Sucks to wake up to read that more have been infected by Neopets.com.
Possibly some of the people having log-in problems on the other thread might even be related to this? I almost hope so, as that would likely mean TNT is trying to clear this up and might have to prevent log-ins for now?
purplecatlover2003: I don't *think* it is possible to get this while using FF (basically it comes from a hole in the Trident engine (which IE uses), not the Gecko engine (which Firefox and Orca use)). But the virus has 'evolved' quite fast over the past couple weeks and I now wonder if this is an "innocent" ad company or some really malicious person trying to really really screw Neopets and all the users s/he can? I wouldn't be surprised if hacking FF were next on this person's list.
Yes of course you may PM me about this or any such semi-related stuff.
In fact your details might help, in case FF is breachable too.
Eternal Serena and any others that get this while playing on Neopets might want to post here what they experienced and the browser used, etc.
I could post more screenies but they are all pretty much similar to what I described in the other thread about this. I got the source code of the page it happened on (this time World Challenge) like allnameswereout said to but he or someone else will have to look that over. Now to brave Neo ...
EDIT: Here is all the
information I could find on this so far. Like I said it is a tad different from the bl4ck.com trojan but the same .WMF virus is used. And now this Java crap. Geez.
spidey wrote:
I searched the Internet for any information concerning this file, an executable .jar file. According to Sophos (
http://www.sophos.com/virusinfo/analyse ... idrdw.html) this is dropped by a trojan along with another file...
exe4j is an EXE creator for Java; it seems as if any program, legitimate or not, can use the library file, exe4jlib.
It seems as if it can be part of a trojan drop which is used to run the actual virus program. The .jar file is only the actuator rather than the virus.