Trust is a weakness

Anything and Everything about Uplink

Moderators: jelco, bert_the_turtle, Chris, Icepick, Rkiver

BladeRunner
level1
level1
Posts: 12
Joined: Tue Jan 21, 2003 5:03 am

Postby BladeRunner » Mon Jan 27, 2003 5:05 pm

I had an interesting adventure today, exploration of windows. It is so~ full of surprises. For example, I found an uninstall file in the windows folder, and to my surprise, when I decided to find out what it might uninstall, I got the following message:

"You do not have sufficient permission to run this file"

This is interesting. I, the owner of this computer, am not allowed to undelete something, wtf. I tracked that program back to an .inf file with various tricks, and it's label was

Ethernet + Creditcard or something, and a bunch of code I admittedly do not understand. Very very interesting. then an .ini file with a lot of senseless characters, within, coded, only thing recognizable a four-digit number.

"Trust is a weakness". Indeed. Everyone who bothers to scan his C:\Windows\ folder will agree to that.
Lord Samuel
level1
level1
Posts: 54
Joined: Sun Apr 28, 2002 11:00 am
Location: Kidderminster

Postby Lord Samuel » Mon Jan 27, 2003 5:15 pm

I would look at this carefully, possible trojan. Might just be a stupid program but I would check up on it if i was you. Something that the owner can't uninstall looks a bit dodge to me. Stupid cracker kids will dump stuff in the windoze folder to make ppl think it's meant to be there. Damn kids!
humpf, my brian is broken
BladeRunner
level1
level1
Posts: 12
Joined: Tue Jan 21, 2003 5:03 am

Postby BladeRunner » Mon Jan 27, 2003 5:25 pm

Thanks for the warning, I have thought about this myself, but everything seems to be fine as much as I can tell. My personal guess is that it's some kind of spyware. Think it's time for

cd usr
delete
cd sys
delete
shutdown
Enallyniv
level2
level2
Posts: 167
Joined: Sun Jan 12, 2003 9:52 pm
Location: Scotland
Contact:

Postby Enallyniv » Mon Jan 27, 2003 8:51 pm

I like that, very well said.
And I think that sounds really weird. I'm going to browse my Windows folder tonight. Do you think it could be something Chris put into the game for us to find, maybe a test of our tracing skills? I haven't seen anything written about it... Hmmm... I'll keep you updated. Just to be safe, try running a virus scan on the file.
AnthonyS
level5
level5
Posts: 1943
Joined: Sat May 25, 2002 7:32 pm
Location: Southampton, UK
Contact:

Postby AnthonyS » Mon Jan 27, 2003 8:55 pm

If it cant be deleted, there is a 78% chance of it being a trojin.
Deepsmeg
level5
level5
Posts: 6510
Joined: Thu Mar 21, 2002 1:26 pm
Location: Register 2102
Contact:

Postby Deepsmeg » Mon Jan 27, 2003 11:14 pm

Ethernet... Creditcard...
Is the system a laptop?
Image
BladeRunner
level1
level1
Posts: 12
Joined: Tue Jan 21, 2003 5:03 am

Postby BladeRunner » Tue Jan 28, 2003 12:26 am

AnthonyS: Tried to delete it and worked. Good advice anyway, thanks.

Deepsmeg: nope, no laptop.
Deepsmeg
level5
level5
Posts: 6510
Joined: Thu Mar 21, 2002 1:26 pm
Location: Register 2102
Contact:

Postby Deepsmeg » Tue Jan 28, 2003 3:07 pm

Fair enough. If it was, it could have been a PCMCIA (Creditcard) Ethernet adapter. :)
Image
There is No Spoon
level3
level3
Posts: 420
Joined: Mon Jun 10, 2002 5:31 am
Location: New Zealand
Contact:

Postby There is No Spoon » Tue Jan 28, 2003 10:21 pm

You can get PCI cards for desktop computers which enable you to use PCMCIA devices.  But anyone with such a device would recognise the 'credit card' notation as refering to such device.
<snip - signature removed - no reason provided>
Spectere_uplink
level4
level4
Posts: 789
Joined: Wed Apr 24, 2002 9:38 pm
Location: Ohio, USA
Contact:

Postby Spectere_uplink » Wed Jan 29, 2003 7:01 am

Quote: from BladeRunner on 11:05 am on Jan. 27, 2003[br]I had an interesting adventure today, exploration of windows. It is so~ full of surprises. For example, I found an uninstall file in the windows folder, and to my surprise, when I decided to find out what it might uninstall, I got the following message:

"You do not have sufficient permission to run this file"
Sounds like it could be a piece of third party software that expects the administrator of an NT computer to be named "Administrator" (which is, as you can tell, poor coding).

This is interesting. I, the owner of this computer, am not allowed to undelete something, wtf.
In Windows NT (especially NT5, which is 2000 and XP) the operating system prevents you from doing things that might damage the system (or others that may gain access to the administrative account) so there is a good possibility that there will be things that you can't delete.

There is another user for NT systems (though you can't log into it normally) called SYSTEM that literally has full control of the machine.  Humans cannot access this account normally (system services can, however).
.what.
Adriac
level5
level5
Posts: 3504
Joined: Wed Jan 23, 2002 7:20 am

Postby Adriac » Wed Jan 29, 2003 7:26 am

"If it cant be deleted, there is a 78% chance of it being a trojan." And why not an essential system file you REALLY don't want to lose?

(Edited by Adriac at 1:27 am on Jan. 29, 2003)
00010001000100000000101100010111000 10110000100010001100001011111000101 10000100100000111100010000000011010 0001011000111100001000100001011

Return to “General”

Who is online

Users browsing this forum: No registered users and 17 guests