and we are doing everything that we can to help put an end to its proliferation.

Son-of-a-Gun 03-08-2003 01:22 PM

Hmm
 
I hope i didnt get this, i have been finding myself dead even though havent played for a while , scary

Maiyn 03-08-2003 03:04 PM

Just a Question will the lastest virus def from norton anti virus detct this?

wildtiger 03-08-2003 04:33 PM

i was on a friends computer looking at new downloads for the interface and he has norton firewall installed and it detected a trojan attack attempt so he was lucky

Caleal 03-08-2003 06:31 PM

Any good firewall software, or hardware, will prevent the communication that this type of trojan tries to do. You still need antivirus software, or to practice safe computing, to prevent them from being installed in the first place though.

I personally use a US Robotics router with a built in firewall, and update the firmware regularly. I don't use antivirus software, but I am the only user for any of the computers on my network, and am very selective about what I download.

BTW, kudos to you Cairenn, or whoever it was that spotted it first and reported it to the place that was hosting it. I noticed they killed the pages for "Violations of terms of service" almost imediatly. =)

Aamdaron 03-09-2003 08:04 AM

i downloaded this and unzipped it but never ran the .exe file norton doesnt detect any viruses (this is the online scan) am i safe?

Kudane 03-09-2003 12:51 PM

Quote:
Originally posted by Aamdaron
i downloaded this and unzipped it but never ran the .exe file norton doesnt detect any viruses (this is the online scan) am i safe?


the trojan was hidden in the EXE, not the zip.. soooo delete the EXE (all the files really) and you will be just fine..

i recommend deleting so you dont forget and go back and run it..

Aamdaron 03-09-2003 07:58 PM

yeah done that thanks for help
firewall not detecting any attacks and norton not picking up anything so i think ill be fine :D :D :D

Aamdaron 03-09-2003 08:09 PM

all other exe on the site fine to run though? ie ccake by sokol etc?

thyil 03-09-2003 08:53 PM

hacked
 
i got this lameass virus too, my account was suspended for 3 weeks pending this investigation i found the trojan in this file..
3cmlnkw.exe so all plz be advised, i must say it truely sux not being able to play ;( only places i have been downloading from were here but i did download a gui driven equi editor, im not sure when i got this but who knows man.
PS.... is this trojan only hidden in .exe files or is it possible it is in .xml? i dont know much about xml and i wanna use my beloved sars gui but am leary of useing stuff from other ppl now.

Cairenn 03-09-2003 09:45 PM

If we leave it up on the site, you can bet your bottom dollar that we've checked it. Remmy.exe (from the four sites mentioned) and Ccake by Sokol found here, are safe.

.xml files themselves are safe. A trojan virus requires an executable file.

To quote Kudane from the front page:

Quote:
Let me add, that very few authors use ".exe" files for thier mods, or patches.. and I try to put a note in the comment section after checking them out, to let you know they are safe. We do have a couple that use Java Scripts and Dobly has decompiled these, and he will put his "stamp of approval" on these to let you know.

Dolby 03-09-2003 10:07 PM

Aye, files hosted by us are checked and if their is the slightest doubt we delete it. You need to watch out for external links in posts to interfaces.

Curumtiny 03-10-2003 02:49 AM

Would a Zip file be considered a executable file type? Also so should we now be weary of people posting their own websites for downloads of their UIs?

Dolby 03-10-2003 03:03 AM

only really need to worry about .vbs and .exe

A zipfile is only a container... kinda like a breifcase or a purse. So the zipfile it self is safe but the things inside may not be. Good thing you can look inside the zip w/o getting hurt.

As for external links... unless you know the author your takeing a risk like with anything you download.

Katn 03-10-2003 06:44 AM

Wow this is some scary stuff..can't beleave someone would go that low to put virus's in a UI like that :(

I keep it safe and only go to eqinterface..tking, and Rem websites..hehe


All times are GMT -5. The time now is 01:50 AM.

vBulletin Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.