Home Forum Downloads My Favorites Register FAQ Mark Forums Read

Go Back   EQInterface Forums > General Discussion > Chit Chat
User Name
Password

Reply
 
Thread Tools Display Modes
Old 03-08-2003, 01:09 PM   #1
Cairenn
Credendo Vides
 
Cairenn's Avatar
 
Join Date: Jul 2002
Posts: 3,866
Interface Author - Click to view interfaces
Default *** Important Notice ***

There was recently another case of a Trojan virus being spread around via a UI by the name of GlixUI. It is a keyboard recorder for "stealing" EQ accounts + passwords. Everyone needs to keep these things in mind:

1. NEVER run Remmy.exe unless it came from Remelio's site, the T.king Art site, the EQLive site or EQinterface.com (here).
2. NEVER run an .exe file provided by unknown sources.
3. If you think you have this Trojan on your system, please contact EverQuest Customer Service immediately.
4. T.King, Remelio, the EQinterface.com team, Sony Online Entertainment, and Federal Bureau of Investigation are all aware of this Trojan virus, and we are doing everything that we can to help put an end to its proliferation.
__________________
"My friends, love is better than anger. Hope is better than fear. Optimism is better than despair. So let us
be loving, hopeful and optimistic. And we’ll change the world."


Co-Founder & Admin: MMOUI
FaceBook Profile, Page, Group
Avatar Image by RafM

Last edited by Kudane : 03-08-2003 at 01:38 PM.
Cairenn is offline   Reply With Quote
Old 03-08-2003, 01:22 PM   #2
Son-of-a-Gun
A Snow Griffin
 
Son-of-a-Gun's Avatar
 
Join Date: Dec 2002
Server: None Current
Posts: 52
Interface Author - Click to view interfaces
Send a message via AIM to Son-of-a-Gun
Unhappy Hmm

I hope i didnt get this, i have been finding myself dead even though havent played for a while , scary
__________________
Believe.
Son-of-a-Gun is offline   Reply With Quote
Old 03-08-2003, 03:04 PM   #3
Maiyn
A Gray Wolf
 
Join Date: Aug 2002
Server: Druzzil Ro
Posts: 6
Default

Just a Question will the lastest virus def from norton anti virus detct this?
Maiyn is offline   Reply With Quote
Old 03-08-2003, 04:33 PM   #4
wildtiger
A Ghoul
 
Join Date: Aug 2002
Server: E'CI
Posts: 19
Default

i was on a friends computer looking at new downloads for the interface and he has norton firewall installed and it detected a trojan attack attempt so he was lucky
wildtiger is offline   Reply With Quote
Old 03-08-2003, 06:31 PM   #5
Caleal
Enhanced Imperial Golem
 
Join Date: Sep 2002
Posts: 201
Interface Author - Click to view interfaces
Default

Any good firewall software, or hardware, will prevent the communication that this type of trojan tries to do. You still need antivirus software, or to practice safe computing, to prevent them from being installed in the first place though.

I personally use a US Robotics router with a built in firewall, and update the firmware regularly. I don't use antivirus software, but I am the only user for any of the computers on my network, and am very selective about what I download.

BTW, kudos to you Cairenn, or whoever it was that spotted it first and reported it to the place that was hosting it. I noticed they killed the pages for "Violations of terms of service" almost imediatly. =)
__________________
Caleal P`Terak
BATTLE CLERIC of Innoruuk, ret
Cazic-Thule server
Shadowed Soul
Caleal is offline   Reply With Quote
Old 03-09-2003, 08:04 AM   #6
Aamdaron
A Gray Wolf
 
Join Date: Mar 2003
Posts: 5
Default

i downloaded this and unzipped it but never ran the .exe file norton doesnt detect any viruses (this is the online scan) am i safe?
Aamdaron is offline   Reply With Quote
Old 03-09-2003, 12:51 PM   #7
Kudane
Co-Founder
 
Kudane's Avatar
 
Join Date: Jul 2002
Server: Xegony
Posts: 2,145
Interface Author - Click to view interfaces
Default

Quote:
Originally posted by Aamdaron
i downloaded this and unzipped it but never ran the .exe file norton doesnt detect any viruses (this is the online scan) am i safe?


the trojan was hidden in the EXE, not the zip.. soooo delete the EXE (all the files really) and you will be just fine..

i recommend deleting so you dont forget and go back and run it..
__________________


.: Have a question? Read this :.
[ F.A.Q ]
Kudane is offline   Reply With Quote
Old 03-09-2003, 07:58 PM   #8
Aamdaron
A Gray Wolf
 
Join Date: Mar 2003
Posts: 5
Default

yeah done that thanks for help
firewall not detecting any attacks and norton not picking up anything so i think ill be fine
Aamdaron is offline   Reply With Quote
Old 03-09-2003, 08:09 PM   #9
Aamdaron
A Gray Wolf
 
Join Date: Mar 2003
Posts: 5
Default

all other exe on the site fine to run though? ie ccake by sokol etc?
Aamdaron is offline   Reply With Quote
Old 03-09-2003, 08:53 PM   #10
thyil
A Gray Wolf
 
Join Date: Oct 2002
Posts: 5
Unhappy hacked

i got this lameass virus too, my account was suspended for 3 weeks pending this investigation i found the trojan in this file..
3cmlnkw.exe so all plz be advised, i must say it truely sux not being able to play ;( only places i have been downloading from were here but i did download a gui driven equi editor, im not sure when i got this but who knows man.
PS.... is this trojan only hidden in .exe files or is it possible it is in .xml? i dont know much about xml and i wanna use my beloved sars gui but am leary of useing stuff from other ppl now.
thyil is offline   Reply With Quote
Old 03-09-2003, 09:45 PM   #11
Cairenn
Credendo Vides
 
Cairenn's Avatar
 
Join Date: Jul 2002
Posts: 3,866
Interface Author - Click to view interfaces
Default

If we leave it up on the site, you can bet your bottom dollar that we've checked it. Remmy.exe (from the four sites mentioned) and Ccake by Sokol found here, are safe.

.xml files themselves are safe. A trojan virus requires an executable file.

To quote Kudane from the front page:

Quote:
Let me add, that very few authors use ".exe" files for thier mods, or patches.. and I try to put a note in the comment section after checking them out, to let you know they are safe. We do have a couple that use Java Scripts and Dobly has decompiled these, and he will put his "stamp of approval" on these to let you know.
Cairenn is offline   Reply With Quote
Old 03-09-2003, 10:07 PM   #12
Dolby
Lord Dolby of Veeshan
 
Dolby's Avatar
 
Join Date: Jul 2002
Server: Veeshan
Posts: 2,397
Default

Aye, files hosted by us are checked and if their is the slightest doubt we delete it. You need to watch out for external links in posts to interfaces.
Dolby is offline   Reply With Quote
Old 03-10-2003, 02:49 AM   #13
Curumtiny
A Shissar Defiler
 
Join Date: Aug 2002
Server: Tarew Marr
Posts: 185
Default

Would a Zip file be considered a executable file type? Also so should we now be weary of people posting their own websites for downloads of their UIs?
__________________

Curumtiny Call Me Yoda
Gnome Warrior (GnomeLord) Level 65
Tarrew Marr
Guild Officer: Invictus Verite
Click on Signiture for Magelo Profile
Curumtiny is offline   Reply With Quote
Old 03-10-2003, 03:03 AM   #14
Dolby
Lord Dolby of Veeshan
 
Dolby's Avatar
 
Join Date: Jul 2002
Server: Veeshan
Posts: 2,397
Default

only really need to worry about .vbs and .exe

A zipfile is only a container... kinda like a breifcase or a purse. So the zipfile it self is safe but the things inside may not be. Good thing you can look inside the zip w/o getting hurt.

As for external links... unless you know the author your takeing a risk like with anything you download.
Dolby is offline   Reply With Quote
Old 03-10-2003, 06:44 AM   #15
Katn
An Icepaw Kobold
 
Katn's Avatar
 
Join Date: Aug 2002
Posts: 87
Interface Author - Click to view interfaces
Default

Wow this is some scary stuff..can't beleave someone would go that low to put virus's in a UI like that

I keep it safe and only go to eqinterface..tking, and Rem websites..hehe
Katn is offline   Reply With Quote
Reply



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT -5. The time now is 09:38 PM.


vBulletin Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© MMOUI