| Pages: 1 2 3 4 [5] 6 :: one page |
| Author |
Thread Statistics | Show CCP posts - 2 post(s) |

Dark Shikari
Caldari Imperium Technologies Firmus Ixion
|
Posted - 2006.10.08 13:11:00 -
[121]
Edited by: Dark Shikari on 08/10/2006 13:10:42
Originally by: Peter Stuyvesant
Originally by: Patch86 Note a new character is spamming the same link now: SiaKharn.
Have any of you looked up these spammers in-game? Denbrown is a 1 day old noobcorp member but SiaKharn sure isn't. Hope the guy didn't get his account hacked 
I'm guessing his account was sold or hacked.
-[23] Member-
Awesome new space games site, from the editor of E-ON! |
|

wystler
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.08 13:12:00 -
[122]
I think that SiaKharn was someone who tried to use the hack program and got his account details pilfered.
|
|

Jim McGregor
Caldari
|
Posted - 2006.10.08 13:35:00 -
[123]
Edited by: Jim McGregor on 08/10/2006 13:35:45
Introduce a post/minute limit please.
--- Eve Wiki | Eve Tribune | Eve Pirate |

Xenofur
Di-Tron Heavy Industries Knights Of the Southerncross
|
Posted - 2006.10.08 13:44:00 -
[124]
ok, this time a real alarm: whoever uses this, DO NOT enter your login data. first thing it does is send that via icq/aim to someone. ethereal ftw. :D
|

Barthez Thed
|
Posted - 2006.10.08 15:03:00 -
[125]
i see the warning post from isd has been de-stickied, that mean all is calm now?
|

Soulis
Slacker Industries Exuro Mortis
|
Posted - 2006.10.08 15:09:00 -
[126]
Originally by: Jim McGregor Edited by: Jim McGregor on 08/10/2006 13:35:45
Introduce a post/minute limit please.
what?!?! that would seriously effect Dark Shikari posting ratio
pfffftttttt - Immy |

Hellspawn01
Amarr The Phantom Conglomerate
|
Posted - 2006.10.08 15:24:00 -
[127]
Any new news about this? Is ccp going after this guy or something?
Ship lovers click here |

Dark Shikari
Caldari Imperium Technologies Firmus Ixion
|
Posted - 2006.10.08 15:25:00 -
[128]
Originally by: Soulis
Originally by: Jim McGregor
Introduce a post/minute limit please.
what?!?! that would seriously effect Dark Shikari posting ratio
Doubt that. I generally think enough before posting that 1-2 posts a minute max wouldn't limit me 
-[23] Member-
Awesome new space games site, from the editor of E-ON! |
|

Karass Sayfo
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.08 15:38:00 -
[129]
Don't worry folks, CRC has been taking care of it 
Try not to make too many DenBrown threads though.
- Karass Sayfo _______
|
|

Hellspawn01
Amarr The Phantom Conglomerate
|
Posted - 2006.10.08 15:46:00 -
[130]
Originally by: Karass Sayfo Don't worry folks, CRC has been taking care of it 
You got more details?
Ship lovers click here |

Hakera
Anari Higard
|
Posted - 2006.10.08 15:58:00 -
[131]
Originally by: Karass Sayfo Don't worry folks, CRC has been taking care of it 
Try not to make too many DenBrown threads though.
- Karass Sayfo
ya know a dev could of just ran a query by char ID on the backend and deleted his posts from the db in like 5 seconds? Would of saved you hours of work but hey ho.
GJ cleaning up anyway for us! o>
|

Hagen Stein
|
Posted - 2006.10.08 16:52:00 -
[132]
Edited by: Hagen Stein on 08/10/2006 17:04:53
Originally by: Xenofur As i said before: Could you please quote actual laws or give solid evidence?
In Germany: º118a, º119a and perhaps º225a StGB
Funny though that I just read another thread were you mentioned that you live in Germany. How comes you don't know the laws of our country? Or at least do a bit research of your own laws before posting statements like "I don't know any country where such laws exist"...
|

Sincere MarkXIII
|
Posted - 2006.10.09 14:08:00 -
[133]
I clicked on the link like the dope that I am.
I didn't download anything though, saw a firewall warning and immediately closed the browser and ran a virus check.
this morning turns out two of my three accounts have been hacked and cleaned out
|

Mortok Tristan
|
Posted - 2006.10.09 14:23:00 -
[134]
Be very carefull folks,
I clicked on it, saw my browser spin, immediatly rebooted the laptop. Upon starting up, zonealarm complained that a new process called csrss was trying to setup a new network port as a server. This program hides under the process name csrss, which is a standard windows process name, you should always see just 1 such process.
it also installs c:\windows\csrss.exe ( +/- size 34 kb ) And the registery is modified to automatically start this up at boot time.
needless to say it installs illegal software on your machine.
|

Sincere MarkXIII
|
Posted - 2006.10.09 14:27:00 -
[135]
how would you suggest i remove it without doing a fesh install of XP ?
|

Benco97
Gallente Fedo Appreciation Group
|
Posted - 2006.10.09 14:38:00 -
[136]
does nobody remember This?
it may look like a bad photoshop but it isn't, i've got shots of the first 10 pages of the forum all crammed with this. Beware the macro-spamming idiots.
Head of the Fedo Appreciation Group (FAG) and Registered Fedo breeder (Sig kindly supplied by Zurtur) |

Ghan Tylous
Caldari Caldari Provisions
|
Posted - 2006.10.09 14:41:00 -
[137]
Lysanter (or what his name is) is putting up links to that site again. He is spamming Ships and Moduls Section 
|

Mortok Tristan
|
Posted - 2006.10.09 14:41:00 -
[138]
Edited by: Mortok Tristan on 09/10/2006 14:42:05 If you see this illegal version of csrss.exe in c:\windows folder (34kb) I can only tell you what i did to resolve it. *** DSCLAIMER USE AT OWN RISK *** use regedit to remove refereces to c:\windows\csrss.exe you should find 1 or two... specifically in a folder called explorer. get rid of it.
Warning: do not remove references to c:\windows\system32\csrss that one is the genuine windows process ( also known as "Client Server Runtime Process").
Reboot... it wont load anymore the illegal csrss.exe program... you can now remove the file c:\windows\csrss.exe
This seems to have resolved it for me. I do not recommend this to ppl who are not familiar with the windows registry and how windows startup works.
|

Tharrn
Amarr 1st Praetorian Guard Vigilia Valeria
|
Posted - 2006.10.09 14:46:00 -
[139]
Not again!!
Now recruiting!
|

Jowen Datloran
Caldari Science and Trade Institute
|
Posted - 2006.10.09 14:46:00 -
[140]
Crap. Here we go again. ---------------- Mr. Science & Trade Institute |

Rodj Blake
Amarr PIE Inc.
|
Posted - 2006.10.09 14:46:00 -
[141]
And now this one too 
Dulce et decorum est, pro imperator mori |

Mad Vicky
Red Frog Investments Daikoku Trade Syndicate
|
Posted - 2006.10.09 15:03:00 -
[142]
The zip file was not the only payload the page was trying to deliver. There was also a kind of encrypted javascript trying to do document.write. I still have this script but for some reason it does not run correctly for me. It looks to me like the string he is trying to write is empty but maybe it actually does something on different computer configuration. I saw people complaining about keylogger being installed without even running the file included in the zip. So the zip may have just been a distraction and the page itself was using some kind of vulnerability to deliver actual payload.
http://www.eve-bookmarks.com (in-game only) |

Mortok Tristan
|
Posted - 2006.10.09 15:06:00 -
[143]
Originally by: Mad Vicky The zip file was not the only payload the page was trying to deliver. There was also a kind of encrypted javascript trying to do document.write. I still have this script but for some reason it does not run correctly for me. It looks to me like the string he is trying to write is empty but maybe it actually does something on different computer configuration. I saw people complaining about keylogger being installed without even running the file included in the zip. So the zip may have just been a distraction and the page itself was using some kind of vulnerability to deliver actual payload.
I fully agree with you, see my post above.
|

Death Kill
Caldari direkte
|
Posted - 2006.10.09 15:08:00 -
[144]
Originally by: Sincere MarkXIII how would you suggest i remove it without doing a fesh install of XP ?
Boot up windows in safe mode, then run cleaning software. Then reboot.
N=R* x fp x ne x fl x Fi x fc x L |

Leandro Salazar
Aeon Industries
|
Posted - 2006.10.09 15:09:00 -
[145]
Okay I stupidly clicked the link as I was browsing a thread and thought it was pointing to something contributing to the topic. The site went into loop and I closed it after about 5 seconds. My HD worked a bit, and that was that. But I don't find any csrss.exe or any other suspicious files. How do I find out if I have any problems? And did not having a C: drive possibly save me? --------- ZOMG my sig was concordokkened! Link removed due to bad language on remote site. -wystler
|

Sincere MarkXIII
|
Posted - 2006.10.09 15:14:00 -
[146]
Quote: If you see this illegal version of csrss.exe in c:\windows folder (34kb) I can only tell you what i did to resolve it. *** DSCLAIMER USE AT OWN RISK *** use regedit to remove refereces to c:\windows\csrss.exe you should find 1 or two... specifically in a folder called explorer. get rid of it.
Warning: do not remove references to c:\windows\system32\csrss that one is the genuine windows process ( also known as "Client Server Runtime Process").
Reboot... it wont load anymore the illegal csrss.exe program... you can now remove the file c:\windows\csrss.exe
This seems to have resolved it for me. I do not recommend this to ppl who are not familiar with the windows registry and how windows startup works.
You win the thread , many thanks, I managed to get ridd of it.
now only to wait till ccp manages to geive me back all my isk ^^
|

Benco97
Gallente Fedo Appreciation Group
|
Posted - 2006.10.09 15:14:00 -
[147]
Edited by: Benco97 on 09/10/2006 15:14:01
Originally by: Leandro Salazar And did not having a C: drive possibly save me?
depends how well it was written, you may have cut it off before it could finish but again, perform the aforementioned searches and cleanings just to be safe.
Head of the Fedo Appreciation Group (FAG) and Registered Fedo breeder (Sig kindly supplied by Zurtur) |

Barthez Thed
|
Posted - 2006.10.09 15:53:00 -
[148]
were those who had problems use IE to open the link, or did any using firefox have problems?
|

Mortok Tristan
|
Posted - 2006.10.09 16:20:00 -
[149]
Originally by: Sincere MarkXIII
Quote: If you see this illegal version of csrss.exe in c:\windows folder (34kb) I can only tell you what i did to resolve it. *** DSCLAIMER USE AT OWN RISK *** use regedit to remove refereces to c:\windows\csrss.exe you should find 1 or two... specifically in a folder called explorer. get rid of it.
Warning: do not remove references to c:\windows\system32\csrss that one is the genuine windows process ( also known as "Client Server Runtime Process").
Reboot... it wont load anymore the illegal csrss.exe program... you can now remove the file c:\windows\csrss.exe
This seems to have resolved it for me. I do not recommend this to ppl who are not familiar with the windows registry and how windows startup works.
You win the thread , many thanks, I managed to get ridd of it.
now only to wait till ccp manages to geive me back all my isk ^^
I also forgot to mention, the link installed autoexec.exe in c:\ i got rid of that too.
|

Exelsior
Endangered Species
|
Posted - 2006.10.09 16:27:00 -
[150]
Originally by: Barthez Thed were those who had problems use IE to open the link, or did any using firefox have problems?
Didn't download the file, just clicked on the link, and using firefox probably saved me. Got nothing ebil on my PC afaik...
|
| |
|
| Pages: 1 2 3 4 [5] 6 :: one page |
| First page | Previous page | Next page | Last page |