| Pages: 1 2 3 4 :: [one page] |
| Author |
Thread Statistics | Show CCP posts - 11 post(s) |
|

Suvetar
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.09 15:37:00 -
[1]
Hi Everyone,
As you probably noticed, we've had a surfeit of posts linking to a shady looking URL recently; as you will no doubt imagine this is indeed a piece of malware that is designed to steal your Username and Password and who knows what else.
So surf safe, don't click any links tempting you to hack EVE and rest assured that your friendly local mod team are doing everything we can to get the forums back on track!
Thanks!
|
|

Unfamed II
FinFleet Lotka Volterra
|
Posted - 2006.10.09 15:43:00 -
[2]
Edited by: Unfamed II on 09/10/2006 15:43:31 Keep up the good work, was about to report one linky, but it had already disappeared while I was writing about it to you. 
|

GC13
Caldari FATAL REVELATIONS Lotka Volterra
|
Posted - 2006.10.09 15:55:00 -
[3]
A trojan? O RLY?
*chalks one up for intuition*

---
New to Eve? Interested in manufacturing stuff, or doing research on blueprints? Check out my fully-updated Science and Industry guide. |

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.09 16:03:00 -
[4]
Edited by: Daald on 09/10/2006 16:02:53 Look for a file in you C: drive called autoexec.exe
That is what the website tries to install by creating an adodb.stream object. It tries to instantiate that object twice. I'm still looking at the second portion of the infecting code. ___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

Verite Rendition
Caldari AUS Corporation CORE.
|
Posted - 2006.10.09 16:08:00 -
[5]
Originally by: Daald Edited by: Daald on 09/10/2006 16:02:53 Look for a file in you C: drive called autoexec.exe
That is what the website tries to install by creating an adodb.stream object. It tries to instantiate that object twice. I'm still looking at the second portion of the infecting code.
I'm assuming he's trying to use a 0-day IE exploit? ---- AUS Corp Lead Megalomanic |

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.09 16:10:00 -
[6]
The code is obfuscated. I'm deobfuscating by hand and trying to insert meaning as I see it.
I'll let you know as I learn more. ___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

Quin Tal
Expeto Libertas
|
Posted - 2006.10.09 16:13:00 -
[7]
Thanks for the heads up Suvetar.
Do you know what one of the URL's is so we know what to look for?
|

Jenny Spitfire
Caldari
|
Posted - 2006.10.09 16:15:00 -
[8]
Originally by: Quin Tal Thanks for the heads up Suvetar.
Do you know what one of the URL's is so we know what to look for?
Ukrainian website, somename.something.somewhere.ua. --------- Cruelty is God's way of showing kindness and God is kind. Vagabond pilots want http://oldforums.eveonline.com/?a=topic&threadID=405915 |

keepiru
Supernova Security Systems
|
Posted - 2006.10.09 16:15:00 -
[9]
Btw, the spamming and cleanup broke the glue on the stickyes in ships & modules, could you slap some new blue-tack on them? :D ----------------
Please fix BC Sig/Agility! |

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.09 16:17:00 -
[10]
I would block anything going to advertology.net
That is where one of the attack vectors is coming from. ___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

Mortok Tristan
|
Posted - 2006.10.09 16:18:00 -
[11]
Originally by: Daald Edited by: Daald on 09/10/2006 16:02:53 Look for a file in you C: drive called autoexec.exe
That is what the website tries to install by creating an adodb.stream object. It tries to instantiate that object twice. I'm still looking at the second portion of the infecting code.
The second part is c:\windows\csrss.exe get rid of it, and references to it in the registry
|

Tharrn
Amarr 1st Praetorian Guard Vigilia Valeria
|
Posted - 2006.10.09 16:32:00 -
[12]
Wohoo... 'Stop Scams' is the newest spambot.
Now recruiting!
|

spurious signal
Caldari Brainiacs
|
Posted - 2006.10.09 16:36:00 -
[13]
Surely now it's time to start curbing the posting rights of trial accounts?
Heck, seems to me that 90% of the uses of trial accounts in general are bad. When 10% of the people logged on at any one time are trial accounts you have to question if they're being used as intended.
|

Tsanse Kinske
WeMeanYouKnowHarm
|
Posted - 2006.10.09 16:38:00 -
[14]
Originally by: Tharrn Wohoo... 'Stop Scams' is the newest spambot.
http://oldforums.eveonline.com/?a=topic&threadID=300394 for an example. 
* * * In the beginning the Universe was created. This has made a lot of people very angry and been widely regarded as a bad move.
-Douglas Adams, writing about EVE |

Jenny Spitfire
Caldari
|
Posted - 2006.10.09 16:39:00 -
[15]
Originally by: Tsanse Kinske
Originally by: Tharrn Wohoo... 'Stop Scams' is the newest spambot.
http://oldforums.eveonline.com/?a=topic&threadID=300394 for an example. 
Spammmer has a political agenda againsts trial accounts.  --------- Cruelty is God's way of showing kindness and God is kind. Vagabond pilots want http://oldforums.eveonline.com/?a=topic&threadID=405915 |

Tharrn
Amarr 1st Praetorian Guard Vigilia Valeria
|
Posted - 2006.10.09 16:39:00 -
[16]
It's not trial accounts - they are using hacked accounts. the last two bots posted using characters that are over a year old.
Now recruiting!
|
|

Karass Sayfo
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.09 16:40:00 -
[17]
Before you click on URLs, put your mouse over first to see the address. When in doubt, dont click!  _______
|
|

Caerleus
Board of Twenty
|
Posted - 2006.10.09 16:41:00 -
[18]
Changing trial account rights will have very little effect. This spammage is coming from accounts that are NOT trial accounts, but either hacked accouts or paid for accounts. This is how they are able to access certain parts of the forums that trial accounts already have no access to.
Post count limters, say 1 post per minute. That would slow them down considerably.
Eve is like a new girlfriend - you know its going down at some point, its just when and for how long. |

Jenny Spitfire
Caldari
|
Posted - 2006.10.09 16:42:00 -
[19]
Edited by: Jenny Spitfire on 09/10/2006 16:42:08
Originally by: Mortok Tristan
Originally by: Daald Edited by: Daald on 09/10/2006 16:02:53 Look for a file in you C: drive called autoexec.exe
That is what the website tries to install by creating an adodb.stream object. It tries to instantiate that object twice. I'm still looking at the second portion of the infecting code.
The second part is c:\windows\csrss.exe crss.exe get rid of it, and references to it in the registry
Fixed. --------- Cruelty is God's way of showing kindness and God is kind. Vagabond pilots want http://oldforums.eveonline.com/?a=topic&threadID=405915 |

GC13
Caldari FATAL REVELATIONS Lotka Volterra
|
Posted - 2006.10.09 16:44:00 -
[20]
You'd figure people wouldn't be stupid enough to click on a link in an obvious spam post. Oh well, I guess the dumbos a few standard deviations below the median for intelligence are making the lives of forumers difficult.
---
New to Eve? Interested in manufacturing stuff, or doing research on blueprints? Check out my fully-updated Science and Industry guide. |
|

Xorus
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.09 16:45:00 -
[21]
With the recent postings of links to keyloggers on the internet we have the following advice to give our forum users, firstly if you don't already have an Anti-Virue program we suggest you get one, there are a number of free products for home users including AVG Free Edition, Avast Home Edition and Avira AntiVir, all of these are free for home users, if you already have an Anti-Virus program make sure its up to date as having an out of date AV program is almost as bad as not having one at all.
Always be careful what you download on the EVE Forums as you never know what it might contain, things like EVEMon and Quickfit are safe to download as they have been tested and are from trusted sources, always be careful of any links posted on these forums as you never know what it may contain, ensure all your security software is up to date before clicking links.
 ---
Wanna Buy a Goat??- Tirg
Member of the 'Kaemonn is My Hero' club Member of the "Immy's Bald Head Appreciation Society" Xorus is currenly off duty counting trees in Siberia. -Ivan K How much is that goaty in the window, baaa baaaa - Cortes (Secretary, Bald Head Appreciation Society)
All your sig are belong to me - Tanis
|
|

Sean Dillon
Caldari Privateers
|
Posted - 2006.10.09 16:46:00 -
[22]
I think people who do this are pathetic.
But Imho every link thats posted somewhere should be approached with caution, I have played other mmorpg where the fenomenon of keyloggers is alot bigger then in eve online. Part of this is because the market system makes it very easy to check market transactions. Nonetheless this doesn't mean people won't give it a try. Aslong people are willing to pay $ for isk on ebay you will see this keep happening.
|

Fleeeeeeeeeee
|
Posted - 2006.10.09 16:49:00 -
[23]
keep jumping up and down on them i'm sure they'll sod offf eventually
|

Baleorg
Gallente Guys of Sarcasm
|
Posted - 2006.10.09 16:57:00 -
[24]
Edited by: Baleorg on 09/10/2006 16:58:09 *cough* clicking links that promise to "gain unfair advantage" ye... btw.. why are *YOU* still using IE ?! :-P you like risks?
---
BTW: A GOOD Cache-Cleaner |

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.09 17:01:00 -
[25]
Originally by: Jenny Spitfire Edited by: Jenny Spitfire on 09/10/2006 16:42:08
Originally by: Mortok Tristan
Originally by: Daald Edited by: Daald on 09/10/2006 16:02:53 Look for a file in you C: drive called autoexec.exe
That is what the website tries to install by creating an adodb.stream object. It tries to instantiate that object twice. I'm still looking at the second portion of the infecting code.
The second part is c:\windows\csrss.exe crss.exe get rid of it, and references to it in the registry
Fixed.
I didn't see that. It seems that the second portion sets up autoexec.exe to gain elevated privileges. I guess there was another attack vector that I didn't follow?
The second portion of that code seems to do this: http://www.snort.org/pub-bin/sigs.cgi?sid=7988
___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

Eve Hel
|
Posted - 2006.10.09 17:20:00 -
[26]
they should have a flame treatment in their nuts area.
seriously thise ppl have no honer... most be sad to be them. |

ElCoCo
Gallente KIA Corp
|
Posted - 2006.10.09 17:22:00 -
[27]
Someone suggested it already... can you put the url on the profanity filter list?
|

Emily Spankratchet
Minmatar Pragmatics
|
Posted - 2006.10.09 17:23:00 -
[28]
Ho hum. At least the bot that starts new threads doesn't completely destroy the forum by randomly necroing things.
Good luck ISD, you're doing a great job.
|

solidshot
Sebiestor tribe
|
Posted - 2006.10.09 17:26:00 -
[29]
new spammer named Traderia
|

ThunderGodThor
KIA Corp
|
Posted - 2006.10.09 17:29:00 -
[30]
So are u guys able to hand out the ban stick fast enough to stop this posting **** (insert varios 4 letter words? I mean few mins ago the corp and alliances was completely spammed.
|

Mortok Tristan
|
Posted - 2006.10.09 17:30:00 -
[31]
The entire forum is under attack at the moment..and probably has been for the last few hours.
|

Caerleus
Board of Twenty
|
Posted - 2006.10.09 17:35:00 -
[32]
This whole episode is sickening.
As a presumption, I'm guessing that this is an indivdual or group that has had their income slashed by recent bannings and is looking either for a new avenue to generate incomes or as a retaliation attack against CCP and its user base.
Very sad and worrying indeed.
Eve is like a new girlfriend - you know its going down at some point, its just when and for how long. |
|

Suvetar
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.09 17:39:00 -
[33]
Thanks for your support folks, it's appreciated!
|
|

Mortok Tristan
|
Posted - 2006.10.09 17:40:00 -
[34]
This is indeed sickening. I believe this is the first time in 2y, it has been this bad.
|

Napolie
Gallente Beagle Corp
|
Posted - 2006.10.09 17:41:00 -
[35]
Just wanted to pop into this thread showing support if it helps 
Get those scums!
Seagull instead of parrot  |

spurious signal
Caldari Brainiacs
|
Posted - 2006.10.09 17:52:00 -
[36]
Originally by: Tharrn It's not trial accounts - they are using hacked accounts. the last two bots posted using characters that are over a year old.
Really? Didn't know that, sorry.
Well, in that case, well... damn. 
|

Zarks
Amarr Electronics
|
Posted - 2006.10.09 18:06:00 -
[37]
My friends account have been hacked and the "create new petition" on the left on this page doesnt work now sadly. And they cant log in to eve or to the forums anymore to do a petition. How are they supposed to handle this?
__________________________________________________ |

Antaris Xenal
Gallente adeptus gattacus Lotka Volterra
|
Posted - 2006.10.09 18:10:00 -
[38]
Okay dont flame but when I first saw it it hadn't been spammed everywhere and someone replied in a post with that link, I clicked it and it just said click here when the window popped up so i did and thought it was another eve online flash or news item u know? It pretty much crashed my IE windows i had open and such, What should I do now? Did it install something on my computer? It was on a computer I don't play eve online on anyways.
|

Barrick Stormsworn
Minmatar CAD Inc.
|
Posted - 2006.10.09 18:13:00 -
[39]
Adblock/Noscript in Firefox FTW :-P
Though I didn't click on the link, of course. Silly spammers... but the people who fall for it are even more silly.
Keep it up, CCP :-) I appreciate your hard work in getting these threads/people taken care of so quickly.
|

Lisa Payne
|
Posted - 2006.10.09 18:23:00 -
[40]
Originally by: Antaris Xenal Okay dont flame but when I first saw it it hadn't been spammed everywhere and someone replied in a post with that link, I clicked it and it just said click here when the window popped up so i did and thought it was another eve online flash or news item u know? It pretty much crashed my IE windows i had open and such, What should I do now? Did it install something on my computer? It was on a computer I don't play eve online on anyways.
yes it did, c:\autoexec.exe and c:\windows\crss.exe
|

keepiru
Supernova Security Systems
|
Posted - 2006.10.09 18:23:00 -
[41]
Quick, everyone gather spare blutack for the broken stickyes! :o ----------------
Please fix BC Sig/Agility! |

Antaris Xenal
Gallente adeptus gattacus Lotka Volterra
|
Posted - 2006.10.09 18:25:00 -
[42]
Originally by: Lisa Payne
Originally by: Antaris Xenal Okay dont flame but when I first saw it it hadn't been spammed everywhere and someone replied in a post with that link, I clicked it and it just said click here when the window popped up so i did and thought it was another eve online flash or news item u know? It pretty much crashed my IE windows i had open and such, What should I do now? Did it install something on my computer? It was on a computer I don't play eve online on anyways.
yes it did, c:\autoexec.exe and c:\windows\crss.exe
Do i get a wiping program and wipe those files off the computer then?
|

R0ME0
|
Posted - 2006.10.09 18:25:00 -
[43]
would be nice if ccp got rid of the curret posts which are still there!!! as this is creating more risk as time goes on for people, who are not that computer literate!!!!
|
|

Eldo Davip
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.09 18:26:00 -
[44]
Thanks for the emails, we're working like madmen. Please spread the word through corp chat/ts/vent etc to not click the links.
___
Email Us (Report a bad post) | Forum Rules - Read 'em! | Website |
|

R0ME0
|
Posted - 2006.10.09 18:29:00 -
[45]
Originally by: Antaris Xenal
Originally by: Lisa Payne
Originally by: Antaris Xenal Okay dont flame but when I first saw it it hadn't been spammed everywhere and someone replied in a post with that link, I clicked it and it just said click here when the window popped up so i did and thought it was another eve online flash or news item u know? It pretty much crashed my IE windows i had open and such, What should I do now? Did it install something on my computer? It was on a computer I don't play eve online on anyways.
yes it did, c:\autoexec.exe and c:\windows\crss.exe
try spybot and adaware and get the updated and start scanning your pc.. this would also be a good suggestion on the opening post. here.
Do i get a wiping program and wipe those files off the computer then?
|

Darius Shakor
Minmatar Freelance Unincorporated Ushra'Khan
|
Posted - 2006.10.09 18:29:00 -
[46]
CRC rules. Nothing more to be said there. ------
Shakor Clan Information Portal http://oldforums.eveonline.com/?a=topic&threadID=3 |

Lisa Payne
|
Posted - 2006.10.09 18:29:00 -
[47]
Originally by: Antaris Xenal
Originally by: Lisa Payne
Originally by: Antaris Xenal Okay dont flame but when I first saw it it hadn't been spammed everywhere and someone replied in a post with that link, I clicked it and it just said click here when the window popped up so i did and thought it was another eve online flash or news item u know? It pretty much crashed my IE windows i had open and such, What should I do now? Did it install something on my computer? It was on a computer I don't play eve online on anyways.
yes it did, c:\autoexec.exe and c:\windows\crss.exe
Do i get a wiping program and wipe those files off the computer then?
check the response of this guy:
http://oldforums.eveonline.com/?a=topic&threadID=406282&page=5#138
|

keepiru
Supernova Security Systems
|
Posted - 2006.10.09 18:33:00 -
[48]
Originally by: Darius Shakor CRC rules. Nothing more to be said there.
----------------
Please fix BC Sig/Agility! |
|

Xorus
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.09 18:36:00 -
[49]
Originally by: Darius Shakor CRC rules. Nothing more to be said there.
Can i have your babies?
But in all seriousness thank you :) ---
Wanna Buy a Goat??- Tirg
Member of the 'Kaemonn is My Hero' club Member of the "Immy's Bald Head Appreciation Society" Xorus is currenly off duty counting trees in Siberia. -Ivan K How much is that goaty in the window, baaa baaaa - Cortes (Secretary, Bald Head Appreciation Society)
All your sig are belong to me - Tanis
|
|

jbob2000
Gallente The Taining corp Knights Of the Southerncross
|
Posted - 2006.10.09 18:41:00 -
[50]
Edited by: jbob2000 on 09/10/2006 18:41:28 So if i dont have those 2 files anywhere on my HD, im ok? Cause all i did was click the link, webpage took a while to load and i thought it was going to be **** or something, so i closed it. Using firefox btw.
|

Lisa Payne
|
Posted - 2006.10.09 18:43:00 -
[51]
your safe. firefox rules :)
|

Hakera
Anari Higard
|
Posted - 2006.10.09 18:46:00 -
[52]
Edited by: Hakera on 09/10/2006 18:46:51
Originally by: Lisa Payne your safe. firefox rules :)
only if your running noscript plugin.
|

Hakera
Anari Higard
|
Posted - 2006.10.09 18:46:00 -
[53]
i hope you have a dev on the case with backend access, it is far easier to ban by ip range then do a sql query on the backend to remove all posts at once.
You can then run a sql query in the content box looking for the url to find any posted with other characters.
that method is at least far more quicker than using frontend forum mod functions.
You can also implement a flood control specifically designed to stop bots which should only affect dark shikiri aside from the bots in his normal posting but the effect is minimal.
|

Jim McGregor
Caldari
|
Posted - 2006.10.09 19:05:00 -
[54]
Originally by: Xorus
Originally by: Darius Shakor CRC rules. Nothing more to be said there.
Can i have your babies?
But in all seriousness thank you :)
/humps leg
--- Eve Wiki | Eve Tribune | Eve Pirate |

DubanFP
Caldari
|
Posted - 2006.10.09 19:39:00 -
[55]
I like the other guy opened a link in a response before it was spammed out. I have 2 csrss files on task manager, one csrss is on c:\Windows, however it is 44kb not 32, and there is no autoexec file to be found. Virus checks "with 2 different anti-virus programs" have been run and nothing has been found. I've been unable to post because i don't want to type in my password on the affected computer. I'm on another computer right now, password has been changed on this comp to something with ~10 alphanumeric characters. But right now i'm still a bit worried about other personal inforamation a bit more importain then just this game. any other info on this?
|

Hakera
Anari Higard
|
Posted - 2006.10.09 20:23:00 -
[56]
Originally by: DubanFP I like the other guy opened a link in a response before it was spammed out. I have 2 csrss files on task manager, one csrss is on c:\Windows, however it is 44kb not 32,and there is no autoexec file to be found.
1. Disable system restore
( Select Start followed by Control Panel, and double-click the System icon. Then:
1.Click the System Restore tab on the System dialog box 2.To enable, clear the Turn off System Restore check box 3.To disable, select the Turn off System Restore check box 4.Click OK when done
2. Delete the file c:/windows/csrss.exe
(make sure it is in the c://windows/ folder and not c://windows/system32/ folder (the latter is a valid file)
3. backup your registry (just in case) - follow this guide
4. click start -> run -> type regedit.exe
4a. Click edit and find search for windows/csrss.exe
4b. You should get a result - delete it
5. reboot your machine, confirm everything works ok, then delete the backup of your registry.
think thats the right way to do it anyway. But im not 100%
|

Annya Avishnaya
Quantum Industries Prime Orbital Systems
|
Posted - 2006.10.09 20:26:00 -
[57]
<3 the mods 
It sucks you've gotta put up with this kinda junk 
|

Hakera
Anari Higard
|
Posted - 2006.10.09 20:41:00 -
[58]
Originally by: Hakera i hope you have a dev on the case with backend access, it is far easier to ban by ip range then do a sql query on the backend to remove all posts at once.
You can then run a sql query in the content box looking for the url to find any posted with other characters.
that method is at least far more quicker than using frontend forum mod functions.
You can also implement a flood control specifically designed to stop bots which should only affect dark shikiri aside from the bots in his normal posting but the effect is minimal.
to add to this - might i also suggest an autolock feature, where any post is locked if there has been no reply within last 30 days?
|
|

Eldo Davip
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.09 20:45:00 -
[59]
Hakera,
Thanks for the suggestions. We have been discussing several of these internally. The devs should come up with a solution soon. ___
Email Us (Report a bad post) | Forum Rules - Read 'em! | Website |
|

Complacency's Bane
Caldari
|
Posted - 2006.10.09 20:45:00 -
[60]
Edited by: Complacency''s Bane on 09/10/2006 20:44:58 csrss.exe
There are a number of spyware/trojan packages which drop csrss.exe into Windows - you may have one of those, and not this particular varient.
|

DubanFP
Caldari
|
Posted - 2006.10.09 20:59:00 -
[61]
Originally by: Complacency's Bane Edited by: Complacency''s Bane on 09/10/2006 20:44:58 csrss.exe
There are a number of spyware/trojan packages which drop csrss.exe into Windows - you may have one of those, and not this particular varient.
Yeah taht's what i was afraid of. Especially considering it refused to let me delete the file, and it seemed off. Oh well whatever virus it was, i removed from registry and got around the inability to delete it by re-naming the file. Only one Csrss file operating now, though i can only imagine what it's done up to thsi point :-(.
|

Stephar
The High Priest
|
Posted - 2006.10.09 21:06:00 -
[62]
I actually had the csrss.exe thing last night at work. I downloaded Security Task Manager, which seemed to fix it.
|

Hakera
Anari Higard
|
Posted - 2006.10.09 21:06:00 -
[63]
Originally by: DubanFP
Yeah taht's what i was afraid of. Especially considering it refused to let me delete the file, and it seemed off.
sorry, i should of added, you may of needed to open taskmanager (ctrl-alt-delete) and end its process first.
looking into stuff further, may well be wise just running one of the trojan removal tools for existing trojans that drop csrss.exe
try this one from sophos, the trojan looks fairly similar.
|

Firebyrd
Gallente Crooked River Productions
|
Posted - 2006.10.09 21:15:00 -
[64]
Edited by: Firebyrd on 09/10/2006 21:20:35 Edited by: Firebyrd on 09/10/2006 21:16:47 I wonder if this was causeing my startup issues that have been going on for past week or so, over the weekend i reinstalled my Win XP software, and have no more problems, the problem i was having it took about 5 trys for windows to startup, kept restarting, and sometimes the windows option of normal or safemode would come up... but no such problems last 3-4 days
the Csrss.exe in my Task manager is 4,664K size, and coure Task manager wont let me stop its running either...lol
And under the User name column says System... so its probably the correct one running..
But i also think i seen an autoexec.exe file in task manager when i have eve running, but i dont now, since i reinstalled win XP ----------------------------------------------- In the End , there can be only 1
Learn from yesterday, that u may be stronger tomorrow
|

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.09 21:24:00 -
[65]
It is crap like this that makes me appreciate even further the operating system choice I made awhile back.
Much sympathy to the mods on this one though. ----- ------------
Updated Linux Desktop+EVE+EVE-TV |

Hakera
Anari Higard
|
Posted - 2006.10.09 21:31:00 -
[66]
Originally by: Stephar I actually had the csrss.exe thing last night at work. I downloaded Security Task Manager, which seemed to fix it.
thanks, i updated my post at the top of the page as thats the easiest way to make sure people end the right process and can then delete the file.
Nifty little tool that though it says my logitec controlers are a 91% probable threat heh.
|

DeODokktor
Caldari Dark Templars The Fonz Presidium
|
Posted - 2006.10.09 23:08:00 -
[67]
CSRSS.EXE is a required windows process for most users. Deleting it can be a bad thing to do (they might not be complaining cause their systems arent restarting).
If it's %winpath%\ then delete it if it's %winpath%\system32\ then I'd suggest not touching it.
|
|

Kaemonn
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.10 00:59:00 -
[68]
Sometimes in order to delete a file or piece of malware off your computer you have to be in safe mode. To do this press F8 as your computer is booting. This will start windows with just the absolute minimum to stay running. From there you can delete what you will.
forum rules | [email protected] You mean to tell me, theres a game that goes with the forums?
|
|
|

Suvetar
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.10 06:06:00 -
[69]
Yes, just to clarify folks:
CSRSS.Exe is an important file for Windows and if you delete the wrong one, it may break your installation but good 
If you search your drive for CSRSS, you should only find it in the following locations:
Windows\$NtServicePackUninstall$ Windows\Prefetch (it will have a name called CSRSS(numbers).PF Windows\System32 Windows\ServicePackFiles\i386
If you right click each of the EXE's (not the PF one) and go to the Version tab, the number should be at between 5.1.2600 .0 and 5.1.2600.2180.
Also check the file details; it should be something like this, depending on your language and service pack:
Company: Microsoft Corporation File Version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Internal Name: CSRSS.Exe Language: English (United States) Original File Name: CSRSS.Exe Product Name: Microsoft« Windows« Operating System Product Version: 5.1.2600.2180
Hope this helps 
And a big thanks to the other people who've taken their time to help solve this problem for anyone unlucky enough to have clicked this link.
|
|

Kuolematon
Space Perverts and Forum Warriors United
|
Posted - 2006.10.10 06:37:00 -
[70]
Originally by: Baleorg why are *YOU* still using IE ?! :-P you like risks?
why are *YOU* still telling me what to use !? :-D you like tardfoxes?
Unnerf Amarr!Ö "I read somewhere that Kali will be featuring turn-based combat to increase immersion." ¬ Waagaa Ktlehr
|

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.10 08:02:00 -
[71]
Originally by: Kuolematon
Originally by: Baleorg why are *YOU* still using IE ?! :-P you like risks?
why are *YOU* still telling me what to use !? :-D you like tardfoxes?
Not helpful Kuo, and once again living up to your sig, I see.
The question is valid when it comes to this sort of crap. IE is notoriously full of holes, to this day, including a few that are current and wide open. No browser is 100% safe under XP, but the poster is correct in pointing out that IE is the worst of the lot.
----- ------------
Updated Linux Desktop+EVE+EVE-TV |

cRaNbErRy MuFfInMaN
mUfFiN fAcToRy Pirate Coalition
|
Posted - 2006.10.10 09:23:00 -
[72]
i have firefox and had clicked on the link thinking it was a joke and it popped up a download which i rejected do i have to worry about this?
im so paranoid i think ill wipe this hardrive clean this weekend =/ long and hard process
Check out http://dl1.eve-files.com/media/0608/new.jpg |
|

Xorus
Forum Moderator Interstellar Services Department

|
Posted - 2006.10.10 10:42:00 -
[73]
Originally by: cRaNbErRy MuFfInMaN i have firefox and had clicked on the link thinking it was a joke and it popped up a download which i rejected do i have to worry about this?
im so paranoid i think ill wipe this hardrive clean this weekend =/ long and hard process
As for what i've read its using an exploit in IE which is obviously not present in FF, i visit a few sites that like to throw trojans and virii at me but i either get prompts to download a strangely named .exe file or my AV (avast) kicks up a message saying the connection contains [Virus name here] with an abart connection message but yes as i mentioned if you don't have any AV i suggest you get some :)Process Explorer also a freeware tool but provides better information than task manager does and also allows you to kill off a few more processes than task manager :) ---
Wanna Buy a Goat??- Tirg
Member of the 'Kaemonn is My Hero' club Member of the "Immy's Bald Head Appreciation Society" Xorus is currenly off duty counting trees in Siberia. -Ivan K How much is that goaty in the window, baaa baaaa - Cortes (Secretary, Bald Head Appreciation Society)
All your sig are belong to me - Tanis
|
|

Jali Prince
Minmatar
|
Posted - 2006.10.10 11:42:00 -
[74]
oh no, im at work reading this cannot check my puter!
 Oh well, the work ones ok....
Life is chocolate |

Trojanman190
Caldari Entropy Tech.
|
Posted - 2006.10.10 14:14:00 -
[75]
Originally by: Hakera
Originally by: Hakera i hope you have a dev on the case with backend access, it is far easier to ban by ip range then do a sql query on the backend to remove all posts at once.
You can then run a sql query in the content box looking for the url to find any posted with other characters.
that method is at least far more quicker than using frontend forum mod functions.
You can also implement a flood control specifically designed to stop bots which should only affect dark shikiri aside from the bots in his normal posting but the effect is minimal.
to add to this - might i also suggest an autolock feature, where any post is locked if there has been no reply within last 30 days?
So simple.... so sweet... this is a great thought.
|

DukDodgerz
Amarr Imperial Academy
|
Posted - 2006.10.10 17:42:00 -
[76]
anyone notice that the url geographical location is/was also a geopraphical location of persons that suddenly came up 'missing' in the game?
could this be a retaliation towards CCP for 'handling' 'something' that we can't discuss on the forums?
Just a thought.
Pattern noticed, comment made, tinfoil hats are on sale at a local Walmart in case you need one.  
|

Kuolematon
Space Perverts and Forum Warriors United
|
Posted - 2006.10.10 17:47:00 -
[77]
Originally by: Sevarus James Not helpful Kuo, and once again living up to your sig, I see.
Ah your right! I see the light now! I will instanly go to firefox page and install it! Thank you sir for showing wrongs on my way of life! 
I don't understand why you people dis IE? It shows pages right (Well IE7 has some flaws but I'm sure that admins will correct their pages to be shown right on my browser!) and beside, it's intergrated to my OS so it works flaweless with it.
Unnerf Amarr!Ö "I read somewhere that Kali will be featuring turn-based combat to increase immersion." ¬ Waagaa Ktlehr
|

Jim McGregor
Caldari
|
Posted - 2006.10.10 19:02:00 -
[78]
Originally by: Kuolematon
I don't understand why you people dis IE? It shows pages right (Well IE7 has some flaws but I'm sure that admins will correct their pages to be shown right on my browser!) and beside, it's intergrated to my OS so it works flaweless with it.
Its the integration that is the problem. A web browser doesnt need to be integrated into a operating system. All you get is security problems. You are exposing the operating system functions right to the internet via the browser, instead of having a extra layer of security by using a separate browser.
Microsoft did a good marketing job when they told people that integrating the web browser is something good, thats for sure. 
--- Eve Wiki | Eve Tribune | Eve Pirate |

DukDodgerz
Amarr Imperial Academy
|
Posted - 2006.10.10 19:27:00 -
[79]
Originally by: Jim McGregor
Originally by: Kuolematon
I don't understand why you people dis IE? It shows pages right (Well IE7 has some flaws but I'm sure that admins will correct their pages to be shown right on my browser!) and beside, it's intergrated to my OS so it works flaweless with it.
Its the integration that is the problem. A web browser doesnt need to be integrated into a operating system. All you get is security problems. You are exposing the operating system functions right to the internet via the browser, instead of having a extra layer of security by using a separate browser.
Microsoft did a good marketing job when they told people that integrating the web browser is something good, thats for sure. 
sooooo true. good write up!
IE has that big gaping hole that allows a webpage to install things using system level authority, something FireFox cannot do, and the user is not even notified if the installer is setup to run 'silent'.
This IE flaw is exploited by big companies such as Adobe and Yahoo to install 'things' when the admin has not provided the ability to the user (the flaw bypasses the security settings). So why wouldn't a 'bad guy' do the same????????
If some people want to remain ignorent and be a life long victim then let them, it just means they have to hire a pro at high cost to 'clean up' their mess....assuming they still have any money in the bank after the badguy has stolen their identity.
|

Adoro
Reunited
|
Posted - 2006.10.10 19:28:00 -
[80]
So I got that script block thing for firefox (cant be to sure).
Get the following domain when on eve-online.com:
teljari.is
Whats with that? --------
Bailian Moxtain:
Quote:
Who needs pride when there's isk to be made
|

Hakera
Anari Higard
|
Posted - 2006.10.10 19:47:00 -
[81]
Originally by: Adoro So I got that script block thing for firefox (cant be to sure).
Get the following domain when on eve-online.com:
teljari.is
Whats with that?
a hit counter - its fine to allow.
|

Maverick McDougel
Shiva Morsus Mihi
|
Posted - 2006.10.10 21:36:00 -
[82]
Originally by: Xorus
Originally by: cRaNbErRy MuFfInMaN i have firefox and had clicked on the link thinking it was a joke and it popped up a download which i rejected do i have to worry about this?
im so paranoid i think ill wipe this hardrive clean this weekend =/ long and hard process
As for what i've read its using an exploit in IE which is obviously not present in FF, i visit a few sites that like to throw trojans and virii at me but i either get prompts to download a strangely named .exe file or my AV (avast) kicks up a message saying the connection contains [Virus name here] with an abart connection message but yes as i mentioned if you don't have any AV i suggest you get some :)Process Explorer also a freeware tool but provides better information than task manager does and also allows you to kill off a few more processes than task manager :)
what types of sites are you going to..... P***.... W***Z? 
got any good ones you want to share?  support BattleClinic buy gtc's from BattleClinic |

DukDodgerz
Amarr Imperial Academy
|
Posted - 2006.10.10 21:42:00 -
[83]
Originally by: Maverick McDougel
Originally by: Xorus
Originally by: cRaNbErRy MuFfInMaN i have firefox and had clicked on the link thinking it was a joke and it popped up a download which i rejected do i have to worry about this?
im so paranoid i think ill wipe this hardrive clean this weekend =/ long and hard process
As for what i've read its using an exploit in IE which is obviously not present in FF, i visit a few sites that like to throw trojans and virii at me but i either get prompts to download a strangely named .exe file or my AV (avast) kicks up a message saying the connection contains [Virus name here] with an abart connection message but yes as i mentioned if you don't have any AV i suggest you get some :)Process Explorer also a freeware tool but provides better information than task manager does and also allows you to kill off a few more processes than task manager :)
what types of sites are you going to..... P***.... W***Z? 
got any good ones you want to share? 
a person can goto msn.com and if an advertising server, hosted by a third party, is comprimised, the advertising banners can be activeX and install applications without you knowing it is happening.
MSN wouldn't be at fault, but it would seem that it came from thier site.
|

Maverick McDougel
Shiva Morsus Mihi
|
Posted - 2006.10.10 21:44:00 -
[84]
Originally by: Kuolematon
Originally by: Sevarus James Not helpful Kuo, and once again living up to your sig, I see.
Ah your right! I see the light now! I will instanly go to firefox page and install it! Thank you sir for showing wrongs on my way of life! 
I don't understand why you people dis IE? It shows pages right (Well IE7 has some flaws but I'm sure that admins will correct their pages to be shown right on my browser!) and beside, it's intergrated to my OS so it works flaweless with it.
actually firefox does show pages right. it is incompetent web masters who don't know how to follow standards that cause pages to not show up as intended when using firefox, opera, or any other browser. IE7 actually has less flaws than other IE versions since microsoft has attempted to fix these flaws with it. anytime i see a site that can only be viewed in IE i think of it as an advertisement for a web master job opening. support BattleClinic buy gtc's from BattleClinic |

Maverick McDougel
Shiva Morsus Mihi
|
Posted - 2006.10.10 21:46:00 -
[85]
Originally by: DukDodgerz
Originally by: Maverick McDougel
Originally by: Xorus
Originally by: cRaNbErRy MuFfInMaN i have firefox and had clicked on the link thinking it was a joke and it popped up a download which i rejected do i have to worry about this?
im so paranoid i think ill wipe this hardrive clean this weekend =/ long and hard process
As for what i've read its using an exploit in IE which is obviously not present in FF, i visit a few sites that like to throw trojans and virii at me but i either get prompts to download a strangely named .exe file or my AV (avast) kicks up a message saying the connection contains [Virus name here] with an abart connection message but yes as i mentioned if you don't have any AV i suggest you get some :)Process Explorer also a freeware tool but provides better information than task manager does and also allows you to kill off a few more processes than task manager :)
what types of sites are you going to..... P***.... W***Z? 
got any good ones you want to share? 
a person can goto msn.com and if an advertising server, hosted by a third party, is comprimised, the advertising banners can be activeX and install applications without you knowing it is happening.
MSN wouldn't be at fault, but it would seem that it came from thier site.
it was meant to be humorous.............. some people have no fun in life.  support BattleClinic buy gtc's from BattleClinic |

DukDodgerz
Amarr Imperial Academy
|
Posted - 2006.10.10 22:01:00 -
[86]
Originally by: Maverick McDougel
Originally by: DukDodgerz
Originally by: Maverick McDougel
Originally by: Xorus
Originally by: cRaNbErRy MuFfInMaN i have firefox and had clicked on the link thinking it was a joke and it popped up a download which i rejected do i have to worry about this?
im so paranoid i think ill wipe this hardrive clean this weekend =/ long and hard process
As for what i've read its using an exploit in IE which is obviously not present in FF, i visit a few sites that like to throw trojans and virii at me but i either get prompts to download a strangely named .exe file or my AV (avast) kicks up a message saying the connection contains [Virus name here] with an abart connection message but yes as i mentioned if you don't have any AV i suggest you get some :)Process Explorer also a freeware tool but provides better information than task manager does and also allows you to kill off a few more processes than task manager :)
what types of sites are you going to..... P***.... W***Z? 
got any good ones you want to share? 
a person can goto msn.com and if an advertising server, hosted by a third party, is comprimised, the advertising banners can be activeX and install applications without you knowing it is happening.
MSN wouldn't be at fault, but it would seem that it came from thier site.
it was meant to be humorous.............. some people have no fun in life. 
sorry, wan't trying to sound mean, just informitive....(besides, ccp would be looking at eskeemoes and such... )
|

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.10 22:06:00 -
[87]
Originally by: Kuolematon
Originally by: Sevarus James Not helpful Kuo, and once again living up to your sig, I see.
Ah your right! I see the light now! I will instanly go to firefox page and install it! Thank you sir for showing wrongs on my way of life! 
I don't understand why you people dis IE? It shows pages right (Well IE7 has some flaws but I'm sure that admins will correct their pages to be shown right on my browser!) and beside, it's intergrated to my OS so it works flaweless with it.
Ahh, my pleasure Kuo! Its always good to see when people instantly take my advice! -lmao.
Seriously man, in my post, the 'dis' as you so eloquently put it, isn't a religious thing. Its a fact. IE6 (which is what most people are using) is a security manager's nightmare, and a malware writer's godsend. Its not a matter of "I wuv da FOX", or "I hate Bill Gates", its a matter of safe browsing and letting in what you WANT and not some silent stealth viral or malware bomb just because you're not 45 seconds up to date on your "blockers".
If you want to use it, heck, more power to you. I'm a firm believer in choice. Just don't assume that because you use it, its the best option out there. It may be FOR you, but for most people, IE can lead to a host of problems such as the topic of this thread. ----- ------------
Updated Linux Desktop+EVE+EVE-TV |

Firebyrd
Gallente Crooked River Productions
|
Posted - 2006.10.11 01:37:00 -
[88]
i use netscape 9.0, it has a Firefox or IE option displays ----------------------------------------------- In the End , there can be only 1
Learn from yesterday, that u may be stronger tomorrow
|

Kuolematon
Space Perverts and Forum Warriors United
|
Posted - 2006.10.11 05:27:00 -
[89]
Originally by: Sevarus James Ahh, my pleasure Kuo! Its always good to see when people instantly take my advice! -lmao.
Seriously man, in my post, the 'dis' as you so eloquently put it, isn't a religious thing. Its a fact. IE6 (which is what most people are using) is a security manager's nightmare, and a malware writer's godsend. Its not a matter of "I wuv da FOX", or "I hate Bill Gates", its a matter of safe browsing and letting in what you WANT and not some silent stealth viral or malware bomb just because you're not 45 seconds up to date on your "blockers".
If you want to use it, heck, more power to you. I'm a firm believer in choice. Just don't assume that because you use it, its the best option out there. It may be FOR you, but for most people, IE can lead to a host of problems such as the topic of this thread.
Well tbh, you got me to think if I should install Firefox or not. When IE7 is out and FireFox 2.0, I will re-evalute my needs and their features.
But on a midsized school where I work as an admin, we use IE. Reason? Because most of 3rd party web programs we are using here in Finland, needs IE and IIS and ASP and whatnot!! 
Unnerf Amarr!Ö "I read somewhere that Kali will be featuring turn-based combat to increase immersion." ¬ Waagaa Ktlehr
|

Complacency's Bane
Caldari
|
Posted - 2006.10.11 07:09:00 -
[90]
Originally by: Kuolematon But on a midsized school where I work as an admin, we use IE. Reason? Because most of 3rd party web programs we are using here in Finland, needs IE and IIS and ASP and whatnot!! 
IETab for Firefox is helpful.
When you do run into a webpage requiring IE, right click -> open in IETab, and now theres a firefox tab containing IE.
Not that I have the ability to use a web browser without mouse gestures though.
|

Jim McGregor
Caldari
|
Posted - 2006.10.11 09:22:00 -
[91]
Originally by: Kuolematon
But on a midsized school where I work as an admin, we use IE. Reason? Because most of 3rd party web programs we are using here in Finland, needs IE and IIS and ASP and whatnot!! 
I suggest you try breaking free from Microsoft while you can. What you are experiencing is just another example of their tactics to integrate things into eachother to the degree that you soon no longer have any options than to go 100% Microsoft or build everything yourself from scratch.
Soon they are going to put services on the web and rent them to people, and I wouldnt be surprised if some functions in Office and Windows require a monthly subscription to use them. And if you dont pay, you will have a hard time finding a replacement for the features you lose. Thats their whole strategy.
--- Eve Wiki | Eve Tribune | Eve Pirate |

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.11 10:53:00 -
[92]
Originally by: Kuolematon
Originally by: Sevarus James Ahh, my pleasure Kuo! Its always good to see when people instantly take my advice! -lmao.
Seriously man, in my post, the 'dis' as you so eloquently put it, isn't a religious thing. Its a fact. IE6 (which is what most people are using) is a security manager's nightmare, and a malware writer's godsend. Its not a matter of "I wuv da FOX", or "I hate Bill Gates", its a matter of safe browsing and letting in what you WANT and not some silent stealth viral or malware bomb just because you're not 45 seconds up to date on your "blockers".
If you want to use it, heck, more power to you. I'm a firm believer in choice. Just don't assume that because you use it, its the best option out there. It may be FOR you, but for most people, IE can lead to a host of problems such as the topic of this thread.
Well tbh, you got me to think if I should install Firefox or not. When IE7 is out and FireFox 2.0, I will re-evalute my needs and their features.
But on a midsized school where I work as an admin, we use IE. Reason? Because most of 3rd party web programs we are using here in Finland, needs IE and IIS and ASP and whatnot!! 
Having been in the tech industry a loong time, I really feel your pain here. Being stuck in a position to use what is handed to you as opposed to the tool that is 'better and safer' can be a royal pain in rear end. I always go this route: Use the tools that work provides during WORK hours, and when I get home, go back to what is the better solution. As you might deduce from the link below my signature...what is safe/secure/ and works better definitely doesn't come from redmond washington.  ----- ------------
Updated Linux Desktop+EVE+EVE-TV |

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.11 16:57:00 -
[93]
Quote:
what is safe/secure/ and works better definitely doesn't come from redmond washington.
I agree but your scope is too narrow. I would say that most of the programs out there are not safe/secure. Every application that has been written can be *****ed. There just has to be enough cofee and desire to sit through tons of assembly code. You will notice that as Firefox gets more and more popular, more and more people will start attacking it.
There is no such thing as the fastest/best/safe/will brush my teeth when I wake up programs out there. ___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

cRaNbErRy MuFfInMaN
mUfFiN fAcToRy Pirate Coalition
|
Posted - 2006.10.11 18:23:00 -
[94]
http://dl1.eve-files.com/media/0610/damnit.PNG
is this related to the trojan cause when i try and start up eve it tells me that. and what is chkdisk utility?
and my eve wont start up
Check out http://dl1.eve-files.com/media/0608/new.jpg |

Hakera
Anari Higard
|
Posted - 2006.10.11 18:34:00 -
[95]
clear your cache (bar your settings folder and prefs.ini) as normal and try again.
It isnt a trojan, just a file corruption by looks of it.
|

cRaNbErRy MuFfInMaN
mUfFiN fAcToRy Pirate Coalition
|
Posted - 2006.10.11 18:40:00 -
[96]
cannot delete file 2710_32: the file or directory is corrupted and unreadable.
=/
C:\Program Files\CCP\EVE\cache\Pictures\Gids
Check out http://dl1.eve-files.com/media/0608/new.jpg |

Adoro
Reunited
|
Posted - 2006.10.11 18:43:00 -
[97]
chkdisk is a windows dos program. reboot your computer with winxp in cd drive. then boot from from cd and run the recovery console.
type chkdisk to perform chkdisk.
can also yse fixmbr --------
Bailian Moxtain:
Quote:
Who needs pride when there's isk to be made
|

Hakera
Anari Higard
|
Posted - 2006.10.11 18:43:00 -
[98]
try:
Step One: Open "My Computer", RIGHT click on the C drive icon, choose "Properties".
Step Two: When that loads, click on the "Tools" tab, then click on the "Check Now" button in the "Error Checking" section.
Step Three: When that little window loads, place a CHECK in BOTH boxes, then click on "Start Now".
Step Four: A message will pop up saying that Error Checking will run after you restart the computer, so......Restart the computer. Error Checking will run automatically after the restart and it locks you out from doing anything until it's finished. It takes a little time to perform the task but after it's finished, it will restart into Windows automatically.
|

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.11 22:40:00 -
[99]
Originally by: Daald
Quote:
what is safe/secure/ and works better definitely doesn't come from redmond washington.
I agree but your scope is too narrow. I would say that most of the programs out there are not safe/secure. Every application that has been written can be *****ed. There just has to be enough cofee and desire to sit through tons of assembly code. You will notice that as Firefox gets more and more popular, more and more people will start attacking it.
There is no such thing as the fastest/best/safe/will brush my teeth when I wake up programs out there.
My 'scope' has to do with the subject matter of this thread. In that context, it's IE that is the most vulnerable to attack. Also in context, my statement was referring to what I use as I was pointing to the link below my signature.
You are correct that firefox is not immune from attack, nor are ANY operating system. The scope of the vulnerability and the EASE of attack under the MS platform are what is causing the major issues here. You don't see one MAC or Linux user in this thread with issues...and we ARE playing EVE and reading the forums here. The major reason behind this isn't that we are 100% secure, it is that the platform we are using is infinitely more secure than windows is, due to the very nature of the administrative rights vs. user rights that are built in from the ground up.
A viral attack on either of these systems, while rare, can do damage ONLY to the user space, and even then ONLY after the user has repeatedly given the offending program permission to do so. The OS and its secured /root system is relatively untouchable. (the only exception would be a complete moron giving the offensive application root authority...and they would deserve whatever they got at that point, tbh.)
To top that off, spreading a virus under these platforms is infinitely more tricky for the viral writer as EACH system has to have permissions enabled by each user, thus slowing to a grinding halt the spread of the offensive code.
The myth that as linux/mac get more widespread they will be attacked with as much success as MS windows does is perpetuated by people who do not know the underlying methodology and architecture of the platforms...or they are spreading FUD to purposely denigrate the non-MS world.
A true NETWORK operating system has security and separation of user space from the applications/kernel designed in to prevent the very things that are occuring on the windows side of the OS fence.
Vista promises much more security as well as IE7 enhancements. However, as I've been in the tech field for twenty years, I'll believe that when I see it. When it was released, XP was touted as the most secure OS on the planet, and you can see how well that stood up. ----- ------------
Updated Linux Desktop+EVE+EVE-TV |

Kuolematon
Space Perverts and Forum Warriors United
|
Posted - 2006.10.12 06:29:00 -
[100]
Originally by: Jim McGregor
I suggest you try breaking free from Microsoft while you can. What you are experiencing is just another example of their tactics to integrate things into eachother to the degree that you soon no longer have any options than to go 100% Microsoft or build everything yourself from scratch.
Soon they are going to put services on the web and rent them to people, and I wouldnt be surprised if some functions in Office and Windows require a monthly subscription to use them. And if you dont pay, you will have a hard time finding a replacement for the features you lose. Thats their whole strategy.
Uh-oh, thats not possible. Year ago I started project where we will assimilate bigger school with Novell system to ours. Now they will enjoy benefits of AD .
And we are already paying to microsoft "per month". Our lisences costs more per year than you can make in 4 years . But you people with "different" point of view just don't understand that it's not so easy to change or drop something. So many things are build around Microsoft products in school world nowadays .. at least here.
Anyway, I won't talk about this subject anymore. It's just like you guys said .. we work with tools that boss'es gives to us and tells us to use. We live with that and ..
PS. Why you think that EVE is build on MSSQL and their server software around Windows enviroment? 
Unnerf Amarr!Ö "I read somewhere that Kali will be featuring turn-based combat to increase immersion." ¬ Waagaa Ktlehr
|

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.12 10:44:00 -
[101]
Originally by: Kuolematon Edited by: Kuolematon on 12/10/2006 07:53:31 PS. Why you think that EVE is build on MSSQL and their server software around Windows enviroment? 
My guess, and its only a guess: Its what the devs knew. What strikes me odd is the fact that they are python programmers at heart, and that's more open source than MS.
The client is simple economics. 80-95%+ of the user base (gamers) use the windows platform.
The server...now that has been a mystery to me since day one. Of course now, they are firefighting memory issues, throwing tons of hardware at the problem...and THAT is typical of an MS environment. I work in a world wide command center for IBM. Our severity 1 and 2 ticket breakdowns over the last six months are an interesting bit in relation to this:
Breakdown of non hardware failure issues: 65% windows (server 2003/XP/Win2k sev1 - memory/cpu problems. (even split across versions.) 20% AIX - cpu problems 10% SUN- cpu issues 5% Linux - cpu issues. (fortune 200 world wide companies).
Personally, even as a linux advocate, I was shocked to see the disparity. In my line of work, I see windows servers as a paycheck, as they continually have problems such as the issues that have been plaguing tranquility.
As to the viral problems we see NO issues in the AIX/SUN/LINUX world, and yet see a continual stream of tickets related to client and mail server problems related to the topic of the thread even with the LATEST and GREATEST AV software available for these platforms. ----- ------------
Updated Linux Desktop+EVE+EVE-TV |

Kitta Kopfhurer
|
Posted - 2006.10.12 16:06:00 -
[102]
Originally by: Kuolematon PS. Why you think that EVE is build on MSSQL and their server software around Windows enviroment? 
One reason might be that MSSQL is actually quite a nice piece of software. (That is: The performance is quite good compared to the price)
Also, comparing raw numbers of exploits / support requests is kinda pointless, considering Microsofts marketshare compared to the other competitors. Latest numbers show that IE has 82% of the browser market. If you were writing an exploit, you probably would like to target the huge population IE-using Joe Random who doesnt know of the other choices and likely not too security-conscious rather than the people who have switched over to FF/Opera/etc for whatever reason?
There already have been plenty of FF exploits doing the rounds, and as the marketshare grows, I would imagine so does the number of exploiters targeting it.
Bottom line: Usually the reason this sort of hacks happen is the user. Visiting seedy websites, clicking on suspicious links, not keeping his software up-to-date etc etc. Whatever your choice of software is, there are ways to make it secure. Do whatever it takes if you dont want to end up having your information stolen.
|

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.12 22:54:00 -
[103]
Edited by: Sevarus James on 12/10/2006 22:54:46
Originally by: Kitta Kopfhurer
Also, comparing raw numbers of exploits / support requests is kinda pointless, considering Microsofts marketshare compared to the other competitors. Latest numbers show that IE has 82% of the browser market. If you were writing an exploit, you probably would like to target the huge population IE-using Joe Random who doesnt know of the other choices and likely not too security-conscious rather than the people who have switched over to FF/Opera/etc for whatever reason?
The comparison I posted is on the server side. That comparison was referring to tickets on the backend (I dont' support clients). The numbers there are far more interesting as linux/aix/SUN are far more numerous than windows, and yet the disparity in issues and problems is still grossly in the microsoft product camp.
Sorry if I wasn't clear about that. ----- ------------
Updated Linux Desktop+EVE+EVE-TV |

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.13 03:55:00 -
[104]
Quote:
The myth that as linux/mac get more widespread they will be attacked with as much success as MS windows does is perpetuated by people who do not know the underlying methodology and architecture of the platforms...or they are spreading FUD to purposely denigrate the non-MS world.
You really underestimate the veracity of the virus writers. But what do I know anyway. I'm a FUD spreading MS lover that doesn't know the methodology and architecture of the non-MS world. ___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

Sevarus James
Minmatar Meridian Dynamics
|
Posted - 2006.10.13 10:45:00 -
[105]
Originally by: Daald
Quote:
The myth that as linux/mac get more widespread they will be attacked with as much success as MS windows does is perpetuated by people who do not know the underlying methodology and architecture of the platforms...or they are spreading FUD to purposely denigrate the non-MS world.
You really underestimate the veracity of the virus writers. But what do I know anyway. I'm a FUD spreading MS lover that doesn't know the methodology and architecture of the non-MS world.
Actually I don't underestimate the veracity. The nature of the 'nix' operating system was designed from the ground up with security in mind to PREVENT this sort of thing from occuring.
The numbers of 'actual' viruses on the non-MS platforms is miniscule to non-existent in comparison, and to be honest, with apache and nix' running a goodly percentage of the world's web servers, you'd think these voracious hackers would have done something already.
The fact that this has NOT occurred should say something. The viral and malware writers target what they can do the most damage to, and that is the non secure (comparatively speaking) end user running a browser that has hooks into everything on the operating system in a very administrative manner. ----- ------------
Updated Linux Desktop+EVE+EVE-TV |

Del369
Caldari Office linebackers Blood of the Innocents
|
Posted - 2006.10.13 10:56:00 -
[106]
Opera 4tw, takes a tad getting used to (set the skin to windows native and it feels a bit like IE (good for getting used to) i just love the free configurability with it, you can customise it any which way you like, right down to adding the buttons you want and removing the ones you don't, nothing touches Opera, not even close 
I want to die quietly in my sleep just like my dear old grandma, and not screaming in terror like her passengers!! |

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.13 13:49:00 -
[107]
Quote:
The fact that this has NOT occurred should say something.
Of course it does. I'm not disputing that. I just disagree with you on what you think it says. ___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

WrathchildeVOTF
|
Posted - 2006.10.13 15:06:00 -
[108]
Quote: Of course it does. I'm not disputing that. I just disagree with you on what you think it says.
Daald, what you seem to miss is that on a *nix operating system, an administrator has to give that shell script permission to run before it can do anything at all.
Windows OS just days "duh...yup, yup, yup" when a virus wants to run.
I'm not quite as far up the food chain in my position, but I support the UNIX boxes in a large corporation. Never had a virus on Sun, HP, or SGI, but our MS Exchange servers get crushed relatively often.
|

Daald
Celestial Fleet Ascendant Frontier
|
Posted - 2006.10.13 16:31:00 -
[109]
Quote:
Daald, what you seem to miss is that on a *nix operating system, an administrator has to give that shell script permission to run before it can do anything at all.
Windows OS just days "duh...yup, yup, yup" when a virus wants to run.
I'm not quite as far up the food chain in my position, but I support the UNIX boxes in a large corporation. Never had a virus on Sun, HP, or SGI, but our MS Exchange servers get crushed relatively often.
I understand that. I really do. I'm not being thick about it. I have administered *nix servers. The exploits always go through paths that the administrator thought were bulletproof and 100% safe.
After all you have to run code on that machine otherwise it is just a paper weight. Windows in its infinite wisdom decided to make scripting easy on its OS opening the door for script kiddies.
If you read that book I quoted they show you how to exploit a C printf function. So any code that actually prints anything and is not designed to look for the overflow is exploitable. That's the point I am making. Any code written in C that prints to the screen and is callable by the user in anyway shape or form is vulnerable. You can believe that it is impossible for a hacker to get there or infinitely harder, but it is not the system that makes it that way. It is the user. The average person using a *nix system is much much more technical than a windows user.
For example. The exploit that triggered this thread uses an adodb object to download the virus on your computer. This virus is then executed. It has as much rights as the user accout it is running in. Most people run as admin so therefore it has complete rights. The second portion tries a buffer overflow attack on another activex object, that I guess the executable uses to gain priviledged rights if it didn't have them already.
So where does the blame lie. 1- Microsoft for not differentiating between COM objects and allowing them to be instantiated that way from a script coming from a foreign website. 2- The user, for clicking a suspicious link, for running as admin and for not having their system patches up to date.
The first portion is only 1 attack vector. The second portion contains many attack vectors that will basically never be fixed because no matter how secure/safe the OS is, the user will find a way to mess it up for conveniance.
As long as there are users out there that don't understand how a hacker operates they will always succeed no matter what OS the user is running on top of hence my point. Don't think that the software you are running on top of will save you from your own ignorance. ___________________________________________ Logic is a systematic method of coming to the wrong conclusion with confidence. -Murphy |

Jaedar Metron
Deadly Alliance
|
Posted - 2006.10.14 13:50:00 -
[110]
CRAP!
I hadnt read this topic and clicked a link in a spam post, the poster was old and I thought he had clicked the "new topic" button a bit too many times.  
Anyways, I clicked the link, but instantly closed the window popping up when I saw the url in the new window. THe page managed to load enuough so I could see a white screen with a blue link in it or something.
I didnt find any autoexec in the windows registry, and I was wondering, did I manage to stop it? And what should I do if I didnt? I'm currently scanning with ewido and avg.
Help is appreciated
-JM |

Hakera
Anari Higard
|
Posted - 2006.10.14 14:02:00 -
[111]
Originally by: Jaedar Metron CRAP!
I hadnt read this topic and clicked a link in a spam post, the poster was old and I thought he had clicked the "new topic" button a bit too many times.  
Anyways, I clicked the link, but instantly closed the window popping up when I saw the url in the new window. THe page managed to load enuough so I could see a white screen with a blue link in it or something.
I didnt find any autoexec in the windows registry, and I was wondering, did I manage to stop it? And what should I do if I didnt? I'm currently scanning with ewido and avg.
Help is appreciated
run antivirus - let it removes what it detects, free av are
Try AVG or Avast for anti-virus.
also follow the guidance setout here afterwards.
|

Xandria Pearl
KIA Corp
|
Posted - 2006.10.16 17:08:00 -
[112]
Main account is suspended pending investigation about hacking/fishing.
I did manage to prevent any damage done as I realized what was happening straight away and changed my password. A GM even confirmed that it was a close call as I changed my pwd the very minute the "hacker" was attempting to access my account.... However, about 1-2 hrs after that occurance I was disconnected from the game and they indeed suspended that account... I was online all the time so the hacker couldn't have caused any damage.... (I even doubt he even got access to my account since I was also online with this alt) My questions are: -How long does that investigation usualy take? -Is it possible to change the login name to Eve to prevent brute pwd attacks in the future now that its' known?
PS. ofcourse the system is scanned with anti-malware stuff, including Zonealarm security suite and the Trendmicro online scan 
|

Hilabana
Minmatar Sebiestor tribe
|
Posted - 2006.10.20 16:10:00 -
[113]
What is the matter with you all ? never click on any links that you do not know for a fact that is safe! eve if your friend says it is!
|

Rilder
Caldari black viper corp
|
Posted - 2006.10.21 08:22:00 -
[114]
Originally by: Hilabana
What is the matter with you all ? never click on any links that you do not know for a fact that is safe! eve if your friend says it is!
Also dont trust the links even a mod throws out, or even the links that are plastard all over the eve website to take you to other parts of the eve website? 
|

splattercat
Cirrius Technologies O X I D E
|
Posted - 2006.10.22 13:32:00 -
[115]
I think you have lost your glue.
page 4?
ShadowDragon > LOL i never said "we dont log" |

Beetle Boy
Minmatar Hybrid Syndicate
|
Posted - 2006.10.26 15:40:00 -
[116]
Originally by: spurious signal Surely now it's time to start curbing the posting rights of trial accounts?
Heck, seems to me that 90% of the uses of trial accounts in general are bad. When 10% of the people logged on at any one time are trial accounts you have to question if they're being used as intended.
SPOT ON  |

PsyMan
Amarr Navy Runners
|
Posted - 2006.11.20 01:55:00 -
[117]
Edited by: PsyMan on 20/11/2006 01:59:48 If you know what you are doing you can actually tweak IE 6 to be as safe if not safer than a default firefox installation, the big issue is the fact that by default it is not. Too many posts back but someone said Mac users were playing eve? is this true or is it on VM's, would love to change skills on my imac at work without having to put XP in.
If only you could change skills in a secure browser eh?
Mac client ftw (all be it a small win)
And FF is a lot better anyway
|
|

Kaemonn
Forum Moderator Interstellar Services Department

|
Posted - 2006.11.20 04:16:00 -
[118]
Ok no need to necro.
forum rules | [email protected]| Eve-CCG You mean to tell me, theres a game that goes with the forums? |
|
| |
|
| Pages: 1 2 3 4 :: [one page] |