Post by POTS on Feb 12, 2005 19:13:25 GMT
At aprox 11:10 CST I was attacked by W32.bropia WORM while logging in to HG.
The attack caused NWN to minimize and WINAMP (my default media player) to open. It also caused the ICON in my taskbar to show that my internet connection was closed (although it was still open).
I immediately disconnected from the internet, updated my ANTI-VIRUS software, and began a full scan. No threats were detected.
In addition I ran ADAWARE 6.0 (spyware removal app) and it detected (2) attempeted edits to the registry.
Also Norton Personal Firewall detected that ISASS.exe (the executable for the W32.bropia WORM) was attempting to access the internet (but had been blocked by NPF).
Others that were logged in to HG also reported the problem.
Here is a link to information on SYMANTEC/NORTON website reference this WORM:
securityresponse.symantec.com/avcenter/venc/data/w32.bropia.m.html
I am looking into this situation some more, but my experience with this is very limited. I am putting this post up although it is not complete just to try and help everyone avoid any problems. If i find out more I will add to this post.
The other person that mentioned the problem (shortly after the restart) was character name "Eryan"(sp) or something. He stated that the attacking IP had traced somewhere out of Germany for what it is worth. He also stated that the version in question was some type of exploit of the nwn character login.
I have logged in to the game since completing the recomended steps from Norton without any problems.
To be safe i recomend everyone keep thier AV software and Firewall up-to-date, and run it (AV) often.
The attack caused NWN to minimize and WINAMP (my default media player) to open. It also caused the ICON in my taskbar to show that my internet connection was closed (although it was still open).
I immediately disconnected from the internet, updated my ANTI-VIRUS software, and began a full scan. No threats were detected.
In addition I ran ADAWARE 6.0 (spyware removal app) and it detected (2) attempeted edits to the registry.
Also Norton Personal Firewall detected that ISASS.exe (the executable for the W32.bropia WORM) was attempting to access the internet (but had been blocked by NPF).
Others that were logged in to HG also reported the problem.
Here is a link to information on SYMANTEC/NORTON website reference this WORM:
securityresponse.symantec.com/avcenter/venc/data/w32.bropia.m.html
I am looking into this situation some more, but my experience with this is very limited. I am putting this post up although it is not complete just to try and help everyone avoid any problems. If i find out more I will add to this post.
The other person that mentioned the problem (shortly after the restart) was character name "Eryan"(sp) or something. He stated that the attacking IP had traced somewhere out of Germany for what it is worth. He also stated that the version in question was some type of exploit of the nwn character login.
I have logged in to the game since completing the recomended steps from Norton without any problems.
To be safe i recomend everyone keep thier AV software and Firewall up-to-date, and run it (AV) often.