Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Irth Online and Zotob.A worm

If you are a Beta tester of Irth Online, make sure you have your anti-virus software updated.  There's a worm called Zotob.A that infects Windows and creates a backdoor for access to your computer.  If you are experiencing abnormally slow processing on your computer, especially during long patching and updates, be sure to monitor for any newly installed programs that is not part of the game.
«1

Comments

  • ScorpesScorpes Member Posts: 830
     Wow that is really bad, and I was considering trying out Irth soon. Are you sure its the installer from the source or was your version possibly infected locally?
  • HolaMariahHolaMariah Member Posts: 5
    I don't know.  I didn't really notice anything until I was patching and I thought it was taking much too long.  I got suspicious and decided to run the microsoft security activex control.  It found the Zotob.A worm.  I immediately updated my Norton Anti-virus too.  I suggest you do the same.
  • BronenekBronenek Member Posts: 240

    I have Norton Internet Security but it didn't seem to pick anything up, ever since I installed it to beta test it weeks ago.

    image

  • polarbanpolarban Member Posts: 5

    Where can I get that security activex control?  Is that part of the Norton antivirus update?

    Really? I didn't know brains were optional for this job.

  • Vlad75Vlad75 Member Posts: 18

    Is there a Windows security patch for this yet?

  • ZnithZnith Member Posts: 212

    Huh? Are you saying the new Irth update has a virus in it? Why do I not read anything about this on the Irth beta boards? I've scanned my pc with Kaspersky and Avast and show nothing

  • kishekishe Member UncommonPosts: 2,012

    Zotob.A is a worm that comes "with the flow" and nothing to do with irth patcher.

    It works same way as msblaster and sneaks around the firewall as fake packet.

  • specuscispecusci Member Posts: 8

    This thread is based on fallacy. First of all, there have been absolutely zero reports from beta testers of any kind of virus on their computer related to Irth Online or the patcher. Second of all, the lead Developer in charge of issuing and uploading the game patches does not have such a virus on their computer, and therefore cannot possibly pass the virus into computers through the patcher. There is no, has never been, and will never be a link between the patcher and this virus.


    DO NOT, and I repeat, DO NOT EVER AGAIN GO AROUND TALKING ABOUT ANY MMORPG, NOT JUST IRTH ONLINE, IN THIS FASHION WITHOUT CONSIDERABLE EVIDENCE OF SUCH A VIRUS. LEGAL ACTION CAN AND MAY VERY WILL BE TAKEN ON INDIVIDUALS CAUGHT DOING THIS, INCLUDING THE INDIVIDUAL IN THIS THREAD. THIS IS NOT A JOKE, YOU CAN BECOME FINED OR EVEN SPEND LENGTHY TIME IN PRISON FOR MISCONDUCT OF THIS MATTER.

  • Zaxx99Zaxx99 Member Posts: 1,761


    Originally posted by specusci
    This thread is based on fallacy. First of all, there have been absolutely zero reports from beta testers of any kind of virus on their computer related to Irth Online or the patcher. Second of all, the lead Developer in charge of issuing and uploading the game patches does not have such a virus on their computer, and therefore cannot possibly pass the virus into computers through the patcher. There is no, has never been, and will never be a link between the patcher and this virus.
    DO NOT, and I repeat, DO NOT EVER AGAIN GO AROUND TALKING ABOUT ANY MMORPG, NOT JUST IRTH ONLINE, IN THIS FASHION WITHOUT CONSIDERABLE EVIDENCE OF SUCH A VIRUS. LEGAL ACTION CAN AND MAY VERY WILL BE TAKEN ON INDIVIDUALS CAUGHT DOING THIS, INCLUDING THE INDIVIDUAL IN THIS THREAD. THIS IS NOT A JOKE, YOU CAN BECOME FINED OR EVEN SPEND LENGTHY TIME IN PRISON FOR MISCONDUCT OF THIS MATTER.


    lmao, shat up.

    If a person strongly feels that playing a mmo he downloaded gave him a virus, then he certainly has the freedom to state this. Whether or not he is wrong is right about where/how he got the virus, there is NO laws against this. It's called freedom of speech. By your ridiculous threats against him and your logic, then I can't go out in the street where people are at and yell out that "Microsoft Windows sucks" or I could be prisoned for causing grave harm to the product which I verbally trash.

    Legal action my ass. Sue the living hell out of me for saying that you my friend are a complete dope.

    - Oh, and typing your garbage in ALL CAPS doesn't make you any more correct, threatening, or scary. It only makes you rude and obnoxious. Combine that with your logic and you are out of the park when it comes to sanity and intelligence.

    Also, just a fact in my experience. I also got this same virus and noticed it only two days after downloading and playing the beta of Irth online. Just a fact. Related to Irth online or not? I don't know.
    Just stating facts. If you'd like proof of this, I'd be happy to send you a copy of the virus in an email or something. Well, I'd have to reinstall Irth to see if I get it again I guess, since my Panda anti virus protection is what noticed the virus and squashed it as soon as I did a full scan of my computer only 2 days after installing Irth. The previous full computer scan done on my computer was 8 days prior to installing the Irth beta.

    - Zaxx

    image

  • specuscispecusci Member Posts: 8


    - Oh, and typing your garbage in ALL CAPS doesn't make you any more correct, threatening, or scary. It only makes you rude and obnoxious. Combine that with your logic and you are out of the park when it comes to sanity and intelligence.

    There is actually a disclaimer that requires corrected and legal documentation through the internet in any shape, size or form to be in caps lock when stated by an authorizing programmer of Microsoft or its Affiliates.

  • Zaxx99Zaxx99 Member Posts: 1,761


    Originally posted by specusci
    There is actually a disclaimer that requires corrected and legal documentation through the internet in any shape, size or form to be in caps lock when stated by an authorizing programmer of Microsoft or its Affiliates.

    rotf. Oh my this is getting good. So "you" are telling me that "you" are a programmer of Microsoft eh? Let me guess. You programmed Windows XP yourself in 3 hours on your Commodore 64 right?


    - Zaxx

    image

  • specuscispecusci Member Posts: 8

    Um, no, I was in an office building with 300 fellow programmers for 3 years...

  • Damian_MHSDamian_MHS Member Posts: 4

    Zaxtor99

    Please read the security update before you attempt to also make a connection to Irth Online with this worm, it is distributed via EMAIL, not through a program.

    It is very clear about how it attacks, what files it effects, and Irth Online could not be one of them since it comes through via email.

    http://securityresponse.symantec.com/avcenter/venc/data/w32.zotob.j@mm.html

    Subject of email: Varies
    Name of attachment: Varies
    Size of attachment: n/a
    Time stamp of attachment: n/a
    Ports: TCP port 445.
    Shared drives: n/a
    Target of infection: Attempts to spread to systems vulnerable to a Windows Plug and Play exploit (MS05-039).

    Thanks

     

    Damian-

    Magic Hat Software

     

  • specuscispecusci Member Posts: 8

    As you can tell, it is impossible for this virus to have infected this file. Please do not doubt my credibility as Microsoft Porgrammer in the future.

  • Zaxx99Zaxx99 Member Posts: 1,761

    Damian, with all due respect, that's exactly where I got your program. You sent me an email with a link to download your game client.

    It's probably not related. I'm not saying that it is related to your program. Just stating facts as I know them with no real accusations.

    - Zaxx

    image

  • Damian_MHSDamian_MHS Member Posts: 4

    Zaxtor,

     

    With all due respect, you still have not read the security bulletin, it comes through email WITH an EXE attached to the email, not through a link to get a file.

     

    Please read the security bulletin before you continue this insanity, it is pretty straight forward.

     

    It either attacks you through an unsecure port or through an EMAIL With very distinctive text and an attached EXE file, not an email with a link.

     

    Damian

    Magic Hat Software

  • kishekishe Member UncommonPosts: 2,012


    Originally posted by zaxtor99
    Damian, with all due respect, that's exactly where I got your program. You sent me an email with a link to download your game client.It's probably not related. I'm not saying that it is related to your program. Just stating facts as I know them with no real accusations.- Zaxx

    most email viruses require you to open some shady attachments included in the email...and no mail i have gotten from irth online has had any attachments.

    trust me or not, there's no conspiracy, magic hat software is not spreading viruses.

  • Zaxx99Zaxx99 Member Posts: 1,761

    Damian, that's fine and I understand that I didn't get the virus though your game client. Thanks for your quick and accurate answers by the way.

    My post was more directed at the idea that someone saying that they think they may have got a virus through a program they used could land them in prison and cause lawsuits. That was the real target of my posts on this thread.

    However, I do see how people just seeing the thread titled "Irth Online and Zotob.A worm" could cause some doubt in the minds of onlookers who may not take sufficient time to real or investigate its legitimacy. For this reason, I am personally requesting that this thread by "locked" by a moderator. Hope it helps.


    - Zaxx

    image

  • SonterSonter Member Posts: 2


    Damian, with all due respect, that's exactly where I got your program. You sent me an email with a link to download your game client.

    Then what was that post for?

  • Damian_MHSDamian_MHS Member Posts: 4

    While I am no lawyer... I will not comment on the legality of the issue. Though I am pretty sure there is a liability with it.

    To be honest I do not care, nor am I bothered. I am only posting the facts to lay to rest unjust rumors that should not have been started in the first place. I would never have posted something like this in the first place without first finding out the facts.

    According to the virus information, it would not even attach itself to an exe, so that being said, when the person found the virus with thier virus scan, it would of said where it was on thier system, and that would not have been Irth Online.

    Thanks for your understanding though.

     

    Damian

    Magic Hat Software

  • ScarisScaris Member UncommonPosts: 5,332


    Originally posted by zaxtor99
    lmao, shat up.If a person strongly feels that playing a mmo he downloaded gave him a virus, then he certainly has the freedom to state this. Whether or not he is wrong is right about where/how he got the virus, there is NO laws against this. It's called freedom of speech. By your ridiculous threats against him and your logic, then I can't go out in the street where people are at and yell out that "Microsoft Windows sucks" or I could be prisoned for causing grave harm to the product which I verbally trash. Legal action my ass. Sue the living hell out of me for saying that you my friend are a complete dope. - Oh, and typing your garbage in ALL CAPS doesn't make you any more correct, threatening, or scary. It only makes you rude and obnoxious. Combine that with your logic and you are out of the park when it comes to sanity and intelligence.Also, just a fact in my experience. I also got this same virus and noticed it only two days after downloading and playing the beta of Irth online. Just a fact. Related to Irth online or not? I don't know.
    Just stating facts. If you'd like proof of this, I'd be happy to send you a copy of the virus in an email or something. Well, I'd have to reinstall Irth to see if I get it again I guess, since my Panda anti virus protection is what noticed the virus and squashed it as soon as I did a full scan of my computer only 2 days after installing Irth. The previous full computer scan done on my computer was 8 days prior to installing the Irth beta.- Zaxx

    Man people are quick to throw out that freedom of speech thing whenever it suits them. You have no idea what your talking about and EVERYONE is accountable for what they say. Wether what they say is acceptable or not is up to the court of law. However I suggest you quit thinking about your rights and start thinking about your civic responsiblities as well. Some people never grow up or get this, most however do.

    Saying "Microsoft Windows sucks" is opinion, saying "This software has a virus in it" is NOT opinion, he is stating fact and should use his head when doing so. Ya, you can walk around all day saying it and get away with it, getting away with it however does not make it right nor does it mean your exercising your right to free speech. Not to mention he is doing so on a privately owned forum, which you have no such right of free speech, its a priveledge here for as long as they wish to allow it.

    - Scaris

    "What happened to you, Star Wars Galaxies? You used to look like Leia. Not quite gold bikini Leia (more like bad-British-accent-and-cinnamon-bun-hair Leia), but still Leia nonetheless. Now you look like Chewbacca." - Computer Gaming World

  • ScarisScaris Member UncommonPosts: 5,332


    Originally posted by HolaMariah
    If you are a Beta tester of Irth Online, make sure you have your anti-virus software updated. There's a worm called Zotob.A that infects Windows and creates a backdoor for access to your computer. If you are experiencing abnormally slow processing on your computer, especially during long patching and updates, be sure to monitor for any newly installed programs that is not part of the game.

    I HIGHLY doubt the fact that you have Zotob came from Irth. I suggest you start using better email practices in the future since I can almost guarantee thats how you got infected. What file was infected in the Irth directory to make you beleive Irth is the cause of this?

    - Scaris

    "What happened to you, Star Wars Galaxies? You used to look like Leia. Not quite gold bikini Leia (more like bad-British-accent-and-cinnamon-bun-hair Leia), but still Leia nonetheless. Now you look like Chewbacca." - Computer Gaming World

  • staypuffkillstaypuffkill Member Posts: 3



    Originally posted by specusci

    This thread is based on fallacy. First of all, there have been absolutely zero reports from beta testers of any kind of virus on their computer related to Irth Online or the patcher. Second of all, the lead Developer in charge of issuing and uploading the game patches does not have such a virus on their computer, and therefore cannot possibly pass the virus into computers through the patcher. There is no, has never been, and will never be a link between the patcher and this virus.


    DO NOT, and I repeat, DO NOT EVER AGAIN GO AROUND TALKING ABOUT ANY MMORPG, NOT JUST IRTH ONLINE, IN THIS FASHION WITHOUT CONSIDERABLE EVIDENCE OF SUCH A VIRUS. LEGAL ACTION CAN AND MAY VERY WILL BE TAKEN ON INDIVIDUALS CAUGHT DOING THIS, INCLUDING THE INDIVIDUAL IN THIS THREAD. THIS IS NOT A JOKE, YOU CAN BECOME FINED OR EVEN SPEND LENGTHY TIME IN PRISON FOR MISCONDUCT OF THIS MATTER.



    DO NOT, and I repeat, DO NOT EVER AGAIN GO AROUND TALKING ABOUT ANY MMORPG, NOT JUST IRTH ONLINE, IN THIS FASHION. SPECUSCI CAN AND MAY VERY WELL TALK TO YOU IN ALL-CAPS. THIS IS NOT A JOKE, SPECUSCI WILL THROW AN ALPHA-NUMERIC TANTRUM AT YOU TO TEACH YOU A LESSON.  NO LAUGHING.  THAT IS NOT ALLOWED EITHER.  THIS IS AN OFFICIAL LAWYER-APPROVED MESSAGE. WHY ELSE DO YOU THINK IT IS IN ALL-CAPS?

  • KjarlKjarl Member Posts: 76

    I downloaded the game and couldnt move once I got in, the lag was horrid even for a beta. The game is supposed to come out in 2 weeks. I think I will Pass. But thats just me.

  • kishekishe Member UncommonPosts: 2,012


    Originally posted by Krom44
    Originally posted by Researcher
    Originally posted by Damian_MHS
    While I am no lawyer... I see my previous post was deleted so I will repost:
    You are not much of a developer either.It was deleted for that? Oh man... somebody seems overly sensitive.

    if devs would be openly attacked every time they post here, mmorpg.com would lose even the last bits of support they have and would go bankrubt, good business always requires some brown nosing.

Sign In or Register to comment.