Pages: [1] 2 :: one page |
|
Author |
Thread Statistics | Show CCP posts - 0 post(s) |
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 10:55:00 -
[1] - Quote
Eve Radio has posted Malware/Adware on their site. A warning was posted and then the thread was locked after only 8 posts.
No forum rule was cited for locking the thread.
The thread was locked by the same CCP rep who posted the News item in the Eve login panel which lead to the EveRadio site.
When you clicked on the "Flash" option to play Eve Radio, a plugin install popup for an FLVPlayerSetup.exe was needed.
The source for this program was a company called Foxtab, of foxtab.com
I still have the file on my computer and the download record, if there are any doubts.
The name of the browser hijack was Babylon.
The author of the site has since changed the link.
I intend to continue posting about this as long as the threads are locked without justification.
If there is indeed a forum rule violation, CCP Navigator, please state it explicitly before locking the thread and I will stop.
In the event that the threads continue to be locked without justification I will be sending a letter with all the details to Whitewolf's board of directors.
It is CCP's responsibility that links posted from the News section of the login page are safe.
Leave the thread unlocked and allow others to comment on what happened.
If you visited the EveRadio site and installed the FLVPlayerSetup.exe you have malware on your computer. Your password may be at risk.
I will follow up with details on how to clean the malware from your computer.
I am not accusing EveRadio of deliberately installing malware/adware on our machines, but it should at least be acknowledged that there was a problem so that all the people who clicked the News item at the login screen can BE AWARE and can take steps to clean the infection.
Locking threads on this only makes it look like you don't want anyone to know. That would be very, very irresponsible. |
Kha'Vorn
Aliastra Gallente Federation
0
|
Posted - 2011.12.18 11:15:00 -
[2] - Quote
Yawn.
|
DarkAegix
Acetech Systems
586
|
Posted - 2011.12.18 11:33:00 -
[3] - Quote
|
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 11:52:00 -
[4] - Quote
Well Kha'Vorn I agree, this is not entertaining for anyone.
Especially those of us who spent the morning cleaning malware from our computer.
I have work but intend to come back tonight or tomorrow morning and post how I cleaned it up for those of you who were infected yesterday.
The short version is that you need a program called 'Hijackthis' and you need to do some registry editing. It's not a big deal but it's not intuitive for people who are casual users.
Uninstalling the software can be done from the Add/Remove programs function but it will still leave files on your machine. Specific things need to be deleted.
Sorry I don't have time this morning to post detailed instructions but they're coming! |
Schnoo
The Schnoo
35
|
Posted - 2011.12.18 12:05:00 -
[5] - Quote
Are you sure it isn't just you not having flash and thus your browser suggesting you download FLVPlayer.exe (the flash player)? |
TR4D3R4LT
Pator Tech School Minmatar Republic
9
|
Posted - 2011.12.18 15:19:00 -
[6] - Quote
Let me help you help yourself.
http://wiki.eveonline.com/en/wiki/W/index.php
5. 23.
In addition I recommend you check a bit around the net of this so called babylon "hijack" of yours. Most likely cause? You installed bundle for flash from your browser recommended site that was not http://get.adobe.com/flashplayer/ After that you managed not to read what the installer asked from you and forgot to untick "add search toolbar." Then you come on eve-o-fora ranting how you were "hijacked" and had to do registry editing. |
Mirima Thurander
Sarajevo Syndicate True Reign
111
|
Posted - 2011.12.18 15:31:00 -
[7] - Quote
u mad bro?
I would be willing to fix all your problems.
All you have to do is click this link, and all your problems will go away. I love the the smell of victory in the morning. It smells like... Blood, vomit and burning flesh. I Like You. I'll Kill You Last. |
Morganta
Peripheral Madness The Midget Mafia
553
|
Posted - 2011.12.18 15:34:00 -
[8] - Quote
TR4D3R4LT wrote:Let me help you help yourself. http://wiki.eveonline.com/en/wiki/W/index.php5. 23. In addition I recommend you check a bit around the net of this so called babylon "hijack" of yours. Most likely cause? You installed bundle for flash from your browser recommended site that was not http://get.adobe.com/flashplayer/ After that you managed not to read what the installer asked from you and forgot to untick "add search toolbar." Then you come on eve-o-fora ranting how you were "hijacked" and had to do registry editing.
this is indeed the most likely scenario
and to the OP, for god's sake don't install DivX player either, they bundle it with a toolbar too
damned user install options....
The American public's reaction to the change was poor and the new cola was a major marketing failure. The subsequent reintroduction of Coke's original formula, re-branded as "Coca-Cola Classic", resulted in a significant gain in sales, leading to speculation that the introduction of the New Coke formula was just a marketing ploy |
DJ Bigcountry
Eve Radio Corporation
1
|
Posted - 2011.12.18 16:10:00 -
[9] - Quote
This is nothing but a situation where a google ad was up and it was for some 3rd party player... Eve Radio website has built in players.... you only need the plugins that it will autodownload when you join... Sorry to anyone who clicked an ad but theres no real control of that :( |
Morganta
Peripheral Madness The Midget Mafia
553
|
Posted - 2011.12.18 16:15:00 -
[10] - Quote
DJ Bigcountry wrote:This is nothing but a situation where a google ad was up and it was for some 3rd party player... Eve Radio website has built in players.... you only need the plugins that it will autodownload when you join... Sorry to anyone who clicked an ad but theres no real control of that :(
sure there is don't carry questionable ads of course it is much easier to just shirk responsibility for your part in this.
The American public's reaction to the change was poor and the new cola was a major marketing failure. The subsequent reintroduction of Coke's original formula, re-branded as "Coca-Cola Classic", resulted in a significant gain in sales, leading to speculation that the introduction of the New Coke formula was just a marketing ploy |
|
Ranger 1
Ranger Corp
538
|
Posted - 2011.12.18 16:23:00 -
[11] - Quote
Morganta wrote:DJ Bigcountry wrote:This is nothing but a situation where a google ad was up and it was for some 3rd party player... Eve Radio website has built in players.... you only need the plugins that it will autodownload when you join... Sorry to anyone who clicked an ad but theres no real control of that :( sure there is don't carry questionable ads of course it is much easier to just shirk responsibility for your part in this.
I'm really not sure they have much control over the ad's Google puts up there since they react differently to each user.
OP, if you'll remember a rep from EVE Radio immediately asked for details so that he could check this out and rectify any malware situation that might have happened.
This was immediately followed by a CCP rep who checked your story of being forced to install anything and found it bogus, closing your thread as a result.
I did find the Foxtab player offered under their Radio/Player section available for download if you manually download it. The big green download button is followed by a description of the player followed by this:
Quote:This product is totally free and offers the user additional bundle products that may include advertisement.
This is pretty standard on most "free" software, and has been since the last century.
Next time take some personal responsibility to actually pay attention to what you are installing before you go on some crusade against the man. Your histrionics are completely unnecessary. A simple email with your concern would have been the appropriate response.
Now if you deselected to have those other options installed and it did so anyway you have a gripe with the company that made it, and I'm sure if that is found to be the case EVE Radio will take steps to have it pulled down. Revenge should not stop at the ship!
It's not so much a mission statement,-áit's more like a family motto. |
Darek Castigatus
Immortalis Inc. Shadow Cartel
4
|
Posted - 2011.12.18 16:28:00 -
[12] - Quote
Ranger 1 wrote:Morganta wrote:DJ Bigcountry wrote:This is nothing but a situation where a google ad was up and it was for some 3rd party player... Eve Radio website has built in players.... you only need the plugins that it will autodownload when you join... Sorry to anyone who clicked an ad but theres no real control of that :( sure there is don't carry questionable ads of course it is much easier to just shirk responsibility for your part in this. I'm really not sure they have much control over the ad's Google puts up there since they react differently to each user.
Quoting for truth, of course it is much easier to just throw baseless accusations around since this is the internet we're dealing with here. |
Morganta
Peripheral Madness The Midget Mafia
553
|
Posted - 2011.12.18 16:34:00 -
[13] - Quote
Darek Castigatus wrote:Ranger 1 wrote:Morganta wrote:DJ Bigcountry wrote:This is nothing but a situation where a google ad was up and it was for some 3rd party player... Eve Radio website has built in players.... you only need the plugins that it will autodownload when you join... Sorry to anyone who clicked an ad but theres no real control of that :( sure there is don't carry questionable ads of course it is much easier to just shirk responsibility for your part in this. I'm really not sure they have much control over the ad's Google puts up there since they react differently to each user. Quoting for truth, of course it is much easier to just throw baseless accusations around since this is the internet we're dealing with here.
yeah, because the host has no control, google just waltzes in and plasters random websites with unwanted ads.
sorry, if you can't afford to run a site in a way that's safe for your users and must resort to inviting uncontrollable content to your pages to do it, then you are a scrub in every sense of the word.
Don't get me wrong, I approve of eve radio's service, even if I don't like the free reign CCP gives em, and I know it costs money to stream audio, but if you can't do it with a modicum of assurance for your clients you stop being a valuable service
know what? just ignore me, I just hate the ad sponsored nightmare the web has become in general, so my comments are fairly biased in that direction The American public's reaction to the change was poor and the new cola was a major marketing failure. The subsequent reintroduction of Coke's original formula, re-branded as "Coca-Cola Classic", resulted in a significant gain in sales, leading to speculation that the introduction of the New Coke formula was just a marketing ploy |
Ranger 1
Ranger Corp
538
|
Posted - 2011.12.18 16:38:00 -
[14] - Quote
Morganta wrote:Darek Castigatus wrote:Ranger 1 wrote:Morganta wrote:DJ Bigcountry wrote:This is nothing but a situation where a google ad was up and it was for some 3rd party player... Eve Radio website has built in players.... you only need the plugins that it will autodownload when you join... Sorry to anyone who clicked an ad but theres no real control of that :( sure there is don't carry questionable ads of course it is much easier to just shirk responsibility for your part in this. I'm really not sure they have much control over the ad's Google puts up there since they react differently to each user. Quoting for truth, of course it is much easier to just throw baseless accusations around since this is the internet we're dealing with here. yeah, because the host has no control, google just waltzes in and plasters random websites with unwanted ads. sorry, if you can't afford to run a site in a way that's safe for your users and must resort to inviting uncontrollable content to your pages to do it, then you are a scrub in every sense of the word. Don't get me wrong, I approve of eve radio's service, even if I don't like the free reign CCP gives em, and I know it costs money to stream audio, but if you can't do it with a modicum of assurance for your clients you stop being a valuable service know what? just ignore me, I just hate the ad sponsored nightmare the web has become in general, so my comments are fairly biased in that direction
Sorry, as I was typing up above I was checking something and added to my post. There is a link to voluntarily download that player with a disclaimer. Explained above. (I was a slow typer). Revenge should not stop at the ship!
It's not so much a mission statement,-áit's more like a family motto. |
QGazQ
5
|
Posted - 2011.12.18 16:44:00 -
[15] - Quote
Right first we need to establish what happened here. Was it that one of the required site plugins (flash or the MS WMP plugins) which somehow caused the problem, probably by a browser sending them to the wrong place. Or if it was indeed an advert.
Given how the OP described it I was assuming it was the first case which is why I asked in the previous thread for details of the OS and browser to try and reproduce the issue. These haven't been given yet, if they are I will try and check it out to confirm.
However its looking like it maybe due to a rogue ad. OP: was it an ad like the one in the bottom left of this image which you clicked? http://bigcountry.eve-radio.com/download%20ad.jpg
If so then that is indeed an ad and not something that is required for our site.
As has been discussed in this thread the ads are provided by google and therefore we expect them to be reasonably reputable, but if this is a dodgy one then it needs reporting or removing. I have tried refreshing the page many times myself and have not yet seen this ad, but again as mentioned they are targeted by google so I may never see it. If you can get the url it points to then we can add it to our block list as we do with ISK ads so it won't be shown again, but you can also click the triangle with the i in it on the top right of the ad which will take you to a google page where at the bottom you can report an issue with the ad.
Regards QGazQ |
Ranger 1
Ranger Corp
538
|
Posted - 2011.12.18 17:06:00 -
[16] - Quote
By the way, you can download this program from CNET.
Here is what they have to say about it in the header to their favorable review.
Quote: FLV Player includes optional bundled software that may trigger alerts from security software. FLV Player has been tested for malware by the CNET Download.com team and meets our security requirements.
The review.
Quote:Most people don't need anything more than a Web browser and a Macromedia plug-in to watch Flash videos. However, if you want a hair's breadth more control over your viewing, this open-source freeware program will do the trick. FLV Player's exceedingly simple controls allow you to navigate backward and forward through videos and play them in a loop. You can also adjust the volume, mute it, and adjust the size of the player. The Settings menu provides some basic control over program behavior, such as opening a new player window when double-clicking on an FLV file and remembering previous settings. And that's about it. Our only major complaint is that the display window doesn't automatically resize to the size of your movie frame. We hope this problem will be remedied in future versions. FLV Player isn't a must-have by any stretch, but it's a decent tool for penny-pinching Flash developers. Read more: FLV Player - Free software downloads and software reviews - CNET Download.com http://download.cnet.com/FLV-Player/3000-13632_4-10467081.html?tag=mncol;1#editorsreview#ixzz1guHxrsK7 Revenge should not stop at the ship!
It's not so much a mission statement,-áit's more like a family motto. |
MrBlades
Eve Radio Corporation
6
|
Posted - 2011.12.18 17:27:00 -
[17] - Quote
Found a google ad which the OP is probably referring to and checked it out on a fresh box. No problems as reported so probably still a troll (yeah, we get those!) but have blocked the offending domain regardless as the ad was ugly and offended my eyes.
Beyond that, take it up with google. I'm sure they will be sympathetic. Merry Christmas. |
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 18:15:00 -
[18] - Quote
No I'm not just out to get Eve Radio, fresh out of nowhere deciding all of a sudden that I'll start an elaborate rumour and troll the forums
QGazQ
No, it wasn't a google ad.
No, you couldn't uncheck an option to prevent having Babylon installed.
No it wasn't a banner ad.
"u mad bro?"
Yes I was mad. CCP Navigator posted a link in news that lead to a site unaffiliated with CCP containing malware. Then a thread warning of the malware was locked 8 posts in by the same individual who posted the news.
And QgazQ of EveRadio was trying to be helpful and get some questions answered so he could correct the problem. Kinda hard to help him with that when the thread is locked.
It seems the only person who wanted it locked was CCP Navigator.
Schnoo,
Quote:Are you sure it isn't just you not having flash and thus your browser suggesting you download FLVPlayer.exe (the flash player)?
I already had Adobe flash, but you are absolutely correct that the message came up as the browser saying FLVPlayerSetup.exe had to be installed to play Eve Radio.
MrBlades,
Says, (while calling me a troll - merry christmas to you too), that the offending software link was removed. Great.
If you think it was a google ad, why was the foxtab player being offered under the Radio/Player section? You never heard of it before... right? ;)
FFS. Take some responsibility for yourselves.
CCP, don't post links to unaffiliated websites on your login page, using your trademark, that therein contain malware.
As a bonus, you won't have to go locking threads afterward! |
Ranger 1
Ranger Corp
538
|
Posted - 2011.12.18 18:19:00 -
[19] - Quote
Cattegirn wrote:No I'm not just out to get Eve Radio, fresh out of nowhere deciding all of a sudden that I'll start an elaborate rumour and troll the forums QGazQ No, it wasn't a google ad. No, you couldn't uncheck an option to prevent having Babylon installed. No it wasn't a banner ad. "u mad bro?" Yes I was mad. CCP Navigator posted a link in news that lead to a site unaffiliated with CCP containing malware. Then a thread warning of the malware was locked 8 posts in by the same individual who posted the news. And QgazQ of EveRadio was trying to be helpful and get some questions answered so he could correct the problem. Kinda hard to help him with that when the thread is locked.It seems the only person who wanted it locked was CCP Navigator. Schnoo, Quote:Are you sure it isn't just you not having flash and thus your browser suggesting you download FLVPlayer.exe (the flash player)? I already had Adobe flash, but you are absolutely correct that the message came up as the browser saying FLVPlayer.exe had to be installed. MrBlades says, (while calling me a troll - merry christmas to you too), that the offending software link was removed. Great. If you think it was a google ad, why was the foxtab player being offered under the Radio/Player section? You never heard of it before... right? ;) FFS. Take some responsibility for yourselves.
Quote: By the way, you can download this program from CNET.
Here is what they have to say about it in the header to their favorable review. Quote:
FLV Player includes optional bundled software that may trigger alerts from security software. FLV Player has been tested for malware by the CNET Download.com team and meets our security requirements.
Perhaps you should let CNET know they don't know what they are talking about.
Revenge should not stop at the ship!
It's not so much a mission statement,-áit's more like a family motto. |
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 18:22:00 -
[20] - Quote
Ranger 1 wrote: Perhaps you should let CNET know they don't know what they are talking about.
The author of the file the site had me downloaded was foxtab.com
And I'm not the one running a website. You tell CNet, if you like. |
|
Ranger 1
Ranger Corp
539
|
Posted - 2011.12.18 18:24:00 -
[21] - Quote
Cattegirn wrote:Ranger 1 wrote: Perhaps you should let CNET know they don't know what they are talking about.
The author of the file the site had me downloaded was foxtab.com And I'm not the one running a website. You tell CNet, if you like.
Nor am I. I'm just one of the thousands of people that has not had a problem with the site or the player.
FLV player is what FoxTab installs... the FoxTab FLV player. Revenge should not stop at the ship!
It's not so much a mission statement,-áit's more like a family motto. |
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 18:36:00 -
[22] - Quote
How to remove:
First find and note the directories/locations of foxtab and babylon
Uninstall foxtab and babylon from your uninstall programs tool.
This will not completely remove the software.
Open the directories located above and make sure everything is deleted.
To remove it completely you need to download a program called "HijackThis" from Trend Micro.
Run it, and do a scan with a report. You'll get a list of registry entries that looks like this. All you gotta do from there is find any entry with the name "foxtab" or "babylon" and check the box next to them. Then at the bottom select "Fix checked" and Hijackthis will remove them.
You may have to manually remove the start menu items.
That did it for me. If you still have it try posting your logs on forums.techguy.org
I hope this helps.
|
QGazQ
5
|
Posted - 2011.12.18 18:40:00 -
[23] - Quote
Cattegirn wrote:QGazQ
No, it wasn't a google ad.
No, you couldn't uncheck an option to prevent having Babylon installed.
No it wasn't a banner ad.
You still haven't answered my main questions which OS, and which browser so I can confirm there isn't (or is) an issue.
RE the locking, that was CCPs choice, but you could still have replied to me directly if you wished, though I also don't have a problem with the discussion being in public.
Cattegirn wrote:Schnoo, Quote:Are you sure it isn't just you not having flash and thus your browser suggesting you download FLVPlayer.exe (the flash player)? I already had Adobe flash, but you are absolutely correct that the message came up as the browser saying FLVPlayerSetup.exe had to be installed to play Eve Radio.
Again the site doesn't require that in any way so I am most puzzled. When you says "came up", in which way. Are you talking popup, the little advice bar which most browsers have now, as just text on the site or what?
Cattegirn wrote: MrBlades,
Says, (while calling me a troll - merry christmas to you too), that the offending software link was removed. Great.
If you think it was a google ad, why was the foxtab player being offered under the Radio/Player section? You never heard of it before... right? ;)
FFS. Take some responsibility for yourselves.
What he has removed is the advert which was misleading. The Radio/Player section just displays the same module as on the home page, I can't remember why that page exists now I think I set it up to help diagnose a problem with a conflict of modules on the home page and its just kind of stayed. It does however have a google ad at the top of it (as do all the pages). So again are you sure it wasn't an advert you clicked?
Yes we do say we haven't heard of it before and the site doesn't require it.
Again any more light you can shed we can check out, but at the moment I'm assuming it was the banner ad.
Regards QGazQ |
Sakurako Kimino
Volatile Nature
8
|
Posted - 2011.12.18 18:42:00 -
[24] - Quote
Cattegirn wrote:
If there is indeed a forum rule violation, CCP Navigator, please state it explicitly before locking the thread and I will stop.
Reopening a locked thread by creating a new one is not allowed.
Recreating or reopening a thread that has been closed by a moderator is prohibited. Threads that have been closed by a moderator have been closed for the benefit of the community. Reopening a locked thread will result in its removal.
thats how this one could be closed you should petition the 1st post it if you think it should have remained open.
what do you think the board of directors from whitewolf can do?
eve is about sin |
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 18:47:00 -
[25] - Quote
QGazQ
Quote:You still haven't answered my main questions which OS, and which browser so I can confirm there isn't (or is) an issue.
Windows 7, 64, Firefox v 8.01
Quote:RE the locking, that was CCPs choice,
A pretty outrageous choice, given that it was a warning for their own customers who may have followed the link from their login page.
I was not at all taking issue with your posts in the thread. I was taking issue with CCP posting risky links on their login page and then squashing a warning about the risk.
"What he has removed is the advert which was misleading."
Fantastic. Good for you guys.
Quote:The Radio/Player section just displays the same module as on the home page, I can't remember why that page exists now I think I set it up to help diagnose a problem with a conflict of modules on the home page and its just kind of stayed.
Well then I'll give you the benefit of the doubt and believe you when you say that you had a Radio/Player section with the foxtab adware link for some problem you were trying to diagnose and can't remember and it just kind of stayed.
Quote:Yes we do say we haven't heard of it before and the site doesn't require it.
Well I'm glad I could bring it to your attention then.
Whatever you say is not an issue with me Gaz, the important thing is you got that crap off your site and acknowledged that it was there, albeit, without your awareness.
Thanks. |
Ranger 1
Ranger Corp
539
|
Posted - 2011.12.18 18:49:00 -
[26] - Quote
Quote:Well I'm glad I could bring it to your attention then.
Whatever you say is not an issue with me Gaz, the important thing is you got that crap off your site and acknowledged that it was there, albeit, without your awareness.
Thanks.
Apparently it's a highly selective piece of malware, as I have the same browser and OS as you and when to their site the first time you posted (the link was still up for the player).
Nada. Revenge should not stop at the ship!
It's not so much a mission statement,-áit's more like a family motto. |
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 18:51:00 -
[27] - Quote
Ranger 1 wrote:
His reluctance to provide details of OS or browser or much of anything else makes this pretty dubious.
Yeah that's it... If I give my OS/Browser info away, I'll sure to be revealed.
Good grief man.
He's acknowledged and fixed the issue. You continuing with the conspiracy theory is pretty ridiculous. |
Nullbeard Rager
Republic Military School Minmatar Republic
9
|
Posted - 2011.12.18 18:52:00 -
[28] - Quote
DJ Bigcountry wrote:This is nothing but a situation where a google ad was up and it was for some 3rd party player... Eve Radio website has built in players.... you only need the plugins that it will autodownload when you join... Sorry to anyone who clicked an ad but theres no real control of that :(
Of course there is...don't...carry...questionable...ads.
|
Cattegirn
Curved Swords
4
|
Posted - 2011.12.18 18:54:00 -
[29] - Quote
CCP is really the one who porked up here for linking a site with such ads on their login page. "EveRadio" sure sounds official.
CCP just needs to be more careful and take some responsibility instead of locking the damn thread. |
Ranger 1
Ranger Corp
539
|
Posted - 2011.12.18 18:55:00 -
[30] - Quote
Cattegirn wrote:Ranger 1 wrote:
His reluctance to provide details of OS or browser or much of anything else makes this pretty dubious.
Yeah that's it... If I give my OS/Browser info away, I'll sure to be revealed. Good grief man. He's acknowledged and fixed the issue. You continuing with the conspiracy theory is pretty ridiculous.
You (finally) posted your info at the same time I did, so I corrected that.
Still odd that nobody could reproduce the issue. Revenge should not stop at the ship!
It's not so much a mission statement,-áit's more like a family motto. |
|
|
|
|
Pages: [1] 2 :: one page |
First page | Previous page | Next page | Last page |