Aikar has written up a wonderful guide to using NoScript to its best use:
http://forums.windower.net/index.php?showtopic=11323
Aikar has written up a wonderful guide to using NoScript to its best use:
http://forums.windower.net/index.php?showtopic=11323
does anyone have a symptom list of an infection, such as file names, behavior, etc that can be used to identify an infection? one of my LS mates noticed "a background process" popping up after he'd visited somepage (he wasn't more specific) and was rather flippant about changing his password remarking that he'd run an AV scan later. if the CGF ran this thru any decent packer, imo it's not terribly likely that the AV solutions could find it even if it were on his system. i'd like to either demonstrate that he is infected and impress upon him the importance of changing his password NOW before the cgf get their little 8 year old hands on his account or verify that nothing happened. for the record he's using IE too, though he claims some nonsense about not running scripts (i don't trust IE's blocking of anything further than i can hurl my computer...strapped to an 80 lb lead weight.)
symptoms include: accounts being stolen. AV solutions may not catch this.Originally Posted by Spekkio
You should ask him for his login/password and change it for him until you can impress upon him that he is an idiot. Oh I hope he doesn't have anyone else's info.
I might have some new information concerning the recent viral outburst.
Yesterday I logged on to ffxi as usual, I enter my member password (which is different from my POL password) and right after I click submit POL "pauses" as in the animations stop and it doesn't do anything because an IE window poped on top of it.
I do not use IE at all however I have both IE and Firefox set on "prompt me for every cookie" setting and the IE window on top of POL was a cookied prompt from w w w . q z o n e 8 . c n which I denied. As soon as I denied it POL "resumes" it's auto login (my POL password is set on auto login) and when I try to start the game, I get the "No such interface supported" just as in this thread: viewtopic.php?f=36&t=32686
Now as of today I still have my account intact however I still get the "No such interface supported" message on every new logon which means I have to restart POL every time. I would really like to know if anyone could shed some light over this situation. Is the "No such interface supported" connected with the hackings? Am I infected? What is that website it was trying to access?
As for the usual questions:
- I use firefox 100% of the time with adblockplus and afromentionned custom cookie control (sadly no noScript at the time).
- The last time I opened IE must have been a year ago.
- Yes I regularly use somepage and have done so during both infections (did not have problems the 1st time).
I have since then installed and configured noScript as well as completely blocked china from my router. What can I do to protect myself / get rid of the "No such interface supported"? What the hell was that cookie prompt?
I think I covered everything, I hope this helps someone get on the track to solving this for everyone and good luck to all of you who lost your accounts.
Your computer is compromised. Change your password on a clean machine and stop logging in from your compromised machine until you can clean it. The most thorough way to clean it is reformatting.Originally Posted by misterx1234
Thanks Aurik, that is what I was planning to do. Now I just need to wait until someone figures this one out so I can clean it.
I'm never clicking on Wafik's helpful images again, what the fuck.
I get the Interface not supported thing also, but none of the other stuff. Any ideas?Originally Posted by aurik
(from other thread)
You might want to download HijackThis and run an analysis and post a log.
http://www.trendsecure.com/portal/en-US ... s/download
Also avoid running POL if you are worried you might have a compromised computer.
Found something through hijackthis:
O20 - Winlogon Notify: Fly - C:\WINDOWS\SYSTEM32\smart.dll
This was the entire line in the log. The file was created on the 25th of May @ 4:10pm. A quick search on google and I found this:
http://virusscan.jotti.org/
Which flags it as a trojan, very few antivirus seem to able to pick it up. Sorry for the lack of details but that's pretty much where I am atm, just trying to point the right people to a possible clue.
Aurik check ur PM's
I just made a post about how to remove this.
viewtopic.php?f=2&t=34205
Thank you very much Mafai!
FYI - Opera is susceptible to this. It was immune to the previous somepage/ffxiah exploits. Guess I finally have to switch to ff.
Thanks Mafai for the help.
Updated the OP with that information. Awesome fix.![]()
=p Maf don't ignore me next time thnx. <3
No offense to anyone in the windower teams, etc but I started getting the no interface error just after my install of windower 3.4. This may be just a coincidence, as I may have visited somepage on my ffxi machine, not 100% sure, just figured I'd share.
Pure coincidence.Originally Posted by Shalafi
That's what I figured cause I know the windower folks are good. Just bad timing/luck for me as I thought it was a windower thing and only checked the windower error forum.Originally Posted by Izzy
Time for an Fhq rant:
This is where I remind anyone from Square Enix reading this thread to add a goddamned security question to our account so these dickheads can't jack people's accounts. I mean seriously, is it THAT hard to add a question? Do you LIKE having people ring your phone off the hook all day long as account after account is jacked, while confidence in your product (regardless of whether or not PlayOnline is responsible) drops like an anvil off a cliff? I cannot overstate how much this frustrates and pisses me off to know that simply surfing around the goddamned web could get my account compromised, just because SE can't add a preventative rather than reactionary approach to this whole bullshit fiasco.