Advertisement
Guest User

Untitled

a guest
Aug 31st, 2011
1,157
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.89 KB | None | 0 0
  1.  
  2. Him: Avira, and Avast! have independently flagged Secrets wsock32.dll a trojan.
  3. Him: Because technically, it is, it allows access to additional (via escalation) system features. But the real trojan, as I stated, is eqgame.dll collecting the data.
  4. Me: What all does it collect?
  5. Him: Your windows login name, your entire IP table (What you're currently connected to, and your route address — so if you're routing through 192.168.3.1 or something nonstandard like that, they can go ahead and masturbate and say you're likely running ShowEQ as a router), your process list along with the locations of every file in your process list, timestamps when EverQuest is loaded and unloaded and a true or false evaluation if certain memory of EverQuest is accessed.
  6. Him: They can do a lot more since it hooks USER32.DLL, which is part of the GDI framework. They can continue along this path and access the system registry under the user credentials it's being executed as.
  7. Me: What all do you think they could potentially do with that dll?
  8. Him: Potential? Infinite. Reality? Depends on the operating system.
  9. Me: Say.. Windows 7 or XP?
  10. Him: If you run EverQuest as administrator — full access to your system.
  11. Me: Jesus
  12. Him: Running it in user-land however, they can read/write to the same directories as EverQuest, as that user. They can read/write to anything the user-land USER32.DLL is allowed (USER32.DLL, as stated is part of GDI — the thing that creates and manages new windows)
  13. Him: Through GDI you can fopen file information to import into a window. Which means it is possible for them to read any file on your disk (though this functionality, is not present)
  14. Him: But that is the level of trust you are giving Project1999 by running their bullshit
  15.  
  16. Don't know about you guys but personally I don't think I can put that much trust in Rogean, Secrets, and Uthgaard.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement