My regular feed of the “RuneScape” search results on Twitter (very useful feature TweetDeck), provides an insight into the types of reasons that unsuspecting (read: guilible) users might encounter that lead them towards lack of account security/computer issues. ‘Edit your RuneScape stats through a glitch’ was the latest to make it’s way across the feed. Now I’m not stupid. I know such a thing doesn’t exist. If it did, there’d be a lot more than 400 ish people with 24 99s. It would be complete chaos So I downloaded the file. It’s always nice to see the attempts that wannabe-black hats are making to try to steal accounts. Information is power. Immediately, before I even had so much as a chance to set AVG on it, the ResidentShield portion of AVG jumped in and chucked up a warning. This is nice because it proves that the software is actually behaving itself and doing useful stuff. A nice secure test of my AV-solutions. So what was there: Worm/Agobot.HEY apparently Turns out it’s a particularly nasty little beast. http://en.wikipedia.org/wiki/Agobot has the details, but in short it’s A Botnet An auto-updating keylogger, packet sniffer, DDoS launcher and more It has a portscanner and a rootkit installer It harvests emails, product keys and passwords Can include a mail client to spam everyone you know Can include a HTTP client to initiate click fraud and DDosS. So don’t just randomly download RS tools because you want to be powerleveled through a glitch or get 9M. It doesn’t exist. These are nasty little counterfeiting attacks that will compromise your computer. Currently I’m looking to Mediafire to take this particular nasty down.
