Trojan succesfully hacks Authenticator Protected Accounts

2 replies [Last post]
bushidox
Turns out kittehform is squishtastic. Who'd'a thought?
bushidox's picture
User offline. Last seen 13 weeks 4 days ago. Offline
Joined: 2007-03-26

Important! MMO has just reported that Blizzard has confirmed that there is a middleman account hacker for their authenticator.

A new virus spawned on the internet a few days ago and seems to be the first trojan capable of hacking a WoW account protected by an Authenticator. It was confirmed by Blizzard a few hours ago.
Basically, what the virus does is fairly simple after you're infected :

  • The next time you log in World of Warcraft, the game asks for your Authenticator code.
  • The virus intercepts it, send it to another server, and sends a wrong one to Blizzard = You get an error.
  • The people behind the virus now have a few seconds/minutes to use the "real" code while it's valid to change your password / empty your account / guild bank.

How to check if you're infected
Just search for a file named "emcor.dll" on your computer, it is most likely located in "C:\Users\(Your user name)\AppData\Temp" but I suggest that you check everything just to be sure. If you do find the file, delete it and make sure you update your anti-virus to prevent any further problem.

To be honest, if you found this file your account is probably already compromised.

What does it mean exactly?

  • Yes, you can get hacked even if you have an authenticator, the chances are MUCH lower but you're not invulnerable.
  • It definitely isn't an excuse to not have an authenticator. We're talking about a single virus here and the authenticator will save your ass 99% of the time.
  • Get a decent anti-virus, buy an authenticator, you'll be safe.

Reposted from MMO-champion.com

Blue source: http://forums.wow-europe.com/thread.html?topicId=12730404058&sid=1&pageNo=1#15

the more you know!

__________________

Yorex: "6pm server/hippie time, 7pm Mountain/Flyover State time, 8pm Central/Real People's time, 9pm Eastern/Godless Liberal time."

Antiarc
Bandages interrupt my dps rotation
Antiarc's picture
User offline. Last seen 1 day 18 hours ago. Offline
Joined: 2007-03-26

Run a software firewall. Problem solved.

Adrine (85 rogue), Delfina (80 priest), Taichon (80 paladin), Grigs (85 warrior), Adliene (85 shaman)
Tibs
Dr Tiblove, or: How I learned to stop worrying and love the stamina
Tibs's picture
User offline. Last seen 3 days 11 hours ago. Offline
Joined: 2007-03-26

Antiarc wrote:
Run a software firewall. Problem solved.

OH NOES! MY CLOCK CYCLES AND RAMZ!?!

__________________

- Move along, nothing to see here. -

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.