BulletProof Nerds Gaming Community
May 25, 2012, 06:33:24 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: TO POST ON THE FORUMS YOU MUST REGISTER ON THE BPN HOMEPAGE, ONCE YOU ARE LOGGED IN THERE, IT AUTOMATICALLY LOGS YOU INTO THE FORUMS AS WELL.  IF YOU STILL CAN'T POST THEN LOG OUT OF THE WEBSITE AND LOG BACK IN, THEN COME BACK TO THE FORUMS.
 
   Home   Help BPN HOMEPAGE Search Login Register  
Pages: 1   Go Down
  Print  
Author Topic: Curse Client Infected by Virus  (Read 803 times)
0 Members and 1 Guest are viewing this topic.
Schlup
Master Admin
1000 POSTS CLUB!!!
*
*

BPN Props: 1226
Offline Offline

Posts: 6664



WWW Awards
« on: December 27, 2011, 06:10:05 PM »

Just an FYI for everybody playing WoW, since I think most people use Curse Client for their WoW addons.  Apparently one of the ads on Curse client infected not 1 but 2 of my computers, also Templar was infected by the same virus.  Please do not treat this as I did when Templar told me about it and kinda blew it off because I didn't think Curse client was infected, they are.  This one is kinda scary as it requires NO user input to download and install the virus.  Simply by having curse client you are leaving yourself open to this virus which I believe includes a root kit virus as well.  It's the most nasty virus I've ever seen and was quite a chore to remove.  It's a rogue virus as well which means it will automatically change it's name and location to avoid detection and removal.

I have tried letting the folks over at Curse know about this virus but they seem to want to push it under the rug and it appears they have no intention at this time of finding its source and removing it. 

I HIGHLY RECOMMEND YOU UNINSTALL CURSE CLIENT AS SOON AS POSSIBLE.

I'm just one of lots of people who have tried telling Curse that one of their ads is infected.  You can visit their forums if you wish to research this further.  The scariest part was my laptop which has only WoW and Curse client installed was infected with the virus this morning without even touching it.  I will be adding a guild message of the day to help spread the word to other guildies.

The virus will act like a piece of anti-virus software titled "Win 7 Security 2012", it will also hijack your browser (all browsers) and redirect to infected websites.  Also, it will take over the Windows scripting program and make any program you open instead just open the virus and the fake anti-virus program.

If you have been infected you will want to go to the following site and follow their directions explicitly.  In fact, I'd recommend everybody that has curse client go here and follow directions for removal.

http://www.bleepingcomputer.com/virus-removal/remove-win-7-security-2012

Monkey_Grill
Senior Admin
1000 POSTS CLUB!!!
*
*

BPN Props: 55
Offline Offline

Posts: 1417



Awards
« Reply #1 on: December 27, 2011, 11:19:26 PM »

Thanks for the info. Curse has been uninstalled.

CoCoCountyKiller
Member
500 POSTS CLUB!
*

BPN Props: 5
Offline Offline

Posts: 729


Awards
« Reply #2 on: December 28, 2011, 10:02:33 AM »

ouch sounds like a bad one!!

co.co.

Co.Co.
Schlup
Master Admin
1000 POSTS CLUB!!!
*
*

BPN Props: 1226
Offline Offline

Posts: 6664



WWW Awards
« Reply #3 on: December 28, 2011, 08:26:33 PM »

Yeah, my Mom called tonight, she doesn't run any curse or anything, she had the virus too.  Seems like this is gonna be a nasty one that's gonna get around.  Keep an eye out and visit the site I listed if you get it.

CoCoCountyKiller
Member
500 POSTS CLUB!
*

BPN Props: 5
Offline Offline

Posts: 729


Awards
« Reply #4 on: December 29, 2011, 10:38:27 AM »

sounds like it is some bad magic Smiley

co.co.

Co.Co.
Schlup
Master Admin
1000 POSTS CLUB!!!
*
*

BPN Props: 1226
Offline Offline

Posts: 6664



WWW Awards
« Reply #5 on: December 29, 2011, 03:26:57 PM »

Well Curse finally admitted it and resolved the issue.  You can read more at their news release below...
http://www.curse.com/news/curse/43460-official-update-regarding-virus-spread-through

samaddams
Member
Newbie Poster
*

BPN Props: 0
Offline Offline

Posts: 6



Awards
« Reply #6 on: February 07, 2012, 08:39:47 PM »

For future reference, always keep flash/java/adobe reader up to date. Not sure if it would have helped in that case, but most online ads use flash, and they regularly roll security updates out.

Java and PDFs are also known to have vulnerabilities from time to time.

Goes without saying, keep your antivirus up to date. If you need a free one I suggest Microsoft Security Essentials.

Intel Quad @ 2.33 GHz
8GB RAM
GeForce 9800 GTX
160GB hard drive, 1TB hard drive
Beer Stein!
Pages: 1   Go Up
  Print  
 
Jump to:  


Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Page created in 0.419 seconds with 23 queries.