Christian Gamers Alliance Forums  

Go Back   Christian Gamers Alliance Forums > The Forgiven > General Chat

Reply
 
Thread Tools Display Modes
  #1  
Old February 28th, 2010, 11:11 AM
rhysj rhysj is offline
Member
 
Join Date: Nov 2006
Posts: 933
new authenticator virus please read

Trojan succesfully hacks Authenticator Protected Accounts
A new virus spawned on the internet a few days ago and seems to be the first trojan capable of hacking a WoW account protected by an Authenticator. It was confirmed by Blizzard a few hours ago.
Quote from: Kropacius (Source)
After looking into this, it has been escalated, but it is a Man in the Middle attack.

http://en.wikipedia.org/wiki/Man-in-the-middle_attack

This is still perpetrated by key loggers, and no method is always 100% secure.

Basically, what the virus does is fairly simple after you're infected :

* The next time you log in World of Warcraft, the game asks for your Authenticator code.
* The virus intercepts it, send it to another server, and sends a wrong one to Blizzard = You get an error.
* The people behind the virus now have a few seconds/minutes to use the "real" code while it's valid to change your password / empty your account / guild bank.


How to check if you're infected
Just search for a file named "emcor.dll" on your computer, it is most likely located in "C:\Users\(Your user name)\AppData\Temp" but I suggest that you check everything just to be sure. If you do find the file, delete it and make sure you update your anti-virus to prevent any further problem.

To be honest, if you found this file your account is probably already compromised.

What does it mean exactly?

* Yes, you can get hacked even if you have an authenticator, the chances are MUCH lower but you're not invulnerable.
* It definitely isn't an excuse to not have an authenticator. We're talking about a single virus here and the authenticator will save your ******oops*******oops*******oops* 99% of the time.
* Get a decent anti-virus, buy an authenticator, you'll be safe.
__________________


Reply With Quote
  #2  
Old February 28th, 2010, 11:44 AM
Neirai the Forgiven's Avatar
Neirai the Forgiven Neirai the Forgiven is offline
Christian Guilds List Manager
 
Join Date: Feb 2005
Location: Alberta, Canada, Terra, The Milky Way, Ardent Sector, Universe 2.4393, Multiverse 6, Omniverse A
Posts: 2,736
Rhys, before we go around deleting dlls, can we get a link to a blue thread talking about this virus?

I don't want to be mean (I don't think I am,) but when it comes to account security, I can't trust anything I read, short of an official document.

Can you link to a blue post on this?

Edit: I found it, but I haven't found any official link referring to the "fix," although it is up on MMO-C, who aren't likely to post a bad fix -- although they themselves have been hacked before :O <<< Paranoia is my watchword.

I agree with MMO-C, however. Good computer/internet security is always a must. An authenticator is a good step, too.
__________________
לדעת
It's not a question of whether or not Jesus would play video games... He would reach the lost no matter where He could find them. The REAL question is, HOW would He play video games??
WWJD seems to be to American Christians Consumers what Hello Kitty is to Japanese teenage girls. --ppar3566

Last edited by Neirai the Forgiven; February 28th, 2010 at 11:52 AM.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Mobile Authenticator now available on Android Gilga Redeemed General 3 February 13th, 2010 05:43 PM
Authenticator on any cell phone? Neirai the Forgiven General Chat 2 October 5th, 2009 07:18 PM
WoW Virus out Angus_Og General Chat 2 May 4th, 2006 09:37 PM
VIRUS?!?! [toj.cc]phantom General Discussion [cga] 3 May 14th, 2005 09:16 AM


All times are GMT -4. The time now is 08:30 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.