All times are UTC - 6 hours




Post new topic This topic is locked, you cannot edit posts or make further replies.   Page 1 of 2
 [ 38 posts ] 
Go to page: 1, 2  Next »  Page:
Author Message

 Post subject: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:10 am 
Staff Elder
Staff Elder
User avatar

Joined: April 6th, 2005, 7:49 am
Posts: 3,432
Location: Questing!
Gender: Male
Status: Offline
We have become aware of a new malicious computer virus/worm, and wanted to let everyone know about some good practices to help keep your computer and RuneScape account safe. There's no need to panic, but there are some precautions you should take.
The reason we are mentioning this worm in particular is because we believe that one version of it may attempt to specifically steal RuneScape passwords by recording your key presses as you type, and sending them back to the worm owner.

The new worm is called Bubbles, but is also known as Ramex, Skipi and Pykspa. Bubbles can get on to a computer in two different ways. Either by being downloaded directly from a third party website, or by a user receiving and opening a file disguised as a web link in third party messaging programs.

The worm cannot be transmitted through playing RuneScape or using the RuneScape.com website.

The security of the RuneScape servers themselves is in no way affected by this, this worms affect users own computers, not our servers which are very well protected.

The best protection against malicious computer software is to stay vigilant and use an up to date anti-virus program.

For anyone who is not currently using an anti-virus program, we really recommend that you install one as soon as possible! In fact install one right now!

If you do have an anti-virus program installed but it is not up to date, please take the time to update it with the latest virus definitions now. Again don't delay!

Lastly, you should never accept files from unknown sources full stop. However pay extra special attention when using 3rd party messaging programs or email as it is very easy to accidentally download malicious software by following a link.

__________________
Ultra Image
_________________
Proud RVA member since 7 Dec 2005!
proud Lieutenant of the Zulu Squad since 22 feb 2006!
Resigned as lieutenant as of august the 5th 2006.
Image


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:27 am 
I post here sometimes
Champion of Saradomin
Champion of Saradomin
User avatar

Joined: September 20th, 2006, 10:25 am
Posts: 5,106
Location: The pub
Gender: Male
Status: Offline

Donor: Prince (2009)
hmmm... this needs globalising...

__________________
There is a village, which is hidden in the shadow of a mountain.
Everybody is suffering from a lack of light.
One day, the eldest of this village leaves for the mountain with a teaspoon in his hands.
The others ask him what he intends to do.
He replies that he is going to move the mountain.
"But you will never succeed!" they cry out.
"No, i will never succeed, but somebody has to start."

~~~The Wising Up Song - Misty's Big Adventure

Hidden: 
Kikori wrote:
Runevillage the forum is pretty well much done. Runevillage the group will eventually die, but as long as we're still friends with each other in the end, it's still a pretty big thought in our heads. Runevillage the family is forever, no matter where we settle down. If absolutely nothing else ever comes of Runevillage in the future, that alone is a pretty damn awesome thought.


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:36 am 
Minor King
Minor King
User avatar

Joined: January 10th, 2005, 3:55 pm
Posts: 814
Location: Melbourne, Australia
Gender: Male
Status: Offline
Time for another scan I guess. Thank the gods for Firefox.

__________________
Steam


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:37 am 
Tweaking all the time
Staff Elder
Staff Elder
User avatar

Joined: July 5th, 2003, 7:13 am
Posts: 8,699
Location: Flanders (northern Belgium)
Gender: Male
Status: Offline

Donor: Knight (2012)
Friend of Hiker
Globalled.

Very important information. Putting on the site as well asap.

- Greetz Glodenox :cheese:

__________________
XML, SOAP, XSLT, JavaScript, SQL, Java, CSS, PHP, Scheme, JSP, C#, ASP.NET, VB.NET, PL/SQL, Visual Basic 6.0, C/AL and C (sorted well to less known).


Top
 Profile WWW 
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:41 am 
Staff Elder
Staff Elder
User avatar

Joined: April 6th, 2005, 7:49 am
Posts: 3,432
Location: Questing!
Gender: Male
Status: Offline
Glodenox wrote:
Globalled.

Very important information. Putting on the site as well asap.

- Greetz Glodenox :cheese:


oh sexy ;) thanks.

I thought it was pretty important too, normally I don't post these things but I thought everyone should know, there are people who don't read updates so yea :P

__________________
Ultra Image
_________________
Proud RVA member since 7 Dec 2005!
proud Lieutenant of the Zulu Squad since 22 feb 2006!
Resigned as lieutenant as of august the 5th 2006.
Image


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 4:04 am 
I post here sometimes
Champion of Saradomin
Champion of Saradomin
User avatar

Joined: September 20th, 2006, 10:25 am
Posts: 5,106
Location: The pub
Gender: Male
Status: Offline

Donor: Prince (2009)
Also, with this in mind, remember to NEVER click URL's from new registered members. it might not be what you expect it to be and may download malicious software into your computer! our mods go a great job of dispoising of such posts but they can never be quick enough! Please be careful when clicking URL's from members with low post counts! we don't want any account lossages here. and also remember to NEVER click email attachments from unknown senders.

Villagers, keep your rs accounts safe :wink:

__________________
There is a village, which is hidden in the shadow of a mountain.
Everybody is suffering from a lack of light.
One day, the eldest of this village leaves for the mountain with a teaspoon in his hands.
The others ask him what he intends to do.
He replies that he is going to move the mountain.
"But you will never succeed!" they cry out.
"No, i will never succeed, but somebody has to start."

~~~The Wising Up Song - Misty's Big Adventure

Hidden: 
Kikori wrote:
Runevillage the forum is pretty well much done. Runevillage the group will eventually die, but as long as we're still friends with each other in the end, it's still a pretty big thought in our heads. Runevillage the family is forever, no matter where we settle down. If absolutely nothing else ever comes of Runevillage in the future, that alone is a pretty damn awesome thought.


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 6:51 am 
Minor King
Minor King
User avatar

Joined: August 5th, 2007, 11:08 pm
Posts: 954
Gender: Male
Status: Offline
^^ I feel for that once :(
Oh great, I STILL dont know how to do a virus check on a mac... -_-
EDIT: 400th Post :0


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 7:09 am 
Village Pictographer
Village Legend
Village Legend
User avatar

Joined: November 27th, 2004, 7:19 am
Posts: 3,987
Location: Why do you wanna know that?
Gender: Male
Status: Offline
Damn pixel lovers. :s

__________________
ImageImageImage
Image


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 7:14 am 
Queen of Runevillage
Sorceror of Saradomin
Sorceror of Saradomin
User avatar

Joined: June 26th, 2004, 2:10 pm
Posts: 4,378
Location: Across the Sea
Gender: Male
Status: Offline
Damn weabos.

Regardless, as long as you're not stupid I think we're all safe now, right dears?


Top
 Profile WWW 
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 7:40 am 
Zoboomafoo!
Village Elder
Village Elder
User avatar

Joined: February 6th, 2006, 12:29 pm
Posts: 16,194
Location: Behind the scenes.
Gender: Male
Status: Offline

Donor: Guardian (2008)
Oh my, well that sucks. Hope no one gets harmed by this. :(


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 7:56 am 
Staff Elder
Staff Elder
User avatar

Joined: April 6th, 2005, 7:49 am
Posts: 3,432
Location: Questing!
Gender: Male
Status: Offline
Someone tried to get me already, gave me a site, and it was an old friend who I hadn't spoken to in 2 years too!

Some people are very sad =/

__________________
Ultra Image
_________________
Proud RVA member since 7 Dec 2005!
proud Lieutenant of the Zulu Squad since 22 feb 2006!
Resigned as lieutenant as of august the 5th 2006.
Image


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 9:09 am 
Sorceror of Saradomin
Sorceror of Saradomin

Joined: March 27th, 2005, 3:58 pm
Posts: 3,192
Location: 3 more days.
Status: Offline
zomg there are keyloggers?? kind of old news tbh, did anyone here NOT know that lots of viruses are sent through msn or aim?

__________________
Image
Image
http://www.wowarmory.com/character-shee ... &n=Imashen
XBL gamertag: ashen1shugar
98% of teens have tried smoking pot and drinking. If you're one of the X% who does both, copy this and put it in your signature.


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 9:19 am 
Champion of Saradomin
Champion of Saradomin

Joined: July 7th, 2005, 6:27 pm
Posts: 6,006
Location: (N)o Wa(Y) im telling you strangers...
Gender: Male
Status: Offline
Yeah lol, this is some pretty old news. There are tons of viruses like this. Some not so smart people on RS still need a reminding though.


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 9:32 am 
I post here sometimes
Champion of Saradomin
Champion of Saradomin
User avatar

Joined: September 20th, 2006, 10:25 am
Posts: 5,106
Location: The pub
Gender: Male
Status: Offline

Donor: Prince (2009)
J@nr0k wrote:
Yeah lol, this is some pretty old news. There are tons of viruses like this. Some not so smart people on RS still need a reminding though.

noooooo no no noo!

this is new! this virus was discovered this morning

__________________
There is a village, which is hidden in the shadow of a mountain.
Everybody is suffering from a lack of light.
One day, the eldest of this village leaves for the mountain with a teaspoon in his hands.
The others ask him what he intends to do.
He replies that he is going to move the mountain.
"But you will never succeed!" they cry out.
"No, i will never succeed, but somebody has to start."

~~~The Wising Up Song - Misty's Big Adventure

Hidden: 
Kikori wrote:
Runevillage the forum is pretty well much done. Runevillage the group will eventually die, but as long as we're still friends with each other in the end, it's still a pretty big thought in our heads. Runevillage the family is forever, no matter where we settle down. If absolutely nothing else ever comes of Runevillage in the future, that alone is a pretty damn awesome thought.


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 9:46 am 
Queen of Runevillage
Sorceror of Saradomin
Sorceror of Saradomin
User avatar

Joined: June 26th, 2004, 2:10 pm
Posts: 4,378
Location: Across the Sea
Gender: Male
Status: Offline
Arn't new viruses invented like...everyday?


Top
 Profile WWW 
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 10:24 am 
Village Elder
Village Elder
User avatar

Joined: September 2nd, 2005, 11:27 am
Posts: 4,588
Location: Sitting in an igloo eating beaver, drinking beer, and watching hockey, eh?
Status: Offline

Donor: Guardian (2008)
People should already know that they should have up to date Anti-virus software and be careful with links.

Doesn't really seem like anything new. There are millions of viruses/keyloggers that can do stuff like this. Why is "bubbles" any different? :-s

__________________
Image | Image | Image
Image
Image | Image | Image | Image | Image
Temporarily Gone


Top
 Profile
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 1:07 pm 
Tweaking all the time
Staff Elder
Staff Elder
User avatar

Joined: July 5th, 2003, 7:13 am
Posts: 8,699
Location: Flanders (northern Belgium)
Gender: Male
Status: Offline

Donor: Knight (2012)
Friend of Hiker
Because it is directed specifically against RuneScape players.

EDIT: hmm... perhaps it isn't... It may just be a good moment to scare people so those who still don't realise they really could use protection will be convinced they should get protection...

- Greetz Glodenox :cheese:

__________________
XML, SOAP, XSLT, JavaScript, SQL, Java, CSS, PHP, Scheme, JSP, C#, ASP.NET, VB.NET, PL/SQL, Visual Basic 6.0, C/AL and C (sorted well to less known).


Top
 Profile WWW 
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:30 pm 
Sorceror of Saradomin
Sorceror of Saradomin

Joined: July 22nd, 2003, 6:00 pm
Posts: 2,754
Location: infront of the computer, waiting to be banned or modded :P
Status: Offline

Donor: Guardian (2007)
i own all bugs, i have a size 16 shoe :D

__________________
45 David said to the Philistine, "You come against me with sword and spear and javelin, but I come against you in the name of the LORD Almighty, the God of the armies of Israel, whom you have defied. 46 This day the LORD will hand you over to me, and I'll strike you down and cut off your head. Today I will give the carcasses of the Philistine army to the birds of the air and the beasts of the earth, and the whole world will know that there is a God in Israel. 47 All those gathered here will know that it is not by sword or spear that the LORD saves; for the battle is the LORD's, and he will give all of you into our hands."
48 As the Philistine moved closer to attack him, David ran quickly toward the battle line to meet him. 49 Reaching into his bag and taking out a stone, he slung it and struck the Philistine on the forehead. The stone sank into his forehead, and he fell facedown on the ground.

http://www.slinging.org/


Top
 Profile WWW YIM 
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:41 pm 
Village Legend
Village Legend

Joined: September 27th, 2003, 7:19 pm
Posts: 753
Status: Offline

Donor: Guardian (2004)
The worm is targeted to runescape users.
taken from:
http://blog.spywareguide.com/2007/09/bubblesfor_kids.html
EDIT: the copy paste didnt include the pictures here. the link above has the full text and pics. and if you don't trust that link, remember i do hold legend status here. 8)

The discovery of the Bubbles worm has led to the discovery of more and more variants across the internet. While all have essentially the same methods of infection, not all simply block security programs. FSL has come across a variant of the Bubbles worm that is designed to steal any and all sensitive information from the victim's computer through the most devious method of all...keylogging!

It starts with an executable downloaded from a questionable website. This executable copies itself into the system32 directory of the victim PC, and these 4 files are copies of the main executable:

Image

That's not all this worm does. It also looks for the game Runescape on the infected PC. Here's a screenshot taken from the main executable, pdo.exe:

Image

For those not aware, Runescape is a MMO game whose target demographic is children, young teens, and teenagers in general. This worm is looking for not only "runescape", but a "RS PIN:" as well. Could this mean payment details? Or (more likely), could they be referring to the victim's PIN to their game bank? Whether its to simply loot your gold, or sell the PIN on illegal forums is unknown. That's not even the scariest part of this infection. It also logs everything the victim does on the infected PC, storing all logged information to a file in the system32 directory called syswinf32.dll.

Image

Syswinf32.dll stores extremely sensitive information monitored from the infected PC.

The above picture is just a sample of what was found in the .dll file. It shows applications that have run, any action taken within the application, any text typed, and any websites visited. Now that it's effectively stealing every piece of information on the victim PC, it's time for the worm to spread to every Skype contact.

Image

Now this worm starts looking familiar. This is the exact same behavior we observed in the original Bubbles worm. When you put it all together what do you get? You get a worm/keylogger that spreads through skype contacts and targets the teenagers that play Runescape. Combine that with the big juicy MAILTO: in the main executable file and you have yourself a wonderful recipe for potential identity theft.

Research Summary Write-Up: Chris Mannon, Senior Threat Researcher
Additional Research: Deepak Setty, Senior Threat Researcher

Posted by Chris Mannon on September 19, 2007 01:33 PM | Permalink

__________________
Image


Last edited by Glodenox on September 29th, 2007, 3:57 pm, edited 2 times in total. Reason: Added the pictures to your post and put the article within quotes.
Top
 Profile WWW 
 

 Post subject: Re: 29 September 2007 - Important information
PostPosted: September 29th, 2007, 3:59 pm 
Tweaking all the time
Staff Elder
Staff Elder
User avatar

Joined: July 5th, 2003, 7:13 am
Posts: 8,699
Location: Flanders (northern Belgium)
Gender: Male
Status: Offline

Donor: Knight (2012)
Friend of Hiker
I have checked out the website and it is safe indeed. I now made it so that you don't need to visit their website to see the pictures though.

Good find! This shows the value why this topic became a global :)

Note: I've updated our previous computer performance guide. It is now the Computer Speed and Security Special Report.

- Greetz Glodenox :cheese:

__________________
XML, SOAP, XSLT, JavaScript, SQL, Java, CSS, PHP, Scheme, JSP, C#, ASP.NET, VB.NET, PL/SQL, Visual Basic 6.0, C/AL and C (sorted well to less known).


Top
 Profile WWW 
 
Display posts from previous:  Sort by  
Post new topic This topic is locked, you cannot edit posts or make further replies.  Page 1 of 2
 [ 38 posts ] 
Go to page: 1, 2  Next »  Page:

All times are UTC - 6 hours


Who is online

Users browsing this forum: No registered users and 40 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Jump to:  

Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
The Village and this web site are © 2002-2012

ThePub 2.0 - Designed by Goten & Jackstick. Coded by Glodenox & Henner.
With many thanks to the Website Team!