Protect Your Account
Greetings all!
Over the years we have seen several 搒cam� attempts perpetrated on our customers. There are some unscrupulous people out there that may try to get control of your EverQuest account. There are a few simple rules you can follow to keep your account secure.
1) Never give out your password. This is the single most important thing you can do to keep your account secure. We will never ask for your password via email or in game.
2) Be careful with your Station name. Your Station name is one of the two things needed to access your account. Don抰 use it as a character name and don抰 post on message boards using your Station name. There抯 no reason to tell anyone your Station name, though we may indeed need that information in your conversations with us regarding your account.
3) Be careful what you download. This is a good precaution for anything you do on the Internet. Files can contain viruses and other dangerous programs. Be certain that any files you download come from a source you trust, and scan them for viruses before opening them. Keep your virus scanning software up to date.
Follow these guidelines and your account should be very secure.
Here are some examples of scam emails sent to our customers. We抮e reproducing them here as examples of things to be aware of.
----
These are the scams that have been brought to our attention. There are several methods that people will try to trick another individual out of his/her account information. Below are some examples of what to look out for. Some of them have italicized text that indicates either false information or incorrect spelling.
Example 1:
quote:
Subject: Shadows Of Luclin Beta Test
Date: Mon, 30 Apr 2001 20:44:00 -0500
From: BetaTesting@deleted.com
To: unsuspecting_recipient@somedomain.com
Dear Sony Station Customer,
As you may know, a new Everquest expansion is coming out soon called, Shadows of Luclin. Until we can finallize this expansion and ship millions of copies on to the market, we must make sure that everything works. So therefore, we at Sony and Verant are looking for a few beta testers. We are looking for people that have been dedicated Everquest players for while, and that have not borken any rules. In order for you to have a chance in participating please click here, to go to our Shadows Of Luclin Beta Testing sign up page.
After you submit the information please allow 5-6 business days for us to review your account. After that period we will send you an email letting you know if you have been qualified or not along with further instructions on how to start you beta testing.
Thanks for Participating,SonyStation.comVerant Interactive
The link will send you to a web page where it asks you to volunteer your STATION NAME and PASSWORD.
Example 2:
quote:
Subj: Everquest Patch for Test Server
Date: Tue, 1 May 2001 12:36:08 AM Eastern Daylight Time
From: anon@anon.com
To: anon@anon.com
EQtest103.exe (56065 bytes)
Here you go, my e-mail is xxxxxxxx@aol.com, give me an e-mail with any problems, questions, or comments, thanks and have fun!
The object of the email is to try to trick the recipient into believing that it contains a 揝hadows of Luclin Expansion Beta Testing file�. The name of the file that is attached with the email is eqtest103.exe, but this can easily change. Upon running the attached Trojan file, your computer is infected with a backdoor program that will record your keystrokes and email them to the creator of the file. Any thing you type, the email recipient will receive.
Backdoor.SubSeven22 is a Trojan horse. It is generally UPX packed; however, unpacked versions and versions packed with different executable packing software do exist. When packed with UPX, the Trojan horse's size is usually between 370 KB and 390 KB. Larger variations have been encountered, however, with file sizes ranging from 470 KB to 550 KB.
Backdoor.SubSeven is a Trojan horse, similar to Netbus or Back Orifice. It enables unauthorized people to access your computer over the Internet without your knowledge. When the server portion of the program is running on a computer, it is possible for the person who is accessing the computer remotely to do the following:
- Set it up as an FTP server
- Browse files on that system
- Take screen shots
- Capture real-time screen information
- Open and close programs
- Edit information in currently running programs
- Show pop-up messages and dialog boxes
- Hang up a dial-up connection
- Restart a computer remotely
- Open the CD-ROM
- Edit registry information
When it is run, BackDoor.Subseven makes the following changes to the system:
- Drops (adds) a copy of itself and a randomly named executable file, such as Eutccec.exe, to the \Windows or \Windows\System folder.
- Adds the dropped file to the load= and run= lines of the Win.ini file.
- Adds the dropped file name to the shell=explorer.exe line of the System.ini file.
- Creates the WinLoader value and sets it equal to the dropped file name in the following registry keys.
- Modifies the (Default) value from "%1" %* to, for example, eutccec.exe "%1" %* in the following registry keys:
HKEY_LOCAL_MACHINE\Software\Classes\
exefile\shell\open\command
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
To remove this, you will want to get an up to date anti virus program.
Example 3:
quote:
From: "[EDITED]"
[EDITED]@hotmail.com
To:
Sent: Thursday, May 03, 2001 10:44 PM
Subject: Verent Registration Patch!
Hail Fellow Norratian!
We at Verant are planning new and exciting things for you this year. As you already know the new "SHADOWS OF LUCLIN" expansion is due out this fall! Now, in order for you to be able to play this expansion, a few things must be done to your account. That is why, by the 10th of May, we will need your regards, saying that it is ok for us to change a few configurations when you log on to EVERQUEST! This meaning a few things. Along with your "OK" to do this, we will need you to send your station name and password. Please do this in a secure way, and never send these things to anyone but verant or sony! Verant and Sony Interactive are in no way responsible for unsecure servers... These changes will be picked up by your computer via patch time!
Thank you for you time. Verant appreciates having you as an EVERQUEST player!
Verant/Sony Chief Graphics Designer
[DELETED NAME] (And incorrect name and title)
_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com
Example 4:
Original Message Follows:
quote:
Subj: You won a FREE Everquest....!!!
Date: 6/3/01 12:54:33 AM !!!First Boot!!!
From: everquestteam@[EDITED].com (EQ TEAM)
To: [EDITED]
Congradulations inhabitant of Norrath!
You've just won a free Everquest T-shirt embroidered with a server and
character name of YOUR CHOICE!
This was a random picking of 100 lucky winners to show Verant and the
Everquest Team's appreciation toward our players!
This T-shirt is 100% free and will be mailed to the address given when you registered your Everquest account. If this address has changed, please email us your new address to insure the winnings are send to the correct
address.
Please email us back insuring you've received this email and DO want your 100% free embroidered Everquest T-shirt.
Along with your acceptance email, please include the following to verify the account belongs to you, as we do no send T-shirts to players whos accounts have not been randomly drawn as a winner.
1) Player name you wish to have on T-shirt (must have a player named this)
2) Player Server you wish to have on T-shirt (must have a character on this server)
3) Station Name
4) Station Password
5) New address (if changed since account was registered)
Thank you and good adventuring in the world of Norrath!
Please feel free to send us any questions you have.
All T-shirts are expected to be delivered at YOUR house within 3-5 weeks
upon sending!
Example 5
quote:
From, Verant [{EDITED}@eqverant.com]
To, Undisclosed.Recipients@ns.optionsnetwork.net
Cut and paste from the email.
Dear Customer,
This is Seth Davis from Verant Interactive. This morning your station name has attempted to be accessed 2,000 times.
Now this means one of two things, you don't remember your password (not likely) or someone is trying to break into your
account (the issue). We have good news however. When someone tries to access our logon server, its like called ID, we
can trace it to the house where they tried to logon. Its called an IP Address (Internet Provider Address ). If you would like,
we can put a block on the other house's IP address so he can never logon to our servers again. If this is the issue for you
please answer the following questions, and "reply" this message. Thank you for your time. Have a great day. Remember
"Shadows of Luclin" will be in stores November 18th. -Seth Davis
-answer all questions and reply-
1) First Name
2) Last name
3) Address
4) City
5) Zip
6) State
7) Phone
8) Billing First Name
9) Billing Last Name
10) Last 6 digits of used credit card
11) Station Name
Example 6:
quote:
Greetings,
The Verant team has been given a chance to search the database of ebay's past transactions. Starting July 1st we will now completely take all action in stopping the process of account selling/trading etc. We have located over 25 account trading and account selling auctions with in the past week. Generally we know the owners of these accounts were notified that account trading/selling /stealing is totally illegal with in our covenant rules.
To give you a basic overview what we do in this situation is permanently delete the account and the IP host of its current user from our login access screen. Once this is done we have organized vote from all the representatives and rank members of verant in which we should even precede more in depth in this matter.
If chosen, depending on the matter we could choose to simply have you account band or depending on the vote have you trialed for Misusage of our accounting.
Here at the Station, Sony Verant we hate banding citizens of our community or doing anything to there accounts unless it's a positive change. Importantly we want our game Everquest to be fun and exciting as an everyday experience.
If you have any questions please refer to the guide that Verant has chosen for you.
Hello Ryan Fuller here,
I have been given the auction site .]http://[EDITED]. I am supposed to ask you if you have any questions about what is going to happen to your account. I personally viewed your ebay queue and to be honest with you I my self does not believe your account should be terminated. I believe you should get a warning or just a temporary suspension. I know people like to sell their account to make money either for college or for some other usage of that profit. As a Verant Ceo represenitive I have the ability to change the status of what might happen to your account with in the next four to five days. What I am going to do is attach a Personal Identification applicant. Basically it just asks you question so we can notify this account you were trying to sell is actually yours. From there once filled out save that to file and send it back to my personal email. My personal email is [EDITED]. If you reply to the address you are reading !
this message from it will only get forwarded and at least take a month to get read.
Ryan Fuller
Verant Sony Interactive
|