Ultimate Online Forums
Go Back   Ultimate Online Forums > Ultima Online > Ultima Online General Discussion

Ultima Online General Discussion Forum for general chat on UO.

 
Thread Tools
Old 19th November 2005, 07:33 AM   #1
Petra Fyde
Visiting from Robin Hood Country
 
Petra Fyde's Avatar
 
Join Date: Jul 2005
Shard: Europa
Posts: 180
Gold: 277
Thanks: 1
Thanked 15 Times in 7 Posts
Petra Fyde is unknown
Thumbs down Armor Manager - is everyone aware?

Picked this information up in UO Hall.

There's a program called Armor Manager. It claims to help you organise your armor properties by working with UO assist dress macro. Which would appear to make it ok to use, since it doesn't interact directly with uo.

But

It apparently has a keylogger in it and is the cause of several of the recent hackings.

Divider

Petra Fyde is offline   Return to Top Reply With Quote
Old 19th November 2005, 07:39 AM   #2
SpyderBite
Guest
 
SpyderBite's Avatar
 
Posts: n/a
Gold: 0 [Check]
Re: Armor Manager - is everyone aware?

Quote:
Picked this information up in UO Hall.
You found a nugget of good information in U.Hall... Impressive. Now go get some rest, Petra you must be exhausted shoveling through the rest of the bs in there to find this gem. hehe

Thanks for the heads up.. I get so frustrated trying to put resists together that I would have installed that proggy in a heartbeat had you not warned us first!
  Return to Top Reply With Quote
Old 19th November 2005, 08:00 AM   #3
Epona
You Have Been Epownt!
 
Epona's Avatar
 
Join Date: Sep 2004
Shard: Catskills
Posts: 687
Gold: 1,105
Thanks: 0
Thanked 0 Times in 0 Posts
Epona the FairEpona the FairEpona the Fair
Re: Armor Manager - is everyone aware?

Just hire me!

Divider

Epona is offline   Return to Top Reply With Quote
Old 19th November 2005, 12:12 PM   #4
UOForums AdministratorAlly
The Couch Hottie
 
Ally's Avatar
 
Join Date: Aug 2004
Shard: Lake Austin, Atlantic
Posts: 4,420
Gold: 2,937
My Mood:
Thanks: 35
Thanked 10 Times in 10 Posts
Ally the GoodAlly the GoodAlly the GoodAlly the GoodAlly the GoodAlly the GoodAlly the GoodAlly the GoodAlly the GoodAlly the GoodAlly the Good
Re: Armor Manager - is everyone aware?

Quote:
Originally Posted by SpyderBite
Thanks for the heads up.. I get so frustrated trying to put resists together that I would have installed that proggy in a heartbeat had you not warned us first!
Hehe... that's what friends are for. I didn't put together anything that I'm wearing right now.

Thanks for the warning Petra

Divider


Lilypie 1st Birthday PicLilypie 1st Birthday Ticker
Ally is online now   Return to Top Reply With Quote
Old 19th November 2005, 12:31 PM   #5
SpyderBite
Guest
 
SpyderBite's Avatar
 
Posts: n/a
Gold: 0 [Check]
Re: Armor Manager - is everyone aware?

Quote:
Originally Posted by Ally
Hehe... that's what friends are for. I didn't put together anything that I'm wearing right now.

Thanks for the warning Petra
Heh.. my friends would tire of me sending them pigeons every 20 minutes though... I go through armor WAY to fast to worry about whether a friend is online to help me sort through it. *chuckles*
  Return to Top Reply With Quote
Old 30th November 2005, 05:22 AM   #6
Smythe
 
Smythe's Avatar
 
Join Date: Oct 2005
Shard: Napa Valley
Posts: 43
Gold: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Smythe is unknown
Re: Armor Manager - is everyone aware?

Not sure if this came up in the thread at U.Hall, but this trojan has now made its way onto ebay. I was bored tonight (or this morning, rather) and decided to see what things were selling on ebay. I go there and find these three programs:

*Links Removed by Admin*

I thought to myself, "These have got to be viruses." So I decided to download them (the seller so generously offers a seven day trial period ). The first sign of there being trouble was when all three programs had roughly the same file size (~498KB). So after completing the download (didn't take long) I ran them through some virus scanners. All three programs reported the same viruses. http://virusscan.jotti.org/ reported the following which remained constant for all three programs:
Quote:
Status:
INFECTED/MALWARE
MD5 a5700e95fcd26f427eb6f53f70ac064b
Packers detected:
-
Scanner results
AntiVir
Found Heuristic/Trojan.Downloader (probable variant)
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found BehavesLike:Trojan.Downloader (probable variant)
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found Trojan-Downloader.Win32.Delf.abo
NOD32
Found probably unknown NewHeur_PE (probable variant)
Norman Virus Control
Found Sandbox: W32/Downloader; [ General information ]

* File length: 39936 bytes.

[ Changes to filesystem ]
* Creates file C:\WINDOWS\icq.exe.

[ Network services ]
* Downloads file from (This -> icq.doc <- was a virus that I removed the link for so as to hopefully avoid any accidental downloads. For more information on this file see my second post in this thread.) as C:\WINDOWS\icq.exe.

[ Security issues ]
* Starting downloaded file - potential security problem.

[ Process/window information ]
* Attemps to NULL C:\WINDOWS\icq.exe NULL.
UNA
Found nothing
VBA32
Found nothing
I really hope no one falls for this. It is bad enough to lose your account, but to unwillingly pay someone to take it from you?

Last edited by Smythe; 30th November 2005 at 07:21 PM.
Smythe is offline   Return to Top Reply With Quote
Old 30th November 2005, 10:50 AM   #7
Severina
Guest
 
Severina's Avatar
 
Posts: n/a
Gold: 0 [Check]
Re: Armor Manager - is everyone aware?

It troubles me that so many virus scanners couldnt detect it.
  Return to Top Reply With Quote
Old 30th November 2005, 11:36 AM   #8
Thradia
*licks*
 
Thradia's Avatar
 
Join Date: Apr 2004
Shard: Napa Valley
Posts: 1,352
Gold: 382
Thanks: 0
Thanked 0 Times in 0 Posts
Thradia the KindThradia the KindThradia the KindThradia the KindThradia the KindThradia the KindThradia the Kind
Re: Armor Manager - is everyone aware?

The ebay links have been removed, as the auctions have links to these illegal third party programs. We do not endorse Third-Party programs at UOF, and it's our policy not to link to them.

However, please do be careful if you are seeking these out. And best not to buy downloadable programs from Ebay at all.

Thank you Smythe for showing us proof of the viruses. I do hope everyone will be careful.

Divider


Thradia is offline   Return to Top Reply With Quote
Old 30th November 2005, 07:22 PM   #9
Smythe
 
Smythe's Avatar
 
Join Date: Oct 2005
Shard: Napa Valley
Posts: 43
Gold: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Smythe is unknown
Re: Armor Manager - is everyone aware?

I linked to those ebay auctions as a means of showing people the infected files, host website, and ebay seller to stay away from. I understand why the links were removed, though.

Quote:
Originally Posted by Severina
It troubles me that so many virus scanners couldnt detect it.
If you thought that was bad then the virus scan for the icq.doc file was much worse.

Quote:
File: icq.doc
Status:
INFECTED/MALWARE
MD5 e7235bb46e395c2db7d938b1e0f19b93
Packers detected:
-
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found Trojan.DownLoader.5688
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found nothing
Only one scanner detected anything. :shocked:
Smythe is offline   Return to Top Reply With Quote
Old 1st December 2005, 03:12 AM   #10
Petra Fyde
Visiting from Robin Hood Country
 
Petra Fyde's Avatar
 
Join Date: Jul 2005
Shard: Europa
Posts: 180
Gold: 277
Thanks: 1
Thanked 15 Times in 7 Posts
Petra Fyde is unknown
Re: Armor Manager - is everyone aware?

erm,
icq.doc?

can you give us some idea where that came from and if it's something we're likely to have gotten from somewhere?

I don't accept files via icq, or anything else for that matter, but sometimes you don't actively have to accept something to get it anyway.
Was it part of the ebay package, or is it from a different source entirely?

Divider

Petra Fyde is offline   Return to Top Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Binky = Community Relations Manager for STOnline Adam Off Topic General Discussion 0 7th November 2007 01:32 PM
BBC Poll: Will Live Earth make people more environmentally-aware? Adam Hot Topics 2 8th July 2007 06:42 AM
Contact Lens Wearers - Be Aware Ally Off Topic General Discussion 8 30th May 2007 09:35 AM
UOForums interview with El of LA, UO Senior News Manager Adam Interview Area 5 10th July 2006 04:04 PM
Devs are Aware of all Problems Thradia UO News & Developer's posts 0 14th March 2006 07:45 AM


All times are GMT -6. The time now is 01:04 AM.


Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
Template-Modifications by TMS
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios