Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > Forest of True Sight > Technician's Corner

Notices

Reply
 
Thread Tools Display Modes
Old Nov 13, 2006, 06:45 PM // 18:45   #1
Wilds Pathfinder
 
Join Date: May 2006
Guild: Hooded Reavers of Eternal Life(Ankh)
Profession: R/
Advertisement

Disable Ads
Default Friendly warning about keyloggers

the back story:

I've been into computers for umpteen years and managed networks etc. Yesterday I grabbed from guru a nice little app (so I thought) that would alleviate my troubles with wiki when it came to looking up skills. It turned out to be a keylogger that I (think) I've managed to squash before it could do any real damage.

Guru promptly deleted the post although I think deleting just the link and posting a warning would have been better.

Yes it was total stupidity on my party and I totally should have known better. But wiki has been problematic and I was desperate and so I did a stupid thing by not checking the source of the post.

the warning:

Never never ever dl something from a forum and just run it. (hell, I checked it with norton etc b4 running it and it passed so I ran it anyway) If you want something talked about in a forum find the home site and do some research.

Never let your own frustration get the best of you and make you do something you wouldn't do in your right mind. There will ALWAYS be someone who anticipates your frustration and positions themself to take advantage of that.

that should take care of it.


ps: if you by chance dl'ed the gwfreaks-installer thing that got posted several times yesterday, look for a 'sys' folder in your windows/system32 folder and take care of what you find there. Basically it's a bastardized version of the Ardakey.spyware keylogger. I never got either Norton or spybot to recognize this as a variant though so just delete manually. There will be a refernce to the gvae.exe file in your registry 'run' listing.

play safe!

edit: This isn't a plea for sympathy just a warning to others who might in a moment of weakness be tempted to do something stupid.

Last edited by Pkest; Nov 14, 2006 at 12:27 AM // 00:27..
Pkest is offline   Reply With Quote
Old Nov 13, 2006, 06:50 PM // 18:50   #2
I dunt even get "Retired"
 
unienaule's Avatar
 
Join Date: Aug 2005
Guild: Fifteen Over Fifty [Rare]
Default

Yeah, and it's an even better idea to never download programs that say they are, for example, "GWfreaks" when not only are they not hosted by GWFreaks, but are hosted on a site that masks where it's really from. But good warning, I guess we thought we nuked it before anyone downloaded it.

Don't flame him, he's warning other people who may have d/led it. Most people would assume that files linked to from here would be safer than random internet files, and that's why we nuked it when we noticed it was... very suspect at the least.
unienaule is offline   Reply With Quote
Old Nov 13, 2006, 06:56 PM // 18:56   #3
Wilds Pathfinder
 
Join Date: May 2006
Guild: Hooded Reavers of Eternal Life(Ankh)
Profession: R/
Default

I totally admit that it was me that dropped the ball on this. But I see it as a thing others might do so a warning about what is going around seems better than just deleting the posts as soon as the admins find them.
Pkest is offline   Reply With Quote
Old Nov 13, 2006, 07:15 PM // 19:15   #4
Ascalonian Squire
 
mask316's Avatar
 
Join Date: Nov 2005
Default

Just for future note. Housecall caught it on a family members computer. Housecall is a free up to date online scanner. I am not pushing them over the others just thinking because its online and updated all the time it may catch newer stuff. Its a Trend Micro product.

Just trying to help.

Take Care Happy Hunting!
mask316 is offline   Reply With Quote
Old Nov 13, 2006, 07:19 PM // 19:19   #5
Wilds Pathfinder
 
Join Date: May 2006
Guild: Hooded Reavers of Eternal Life(Ankh)
Profession: R/
Default

Quote:
Originally Posted by mask316
Just for future note. Housecall caught it on a family members computer. Housecall is a free up to date online scanner. I am not pushing them over the others just thinking because its online and updated all the time it may catch newer stuff. Its a Trend Micro product.

Just trying to help.

Take Care Happy Hunting!

Thanks! Good to know. I usually only run housecall after I've had an issue with Norton but perhaps I need to rethink that strategy. Especially since I had basically determined this thing was toxic and couldn't get any of my usual guardians to confirm it.

Last edited by Pkest; Nov 13, 2006 at 07:21 PM // 19:21..
Pkest is offline   Reply With Quote
Old Nov 13, 2006, 07:28 PM // 19:28   #6
Grotto Attendant
 
makosi's Avatar
 
Join Date: Mar 2006
Location: "Pre-nerf" is incorrect. It's pre-buff.
Guild: Requirement Begins With R [notQ]
Profession: Me/
Default

Like the Announcement says when the Guild Wars client opens, just don't download anything whatsoever unless its specifically endorsed by a reputable source. Anything directly related to Guild Wars will download automatically when the client opens and any other sources' 'patches' will most likely be keyloggers and you can wave bye-bye to your account forever.

Last edited by makosi; Nov 13, 2006 at 08:17 PM // 20:17..
makosi is offline   Reply With Quote
Old Nov 13, 2006, 07:43 PM // 19:43   #7
Wilds Pathfinder
 
Join Date: May 2006
Guild: Hooded Reavers of Eternal Life(Ankh)
Profession: R/
Default

Quote:
Originally Posted by makosi
Like the Announcement says when the Guild Wars client opens, just don't download anything whatsoever unless its specifically endorsed by a reuptable source. Anything directly related to Guild Wars will download automatically when the client opens and any other sources' 'patches' will most likely be keyloggers and you can wave bye-bye to your account forever.
As even Gaile has pointed out, the warning when you log into gw is really about programs that run during play or try to replace the gw client. There are a number of usefull utilites that don't require or try to hack the gw client (gwfreaks being one of them). You simply must be assured of the source.

For instance, the post I pulled the toxic thing from was an originated post by a very new member with only 8 posts. (hindsight is 20/20 I didn't check this at the time I will from now on - live and learn) There was a later post where someone asked for 'safe' utilities and several people responded with links all to the homesites of popular, useful lutilities.

The moral is to check the link and the provider of the link to make sure this is something legit and not just some fly-by-nighter posting a link to the latest greatest account stealer.

Yes of course you can avoid all 3rd party utils and probably be safe. But with Wiki's current situation, there are likely to be many seeking other alternatives and suggestions about the safest way to approach utils. Providing a few do's and don'ts about that is the goal of this thread.
Pkest is offline   Reply With Quote
Old Nov 13, 2006, 08:05 PM // 20:05   #8
Krytan Explorer
 
Lynxius's Avatar
 
Join Date: Apr 2006
Default

The fact that you took your time to warn the player community should be something praised.

Thank you for sharing this.

Not that i use any programs of any sort, but this might at least keep any tempted people at bay.

Gl & Hf
Lynxius is offline   Reply With Quote
Old Nov 13, 2006, 08:26 PM // 20:26   #9
Site Contributor
 
Join Date: Jun 2005
Profession: R/
Default

Thanks for the heads up! And you're right about House call, they find things that no other program does.
Commander Ryker is offline   Reply With Quote
Old Nov 13, 2006, 11:33 PM // 23:33   #10
La-Li-Lu-Le-Lo
 
Faer's Avatar
 
Join Date: Feb 2006
Default

We've been diligently nuking those threads and banning the spamming members as they appear, but sometimes we're not fast enough to save everyone the pain of getting infected.

It's nice to know that a member of the community is looking out for the rest of the crew.
__________________
Stay Breezy
Faer is offline   Reply With Quote
Old Nov 14, 2006, 12:20 AM // 00:20   #11
Pre-Searing Cadet
 
Join Date: Oct 2006
Profession: E/Mo
Default

http://www.virustotal.com

You can submit a file to this website, and it will give you the results from 26 different virus scanners.
I have had good luck with that.
Ravage382 is offline   Reply With Quote
Old Nov 14, 2006, 02:33 AM // 02:33   #12
Site Contributor
 
Neo Nugget's Avatar
 
Join Date: Jan 2006
Profession: R/
Default

Was it that thing where it was posted in 3 different topics?If so great catch in saving people alot of trouble.
Neo Nugget is offline   Reply With Quote
Old Nov 14, 2006, 02:55 AM // 02:55   #13
Grotto Attendant
 
LifeInfusion's Avatar
 
Join Date: May 2005
Location: in the midline
Profession: E/Mo
Default

GWFreaks is clean, you probably got a mirror that had been corrupted.
LifeInfusion is offline   Reply With Quote
Old Nov 14, 2006, 03:02 AM // 03:02   #14
Lion's Arch Merchant
 
GrandCharm~'s Avatar
 
Join Date: Jul 2006
Location: canada
Default

Quote:
Originally Posted by Pkest
the back story:
ps: if you by chance dl'ed the gwfreaks-installer thing that got posted several times yesterday, look for a 'sys' folder in your windows/system32 folder and take care of what you find there. Basically it's a bastardized version of the Ardakey.spyware keylogger. I never got either Norton or spybot to recognize this as a variant though so just delete manually. There will be a refernce to the gvae.exe file in your registry 'run' listing.

play safe!

edit: This isn't a plea for sympathy just a warning to others who might in a moment of weakness be tempted to do something stupid.
Damnit .. I downloaded that on my other computer and used my other account on it , it was gone =\
GrandCharm~ is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:04 PM // 13:04.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("