Unofficial World of Warcraft Forums  
Please respect other members. Please do not post links or information about hacking/warez/cheats.
Read the rules of these forums as we rarely warn before banning. Lost or need RSS check the forum map.

Quick Site Nav
Navigation
WoW: IncGamers
WoW Forums
Community Blogs
WoW Info
Wrath of the Lich King Info
Primary Professions
Secondary Professions
Maps
Classes
PvP
A-Z Index
Guides
Submit Guides
List Guides
UI/Mods
Latest Mods
Submit Mod
List Macros
Submit Macro
Media Gallery
Gallery Home
Upload Pics
Community WoW Shots
Community BC Shots
Player Pics
Official WoW Shots
Official BC Shots


Donate and get extra forum perks
Support WoW:IncGamers

Go Back   Unofficial World of Warcraft Forums > WoW Community Forums > UI Customisation > WoWUI Site Feedback Forum
Connect with Facebook

Reply
 
Thread Tools Display Modes
Old 11-01-2008, 12:07 AM   #1
Wolivere
WoW: IncGamers Member
 
Join Date: Nov 2007
Location: Winnipeg
Posts: 3
UI Central File Concern

I installed UI Central two days ago this morning, and my account was compromised this morning.

After looking into it, right now lit looks like I got Trojan.Agent.AFZI from UI central.

C:\Windows\SysWOW64\wzcsvbc.dll Trojan.Agent.AFZI Deleted


Its the second time I have had issues from here.
Wolivere is offline   Reply With Quote
Old 11-01-2008, 01:21 AM   #2
Rushster
Administrator
 
Rushster's Avatar
 
Join Date: Jun 2003
Location: Edinburgh, Scotland
Posts: 5,767
To wolivere54. UICentral is clean, no virsuses or trojans. Checked with latest download on the site, NoD32 and Kaspersky. All files 100% perfect. Also on new install from the file hosted here no such file trojan inserted into Windows directory. I suggest you look elsewhere for the issue I'm afraid :(


Quote:
Originally Posted by Wolivere View Post
I installed UI Central two days ago this morning, and my account was compromised this morning.

After looking into it, right now lit looks like I got Trojan.Agent.AFZI from UI central.

C:\Windows\SysWOW64\wzcsvbc.dll Trojan.Agent.AFZI Deleted


Its the second time I have had issues from here.
__________________
"We are the priest of the Temples of Syrinx!"
Rushster is offline   Reply With Quote
Old 11-01-2008, 08:32 PM   #3
Kimina
WoW: IncGamers Member
 
Join Date: Nov 2007
Posts: 6
Quote:
Originally Posted by Rushster View Post
To wolivere54. UICentral is clean, no virsuses or trojans. Checked with latest download on the site, NoD32 and Kaspersky. All files 100% perfect. Also on new install from the file hosted here no such file trojan inserted into Windows directory. I suggest you look elsewhere for the issue I'm afraid :(
Actually Rushster I spent the last few hours performing analysis and I have to disagree with you once again, I'm afraid. I don't want this to become as big of a deal as it was last time so I'll gladly give you all of my information on the details of the infection and I urge you to rebuild your program and reupload it. In the meantime if you want to meet me somewhere where we can talk such as irc.freenode.net (Find me as Shirik) I'll fill you in.

Regards,
-- Kimina
Kimina is offline   Reply With Quote
Old 11-01-2008, 09:59 PM   #4
Thargos
WoW: IncGamers Member
 
Thargos's Avatar
 
Join Date: Dec 2006
Posts: 1,200
o rly? ?
Thargos is offline   Reply With Quote
Old 11-01-2008, 10:28 PM   #5
Asteria
WorldofWar.Net Member
 
Asteria's Avatar
 
Join Date: Jan 2005
Posts: 138
Quote:
Originally Posted by Thargos View Post
And suddenly it all becomes clear. Why am I not surprised to see a link from that site.
For the record my version (from this site of course) is clean too.
Asteria is offline   Reply With Quote
Old 11-01-2008, 10:40 PM   #6
Kimina
WoW: IncGamers Member
 
Join Date: Nov 2007
Posts: 6
Quote:
Originally Posted by Asteria View Post
And suddenly it all becomes clear. Why am I not surprised to see a link from that site.

For the record my version (from this site of course) is clean too.
Naturally I can't tell you the date of the infection, which means I'm sure there are safe people out there whom downloaded it at an OK time. But the copy I downloaded this morning was indeed infected, as can be proven because the malicious part of the application is actually even written in .NET, and compiled .NET is actually extremely trivial to convert back into source code.

The steps in that link should be sufficient to ensure your safety.
Kimina is offline   Reply With Quote
Old 11-01-2008, 10:43 PM   #7
Rushster
Administrator
 
Rushster's Avatar
 
Join Date: Jun 2003
Location: Edinburgh, Scotland
Posts: 5,767
I am looking into this again to triple check.
__________________
"We are the priest of the Temples of Syrinx!"
Rushster is offline   Reply With Quote
Sponsored Links
Old 11-01-2008, 11:49 PM   #8
cladhaire
WoW: IncGamers Member
 
Join Date: Oct 2005
Location: Syracuse, NY
Posts: 1
Quote:
Originally Posted by Asteria View Post
And suddenly it all becomes clear. Why am I not surprised to see a link from that site.
For the record my version (from this site of course) is clean too.
No one raised any alarms. The community did exactly what you asked them to do by alerting you as soon as they were able to verify a threat. Why the ridiculous mudslinging already =(.

I hope some day you realize that some members of the community aren't in this for the competition or the thrill of it, but quite literally for the good of the addon community.

Best wishes to WowUI as you work through resolving and verifying this issue.

- Cladhaire
cladhaire is offline   Reply With Quote
Old 12-01-2008, 01:02 AM   #9
Grizzly UK
WorldofWar.Net Member
 
Grizzly UK's Avatar
 
Join Date: Jul 2005
Location: England, UK
Posts: 60
Quote:
Originally Posted by Asteria View Post
And suddenly it all becomes clear. Why am I not surprised to see a link from that site.
For the record my version (from this site of course) is clean too.
What an amazing response! Instead of waiting and allowing Rushter and the team here to investigate you just up and shoot the messenger! IF UICentral has been infected then it should be investigated and if the warnings are correct everyone needs to be informed so that people can take appropriate measures!

Do you really want to risk your account being hijacked just because YOU think it's easier to blame another site! Your response is just plain ignorant and immature! Maybe in future you should leave the backyard politics where they belong, otherwise just !
Grizzly UK is offline   Reply With Quote
Old 12-01-2008, 01:34 AM   #10
Rushster
Administrator
 
Rushster's Avatar
 
Join Date: Jun 2003
Location: Edinburgh, Scotland
Posts: 5,767
Regarding date of infection. Based on findings so far it would have been after 14:16 CET (GMT +1) on 11th Jan. I think this file has been tampered with but we are running a full server sweep right now. To be on the safe side I would check your files if you did download after that above stated time. I don't think it will have affected many people and it will not have infected people already using the application. Needless to say I am pretty fed up with the gold farmers, they are such a pain in the arse and really spend a lot of time looking for expolits. Sadly I have a feeling they are on the prowl again, and like last time, I fear we will see a spate of attacks on multiple sites in the coming weeks.

As for UIC, well I am leaving it offline for download just now while I look at a super-secure mode of distro for the UIC installer.

No mods on the site will have be affected because we don't accept executable files in case anyone is worrying about that.
__________________
"We are the priest of the Temples of Syrinx!"
Rushster is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 07:39 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Advertisement System V2.5 By   Branden