SRO = spyware/adware

A place for general discussion about Silkroad Online. Talk about the game or ask questions. Please keep threads Silkroad Online related.
Post Reply
jyro
Casual Member
Posts: 85
Joined: Sun Apr 29, 2007 9:48 am

SRO = spyware/adware

Post by jyro »

Maybe you care, maybe you don't, I don't know...

But I thought something has to be up with SRO, so I sniffed the SRO packets and found SMB browsing packets right from their server and also I get Microsoft Messenger packets that contain ads for some registry cleaner... saying that it detected corruption and like 55 errors in my registry or some crap and to dl thier program.

I know for sure the SMB browse is from SRO, I can see the IP it's from and there's absolutely NO NEED WHATSOEVER for them to be looking at peoples file sharing network. I'm also 99.9999% sure that the MSN packets are tunnled from another server that pays for it because I only get them when SRO is running.

Edit:
I just discovered the spam isn't from SRO, though the SMB still is, the IP is the same so there's no mistake there.
Last edited by jyro on Sat May 05, 2007 4:56 pm, edited 1 time in total.

User avatar
XemnasXD
Chronicle Writer
Posts: 9841
Joined: Thu Jan 25, 2007 1:20 am
Quick Reply: Yes
Location: US - Illidan

Post by XemnasXD »

I use Kaspersky as a virus detector and if you have it you'll know how amazing it is. The first time i used it it completly cleared my compy of all that bad stuff that macafee and Adware missed. Now kaspersky is very touchy about everything i do on my compy but it never fails that when im on SRO i'll get a message from Kaspersky detecting keyloggers. It happens when im in or out of a party as well as when alot of ppl and no one is around. So i can't blame random ppl and i can't say that its someone in my party so my only conclusion is that theres something in SRO that uses some type of keylogging program for whatever reason. weird huh?
Image Image
signatures by Hostage Co. <3
~PoP is DEAD! My sTyLe is Supa-Flat!!~

User avatar
Quyxz
Advanced Member
Posts: 2364
Joined: Tue Apr 11, 2006 4:47 pm
Quick Reply: Yes
Location: The Netherlands

Post by Quyxz »

Yes. I also think SRO isn't totally clean.
Sometimes my PC is just getting farked up by it. :/
One oldskool matherfacker
Image

User avatar
numatan
Common Member
Posts: 117
Joined: Mon Apr 02, 2007 3:57 pm
Quick Reply: Yes
Location: Sparta

Post by numatan »

jyro, are you running XP with SP2?

Windows Messenger Service is disabled by default with SP2. If you're getting Alerter messages you will want to disable that under Administrative Tools > Services > Messenger.

Also, surely you're running behind either a software and/or hardware firewall that blocks SMB requests? I am using the pfSense stateful firewall along with the freebie ZoneAlarm software firewall, and I've never seen SMB requests other than those on my LAN.

jyro
Casual Member
Posts: 85
Joined: Sun Apr 29, 2007 9:48 am

Post by jyro »

Quyxz wrote:Yes. I also think SRO isn't totally clean.
Sometimes my PC is just getting farked up by it. :/


I don't know about you, but I HATE spyware with a passion.
This may be enough to make me quit, if I don't quit I surely won't be giving them my money.

numatan wrote:jyro, are you running XP with SP2?

Windows Messenger Service is disabled by default with SP2. If you're getting Alerter messages you will want to disable that under Administrative Tools > Services > Messenger.

Also, surely you're running behind either a software and/or hardware firewall that blocks SMB requests? I am using the pfSense stateful firewall along with the freebie ZoneAlarm software firewall, and I've never seen SMB requests other than those on my LAN.


Yeah, I have SP2 and a firewall.
The packets getting in aren't the problem, I'm just mad that they're even there to begin with.

User avatar
Rainigul
Senior Member
Posts: 4490
Joined: Thu Mar 29, 2007 5:43 pm
Quick Reply: Yes
Location: Pacific

Post by Rainigul »

It does have keyloggers, I saw a topic before that some guy downloaded ksro to sniff around in its packets so he could do stuff with isro. He said he found keyloggers and that irso must not be safe too.
But this one guy replied, and there was some reason for it.
It was so that they could detect if you were actually typing or not, so they could ban bots... I'm not sure if that was the reason, but don't worry, you're not gonna get hacked or anything.
As much as people hate to think, joymax is actually a good company, but there are some issues with their bosses and stuff which makes people not like them.

jyro
Casual Member
Posts: 85
Joined: Sun Apr 29, 2007 9:48 am

Post by jyro »

Rainigul wrote:It does have keyloggers, I saw a topic before that some guy downloaded ksro to sniff around in its packets so he could do stuff with isro. He said he found keyloggers and that irso must not be safe too.
But this one guy replied, and there was some reason for it.
It was so that they could detect if you were actually typing or not, so they could ban bots... I'm not sure if that was the reason, but don't worry, you're not gonna get hacked or anything.
As much as people hate to think, joymax is actually a good company, but there are some issues with their bosses and stuff which makes people not like them.


This stuff is just underhanded though... they could at least do it in the open, I don't like people who sneak around.

User avatar
numatan
Common Member
Posts: 117
Joined: Mon Apr 02, 2007 3:57 pm
Quick Reply: Yes
Location: Sparta

Post by numatan »

Almost all MMOs have some mechanism to kick people off the servers for inactivity. It's usually a timer between keypresses, mouse clicks, or mouse movements. If those events don't happen within a set period of time, then the user gets kicked.

It's amazing that SRO doesn't use this especially since a lot of people log in and just stand around without logging out because it can be so difficult to get back on.

As for a firewall that allows unsolicited external access on ports 137, 138, 139, and 445... well, that's just as good as not running a firewall at all. Be advised that a lot of malware can hook firewalls and antivirus programs to prevent their detection.

jyro
Casual Member
Posts: 85
Joined: Sun Apr 29, 2007 9:48 am

Post by jyro »

numatan wrote:Almost all MMOs have some mechanism to kick people off the servers for inactivity. It's usually a timer between keypresses, mouse clicks, or mouse movements. If those events don't happen within a set period of time, then the user gets kicked.

It's amazing that SRO doesn't use this especially since a lot of people log in and just stand around without logging out because it can be so difficult to get back on.

As for a firewall that allows unsolicited external access on ports 137, 138, 139, and 445... well, that's just as good as not running a firewall at all. Be advised that a lot of malware can hook firewalls and antivirus programs to prevent their detection.


Yeah I have the ports blocked, I can still see the packets though...
But actually I don't believe the firewall is really blocking anything because firewalls on XP suck, but I can only hope.

User avatar
NuclearSilo
Forum God
Posts: 8834
Joined: Mon Aug 21, 2006 12:00 pm
Quick Reply: Yes
Location: Age of Wushu

Post by NuclearSilo »

Who cares? Keylogger or not, your account infomation will be sent to JM. Why do they care if they already had access to server database?
Playing Age of Wushu, dota IMBA

jyro
Casual Member
Posts: 85
Joined: Sun Apr 29, 2007 9:48 am

Post by jyro »

NuclearSilo wrote:Who cares? Keylogger or not, your account infomation will be sent to JM. Why do they care if they already had access to server database?


Yeah, I don't even care about the keylogger. It's the other spyware that ticks me off.

ROFL MD told me there is no spyware and to not spread rumors.
I can see the freaking packets and the ad that is in them! :roll:

User avatar
numatan
Common Member
Posts: 117
Joined: Mon Apr 02, 2007 3:57 pm
Quick Reply: Yes
Location: Sparta

Post by numatan »

jyro wrote:
numatan wrote:Almost all MMOs have some mechanism to kick people off the servers for inactivity. It's usually a timer between keypresses, mouse clicks, or mouse movements. If those events don't happen within a set period of time, then the user gets kicked.

It's amazing that SRO doesn't use this especially since a lot of people log in and just stand around without logging out because it can be so difficult to get back on.

As for a firewall that allows unsolicited external access on ports 137, 138, 139, and 445... well, that's just as good as not running a firewall at all. Be advised that a lot of malware can hook firewalls and antivirus programs to prevent their detection.


Yeah I have the ports blocked, I can still see the packets though...
But actually I don't believe the firewall is really blocking anything because firewalls on XP suck, but I can only hope.

If you can see the packets but have the ports blocked, then the ports are not being blocked. Period.

The firewall you are using is either compromised or has rules to allow traffic on those ports. Most likely it's compromised due to a malware hook or a rootkit.

Software firewalls other than XP's Windows Firewall on XP are OK, but the best protection is provided by a combination of software and hardware firewalls. I have pfSense running on an ancient 233MHz PII with 14 PCs on my home network and have no latency issues playing MMOs or FPS.

Regardless, get that computer off the internet until you can plug the hole.

User avatar
Sharp324
Senior Member
Posts: 4383
Joined: Tue Jan 30, 2007 4:24 am
Quick Reply: Yes
Location: Off Topic

Post by Sharp324 »

jyro wrote:
Quyxz wrote:Yes. I also think SRO isn't totally clean.
Sometimes my PC is just getting farked up by it. :/


I don't know about you, but I HATE spyware with a passion.
This may be enough to make me quit, if I don't quit I surely won't be giving them my money.

numatan wrote:jyro, are you running XP with SP2?

Windows Messenger Service is disabled by default with SP2. If you're getting Alerter messages you will want to disable that under Administrative Tools > Services > Messenger.

Also, surely you're running behind either a software and/or hardware firewall that blocks SMB requests? I am using the pfSense stateful firewall along with the freebie ZoneAlarm software firewall, and I've never seen SMB requests other than those on my LAN.


Yeah, I have SP2 and a firewall.
The packets getting in aren't the problem, I'm just mad that they're even there to begin with.



Well most games now a days have adware in them that monitor what you do, but only are active while your playing...
------------------------------

jyro
Casual Member
Posts: 85
Joined: Sun Apr 29, 2007 9:48 am

Post by jyro »

numatan wrote:
jyro wrote:
numatan wrote:Almost all MMOs have some mechanism to kick people off the servers for inactivity. It's usually a timer between keypresses, mouse clicks, or mouse movements. If those events don't happen within a set period of time, then the user gets kicked.

It's amazing that SRO doesn't use this especially since a lot of people log in and just stand around without logging out because it can be so difficult to get back on.

As for a firewall that allows unsolicited external access on ports 137, 138, 139, and 445... well, that's just as good as not running a firewall at all. Be advised that a lot of malware can hook firewalls and antivirus programs to prevent their detection.


Yeah I have the ports blocked, I can still see the packets though...
But actually I don't believe the firewall is really blocking anything because firewalls on XP suck, but I can only hope.

If you can see the packets but have the ports blocked, then the ports are not being blocked. Period.

The firewall you are using is either compromised or has rules to allow traffic on those ports. Most likely it's compromised due to a malware hook or a rootkit.

Software firewalls other than XP's Windows Firewall on XP are OK, but the best protection is provided by a combination of software and hardware firewalls. I have pfSense running on an ancient 233MHz PII with 14 PCs on my home network and have no latency issues playing MMOs or FPS.

Regardless, get that computer off the internet until you can plug the hole.


Yeah normally I would, I'm just a bit annoyed is all.
This is just my XP partition, I don't really care what happens to it because I reinstall it all the time anyway... I have three other linux boots on this machine to use.

User avatar
SoBlu
Valued Member
Posts: 389
Joined: Sat Mar 24, 2007 4:26 pm
Quick Reply: Yes
Location: Athens

Post by SoBlu »

What else is Joymax going to do to you jyro besides already piss you off and send you to jsro.

I told u yesterday to stop being emo, girls dont find it attractive.

If they have anything it is standard and I trust it more then some bot program would be putting on my computer.
Image
"Those who do not remember the past are condemned to repeat it."

jyro
Casual Member
Posts: 85
Joined: Sun Apr 29, 2007 9:48 am

Post by jyro »

SoBlu wrote:What else is Joymax going to do to you jyro besides already piss you off and send you to jsro.

I told u yesterday to stop being emo, girls dont find it attractive.

If they have anything it is standard and I trust it more then some bot program would be putting on my computer.


You probably don't even know what emo is, you just want to try and make me mad. Getting ticked off is not emo, it's called being human.

I'm allowed to blow off steam as long as I don't break the rules and it obviously bothers you more than you bother me.

shadowman20875

Post by shadowman20875 »

yeah... okay, ty for the info i guess, but no need to alarm ppl who don know anything about computers

PPL WHO DONT SPEAK COMP.:

just get a good firewall and scan ur comp regularly

User avatar
William-CL
Forum Legend
Posts: 7363
Joined: Wed Feb 28, 2007 10:10 am
Quick Reply: Yes
Location: N/A

Post by William-CL »

my old comp got farked up when i played sro to much a day. I got soem weird error saying that additional oftware may have cause it. So i uninsttalled it from old comp and have never had the prob since.
Image

Post Reply

Return to “Silkroad General Discussion”