Originally Posted by Twig
Have you tracked your account? Is anyone selling your stuff? Jesus christ Twig, I am sorry that sucks so bad. Especially knowing you and your account. . .
Originally Posted by Twig
Have you tracked your account? Is anyone selling your stuff? Jesus christ Twig, I am sorry that sucks so bad. Especially knowing you and your account. . .
It's ok believe me we understand why people are so angry and upset. We are trying to help everyone in anyway we can.
oh I forgot to mention about the Linkshell account. Yes, the link is so that other people that are not logged onto it can see your gear, quests , or whatever you want to share. That is why we had you log into the Linkshell site and enable the ability to see information offline.
wow didnt know that many ppl got hacked at exactly same time .
anyhow we found one that someone had "infostealer.gamania" on his PC after doing virus scan , then whoever that was registered in his POL got hacked.
list from Odin would be: Hulkk , Hiaku , Emmaliz , Varus . that i know of
ofcourse we found 3 mules that were selling the same exact stuff , and which one of them bazaaring herald gaiters , novio earring and manteel.
edit: also all of them logged back with same exact position of where they were , none of them were in a city , but somehow all thier none rare ex items gone , did that happen to others?
5 min ago, someone attempted to hack into one of my Dynamis friend's account. For some strange reason that person didn't change the password immediately, so another friend went into a log-in war with whoever this hacker is and managed to change the password before they did.
Said hacker ported the character to Altepa but didn't manage to do anything before we got it back.
Just some more information. There was a trojan loose though I am not sure yet exactly where it came from. I used IE and had multiple browser tabs open to FFXI information sites such as Allakhazam, FFXIclopedia, FFXI-atlas, FFXIAH, though I suspect that the FFXIAH was the culprit. The particular trojan I located was:
Trojan-PSW.Win32.OnLineGames.a
The file was Windows\System32\kb1ss1p.dll
It could be it.
Some info about it (under 3. Using Malware):
http://www.kaspersky.com/reading_room?chapter=207716493
As for RMT sites or entities using malware through advertisements, etc. to compromise and rob accounts, I fully believe it.
Be careful out there. Everyone is a target. The OP's mentioned timeframe of when the compromises occurred is dead accurate.
Thank you so much for that informaton!!! I have already contacted my sita admin and he is looking into this for everyone. I will keep you all posted as fas as what we can find out. If this is the issue, hopefully we can inform other sites about this if it is an issue
I posted this in the other thread, but I will post here too.
It happened again. I have been using it all day without it trying to download something. Now it just happened.
http://img266.imageshack.us/img266/861/safehd0.th.jpg
When I click the "x" on the pop up box, it pops another box trying to send me to another webpage.
http://img89.imageshack.us/img89/9039/safe2ra5.th.jpg
Just for the people good with this stuff, am I safe? I didn't dl anything and just "x" out of it.
edit: beaten to it
Thanks again for all your help! They are working on this to see whats going on.
It doesn't sound like you are safe, but I am not an internet security guru or anything close. I certainly didn't press OK, and I was still infected. I was infected with another Trojan too from it days ago: Trojan.FakeAlert
If you use the FFXI Shortcut (PlayOnline saves your Account password so you don't have to enter your password), and it bumps you back to the login screen where you have to input your password again because it was saved but mysteriously wasn't there anymore, DON'T type in your password and log in.
Duken was moved to Midgar
i found this trojin in my comp c:/window/system32/in3.dll
Didn't something similar happen a long while back with banner ads on Alla?
Activex fails, just because it allows this rubbish to happen. IE is the only browser that uses it and the only browser that integrates viruses and spyware into the operating system.
Protect yourself with Mozilla + Flashblock + Adblock + Filterset.g + (if you want added security) Noscript. I use all except noscript and have no issues with ads or spyware ever. I work in the industry and repair spyware/virus/trojans on a daily basis. Every single time IE has installed an activex control that has bled into the operating system and other software.
The following tools will scan/remove and further down protect you from most of these issues. Before running any of these first disable System Restore. Control Panel > System > System Restore (disable on all drives and click OK)
Windows Defender
Adaware
AVG Anti-Rootkit
Mozilla
Adblock
Filterset.g
Flashblock
Noscript
couldn't agree with you more. activex is one of the most poorly conceived systems layered on top of one of the most poorly conceived systems ever invented. a browser interacts with so many potentially infectious vectors, it should be absolutely no stretch to realize that it should be greatly divorced from the OS as well as any other applications.Originally Posted by Builttolast
regardless, my general policy is that one can never be sure that an infected computer is cleaned, only made less infected. i never rely on an infected machine as a secure, trusted install anymore until i do a complete reload of the OS. considering the high amount you stand to lose if your computer should remain infected, i'd suggest you go through with a full re-install. regardless, the above tools should without a doubt be run, and up to date antivirus software should be installed on your PC. AVG offers a free, albeit slightly limited, antivirus application that does a fairly good job. give that a go if you don't already have some up to date antivirus running.
Originally Posted by Ddong
I just got that pop up a minute ago on ffxiah. didnt click anything... just shut down explorer through task manager.
running mcafee right now, and about to run the others i have. Ad-Aware, Spybot and HijackThis.
if this happens to anyone else can you PLEASE screenshot it also. We're trying to find out what ad it is so we need your help.
Jussy from Quetzalcoatl found this when he did a virus scan after losing his account.
[/quote]Originally Posted by Jussy
[/quote]Originally Posted by Dowzer
HAHAHAHAHAHAHAHAHAHAHA.
[/quote]Originally Posted by Dowzer
Waste of your $70. If there's something i can't stand its norton. AVG or NOD32 is where its at