Item Search
     
BG-Wiki Search
Closed Thread
Page 11 of 47 FirstFirst ... 9 10 11 12 13 21 ... LastLast
Results 201 to 220 of 931
  1. #201
    Smells like Onions
    Join Date
    Jan 2008
    Posts
    8
    BG Level
    0

    Quote Originally Posted by Narse View Post
    Did you attempt to log back in from the same PC and were unable to immediately after crashing when you were getting hacked? I imagine, with a token, if your POL just crashes, the best thing to do is to just log on from another computer and change PW, or at least reboot the system you're on first.

    Also, has anyone done any rootkit scans yet that has been hacked?

    I did 1 attempt to relog on the first hack on the same PC. At the same time I was doing it I was booting up my second PC and logged in there and kicked them. The second time that I was hacked I went straight to my second PC and logged in there but I was not fast enough and was stripped. After the First hack I changed all my PW's mulitiple times on my 2nd PC before attempting to log back in on my main PC. After the second hack I changed PW's 2 times on my 2nd PC and will be calling SE to unlock/rollback my account when they open in 30mins. I have ran 2 different rootkit scans since my first post in this thread and nothing turned up in either scan. I am begining to wonder if this "hack" can be found by any scans of any kind. Before I play again on my main PC I plan on wiping the hard drive and re-installing everything. This may be the only thing so far that can take care of whatever has infected my PC.

  2. #202
    WASTE OF CURRENCY
    I CAN'T I CAN'T I CAN'T

    Join Date
    Feb 2006
    Posts
    9,066
    BG Level
    8
    FFXIV Character
    Izzy Izumi
    FFXIV Server
    Sargatanas
    FFXI Server
    Phoenix
    WoW Realm
    Arthas

    Quote Originally Posted by Therin View Post
    You'd think that if someone had the means to use those types of keyloggers, they'd target something with a little more value than an MMORPG. Like a bank account. I wouldn't think we'd have to worry about that, for a while. But I dunno.
    Stealing an MMO account is not punishable by law in most (all?) places. If I were a thief, I'd steal something I couldn't possibly get in trouble for if I got caught too!

  3. #203

    Quote Originally Posted by Izzy View Post
    Hahah, of course you're going to get DC'd if your IP changes.
    Well that's logical I meant to point out that you do stay connected for a little before you get kicked off, and the connection lets you actually do stuff before you get kicked off, so in that time it might be too late

  4. #204
    Relic Shield
    Join Date
    Oct 2006
    Posts
    1,600
    BG Level
    6
    FFXI Server
    Odin

    Quote Originally Posted by Frogger View Post
    I did 1 attempt to relog on the first hack on the same PC. At the same time I was doing it I was booting up my second PC and logged in there and kicked them. The second time that I was hacked I went straight to my second PC and logged in there but I was not fast enough and was stripped. After the First hack I changed all my PW's mulitiple times on my 2nd PC before attempting to log back in on my main PC. After the second hack I changed PW's 2 times on my 2nd PC and will be calling SE to unlock/rollback my account when they open in 30mins. I have ran 2 different rootkit scans since my first post in this thread and nothing turned up in either scan. I am begining to wonder if this "hack" can be found by any scans of any kind. Before I play again on my main PC I plan on wiping the hard drive and re-installing everything. This may be the only thing so far that can take care of whatever has infected my PC.
    post a hijackthis log of that pc.

    also you could look at the modules being hooking pol just by going to the login screen and running this (this is how i found smart.dll during the early account stealing days). you do not need to login.

    http://lmxvii.net/mafai/showmodules.exe

    When at the login screen, open this program, then pick pol.exe in the top box. Down below will load all the modules. Right click and hit select all, then hit save selected this will generate a text file. Post the contents of the file back here.

    Back when the hackings first occured, smart.dll looked like this. The bold is what threw a flag to me:

    Code:
    ==================================================
    Module Name : smart.dll
    Base Address : 0x013C0000
    Module Size : 0x0000C000
    Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-215
    Description : Framebuffer Display Driver
    Company : Microsoft Corporation
    Product Name : Microsoft? Windows? Operating System
    Modified Date : 5/26/2008 11:07:07 AM
    File Size : 35,840
    Filename : C:\WINDOWS\system32\smart.dll
    File Attributes : A
    ==================================================

  5. #205
    Salvage Bans
    Join Date
    Jun 2006
    Posts
    829
    BG Level
    5

    Quote Originally Posted by Mafai View Post
    post a hijackthis log of that pc.

    also you could look at the modules being hooking pol just by going to the login screen and running this (this is how i found smart.dll during the early account stealing days). you do not need to login.

    http://lmxvii.net/mafai/showmodules.exe

    When at the login screen, open this program, then pick pol.exe in the top box. Down below will load all the modules. Right click and hit select all, then hit save selected this will generate a text file. Post the contents of the file back here.

    Back when the hackings first occured, smart.dll looked like this. The bold is what threw a flag to me:

    Code:
    ==================================================
    Module Name : smart.dll
    Base Address : 0x013C0000
    Module Size : 0x0000C000
    Version : 5.1.2600.2180 (xpsp_sp2_rtm.040803-215
    Description : Framebuffer Display Driver
    Company : Microsoft Corporation
    Product Name : Microsoft? Windows? Operating System
    Modified Date : 5/26/2008 11:07:07 AM
    File Size : 35,840
    Filename : C:\WINDOWS\system32\smart.dll
    File Attributes : A
    ==================================================
    My 'hacking' seems to have been a little different than what is generally happening to people right now (my system was knocked offline with a "logged in from another terminal" message, and [perhaps because I didn't notice it for 30minutes + having a token] my account appeared to never have actually been accessed), but I have, as of yet, been unable to determine how anyone could have access to my information (I use FireFox + NoScript, etc). I'll post info on the PC I was at when I was logged on from another terminal, and in a bit the other PCs that I use to play FFXI with as well.

    Main PC, running Vista 32 bit OS

    CurrProcess info:

    Spoiler: show

    ==================================================
    Process Name : pol.exe
    ProcessID : 4776
    Priority : Normal
    Product Name : PlayOnline Viewer
    Version : 1.18.12
    Description : PlayOnline Viewer
    Company : SQUARE ENIX CO., LTD.
    Window Title : PlayOnline Viewer Ver.1.18.12b - Windower Enabled
    File Size : 1,600,000
    File Created Date : 1/19/2007 3:08:30 PM
    File Modified Date : 4/7/2009 4:22:38 AM
    Filename : C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    Base Address : 0x00400000
    Created On : 8/24/2009 11:17:53 AM
    Visible Windows : 1
    Hidden Windows : 4
    User Name : Peter-PC\Peter
    Mem Usage : 60280 K
    Mem Usage Peak : 60420 K
    Page Faults : 33374
    Pagefile Usage : 84152 K
    Pagefile Peak Usage : 90652 K
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : pol.exe
    Base Address : 0x00400000
    Module Size : 0x001CB000
    Version : 1.18.12
    Description : PlayOnline Viewer
    Company : SQUARE ENIX CO., LTD.
    Product Name : PlayOnline Viewer
    Modified Date : 4/6/2009 11:22:38 PM
    File Size : 1,600,000
    Filename : C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ntdll.dll
    Base Address : 0x778F0000
    Module Size : 0x00127000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : NT Layer DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:38:16 PM
    File Size : 1,203,792
    Filename : C:\Windows\system32\ntdll.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : kernel32.dll
    Base Address : 0x76260000
    Module Size : 0x000DB000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows NT BASE API Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 2/13/2009 3:49:05 AM
    File Size : 888,832
    Filename : C:\Windows\system32\kernel32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SYSFER.DLL
    Base Address : 0x61750000
    Module Size : 0x0005E000
    Version : 11.0.2020.21
    Description : Symantec CMC Firewall sysfer
    Company : Symantec Corporation
    Product Name : Symantec CMC Firewall
    Modified Date : 8/20/2008 1:39:26 PM
    File Size : 357,760
    Filename : C:\Windows\SYSTEM32\SYSFER.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : PolHook.dll
    Base Address : 0x10000000
    Module Size : 0x00010000
    Version : 1.18.07
    Description : PlayOnline Viewer polhook Module
    Company : SQUARE ENIX CO., LTD.
    Product Name : PlayOnline Viewer
    Modified Date : 9/10/2008 12:00:19 PM
    File Size : 61,440
    Filename : C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\PolHo ok.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : USER32.dll
    Base Address : 0x767A0000
    Module Size : 0x0009D000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Multi-User Windows USER API Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:48 PM
    File Size : 627,200
    Filename : C:\Windows\system32\USER32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : GDI32.dll
    Base Address : 0x775D0000
    Module Size : 0x0004B000
    Version : 6.0.6001.18159 (vistasp1_gdr.081020-1655)
    Description : GDI Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 10/21/2008 12:25:18 AM
    File Size : 296,960
    Filename : C:\Windows\system32\GDI32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ADVAPI32.dll
    Base Address : 0x76170000
    Module Size : 0x000C6000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Advanced Windows 32 Base API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:44 PM
    File Size : 798,720
    Filename : C:\Windows\system32\ADVAPI32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : RPCRT4.dll
    Base Address : 0x760A0000
    Module Size : 0x000C2000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Remote Procedure Call Runtime
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/23/2009 7:43:04 AM
    File Size : 784,896
    Filename : C:\Windows\system32\RPCRT4.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : IMM32.DLL
    Base Address : 0x76240000
    Module Size : 0x0001E000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Multi-User Windows IMM32 API Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:34 PM
    File Size : 114,688
    Filename : C:\Windows\system32\IMM32.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : MSCTF.dll
    Base Address : 0x77820000
    Module Size : 0x000C8000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : MSCTF Server DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:56 PM
    File Size : 806,912
    Filename : C:\Windows\system32\MSCTF.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : msvcrt.dll
    Base Address : 0x77770000
    Module Size : 0x000AA000
    Version : 7.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows NT CRT DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:35:16 PM
    File Size : 680,448
    Filename : C:\Windows\system32\msvcrt.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINMM.dll
    Base Address : 0x74770000
    Module Size : 0x00032000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : MCI API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:56 PM
    File Size : 189,952
    Filename : C:\Windows\system32\WINMM.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ole32.dll
    Base Address : 0x77620000
    Module Size : 0x00144000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Microsoft OLE for Windows
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:02 PM
    File Size : 1,315,328
    Filename : C:\Windows\system32\ole32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : OLEAUT32.dll
    Base Address : 0x77AC0000
    Module Size : 0x0008D000
    Version : 6.0.6001.18000
    Description :
    Company : Microsoft Corporation
    Product Name :
    Modified Date : 1/18/2008 11:36:02 PM
    File Size : 563,200
    Filename : C:\Windows\system32\OLEAUT32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : OLEACC.dll
    Base Address : 0x74730000
    Module Size : 0x00039000
    Version : 4.2.5406.0 (longhorn_rtm.080118-1840)
    Description : Active Accessibility Core Component
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:02 PM
    File Size : 215,040
    Filename : C:\Windows\system32\OLEACC.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : DDRAW.dll
    Base Address : 0x70BB0000
    Module Size : 0x000E5000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Microsoft DirectDraw
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:04 PM
    File Size : 522,752
    Filename : C:\Windows\system32\DDRAW.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : DCIMAN32.dll
    Base Address : 0x74490000
    Module Size : 0x00006000
    Version : 6.0.6001.18272 (vistasp1_gdr.090615-0258)
    Description : DCI Manager
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 6/15/2009 10:20:00 AM
    File Size : 10,240
    Filename : C:\Windows\system32\DCIMAN32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SETUPAPI.dll
    Base Address : 0x76610000
    Module Size : 0x0018A000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows Setup API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:26 PM
    File Size : 1,590,272
    Filename : C:\Windows\system32\SETUPAPI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : dwmapi.dll
    Base Address : 0x728C0000
    Module Size : 0x0000C000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft Desktop Window Manager API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:08 PM
    File Size : 39,936
    Filename : C:\Windows\system32\dwmapi.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ShimEng.dll
    Base Address : 0x745A0000
    Module Size : 0x0001E000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Shim Engine DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:13 AM
    File Size : 111,104
    Filename : C:\Windows\system32\ShimEng.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : apphelp.dll
    Base Address : 0x75D20000
    Module Size : 0x0002C000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Application Compatibility Client Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:44 PM
    File Size : 171,008
    Filename : C:\Windows\system32\apphelp.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : AcGenral.DLL
    Base Address : 0x68E70000
    Module Size : 0x00213000
    Version : 6.0.6001.18165 (vistasp1_gdr.081031-1507)
    Description : Windows Compatibility DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 10/31/2008 10:44:34 PM
    File Size : 2,154,496
    Filename : C:\Windows\AppPatch\AcGenral.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SHLWAPI.dll
    Base Address : 0x76530000
    Module Size : 0x00058000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Shell Light-weight Utility Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:30 PM
    File Size : 351,744
    Filename : C:\Windows\system32\SHLWAPI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : UxTheme.dll
    Base Address : 0x750E0000
    Module Size : 0x0003F000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Microsoft UxTheme Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:48 PM
    File Size : 240,128
    Filename : C:\Windows\system32\UxTheme.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : NETAPI32.dll
    Base Address : 0x75C50000
    Module Size : 0x00075000
    Version : 6.0.6001.18157 (vistasp1_gdr.081015-1604)
    Description : Net Win32 API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 10/15/2008 11:47:33 PM
    File Size : 466,944
    Filename : C:\Windows\system32\NETAPI32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : PSAPI.DLL
    Base Address : 0x77A20000
    Module Size : 0x00007000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Process Status Helper
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:12 AM
    File Size : 12,288
    Filename : C:\Windows\system32\PSAPI.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : MSACM32.dll
    Base Address : 0x716E0000
    Module Size : 0x00014000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Microsoft ACM Audio Filter
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:56 PM
    File Size : 71,680
    Filename : C:\Windows\system32\MSACM32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : VERSION.dll
    Base Address : 0x75290000
    Module Size : 0x00008000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Version Checking and File Installation Libraries
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:48 PM
    File Size : 20,480
    Filename : C:\Windows\system32\VERSION.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SHELL32.dll
    Base Address : 0x76840000
    Module Size : 0x00B10000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows Shell Common Dll
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/6/2008 8:14:25 AM
    File Size : 11,580,928
    Filename : C:\Windows\system32\SHELL32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : sfc.dll
    Base Address : 0x72670000
    Module Size : 0x00005000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows File Protection
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:13 AM
    File Size : 4,608
    Filename : C:\Windows\system32\sfc.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : sfc_os.DLL
    Base Address : 0x71DE0000
    Module Size : 0x0000D000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows File Protection
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:26 PM
    File Size : 38,912
    Filename : C:\Windows\system32\sfc_os.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : USERENV.dll
    Base Address : 0x75E50000
    Module Size : 0x0001E000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Userenv
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:48 PM
    File Size : 108,032
    Filename : C:\Windows\System32\USERENV.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : Secur32.dll
    Base Address : 0x75E30000
    Module Size : 0x00014000
    Version : 6.0.6001.18272 (vistasp1_gdr.090615-0258)
    Description : Security Support Provider Interface
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 6/15/2009 10:24:05 AM
    File Size : 72,704
    Filename : C:\Windows\System32\Secur32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : urlmon.dll
    Base Address : 0x77490000
    Module Size : 0x00132000
    Version : 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
    Description : OLE32 Extensions for Win32
    Company : Microsoft Corporation
    Product Name : Windows® Internet Explorer
    Modified Date : 7/21/2009 4:52:13 PM
    File Size : 1,208,832
    Filename : C:\Windows\system32\urlmon.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : iertutil.dll
    Base Address : 0x76340000
    Module Size : 0x001E8000
    Version : 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
    Description : Run time utility for Internet Explorer
    Company : Microsoft Corporation
    Product Name : Windows® Internet Explorer
    Modified Date : 7/21/2009 4:47:27 PM
    File Size : 1,985,536
    Filename : C:\Windows\system32\iertutil.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : MPR.dll
    Base Address : 0x759C0000
    Module Size : 0x00014000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Multiple Provider Router DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:54 PM
    File Size : 68,608
    Filename : C:\Windows\system32\MPR.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : AcLayers.DLL
    Base Address : 0x74090000
    Module Size : 0x00088000
    Version : 6.0.6001.18165 (vistasp1_gdr.081031-1507)
    Description : Windows Compatibility DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 10/31/2008 10:44:34 PM
    File Size : 541,696
    Filename : C:\Windows\AppPatch\AcLayers.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINSPOOL.DRV
    Base Address : 0x74550000
    Module Size : 0x00042000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows Spooler Driver
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:32:58 PM
    File Size : 258,048
    Filename : C:\Windows\system32\WINSPOOL.DRV
    File Attributes : A
    ==================================================


    Post character limit, will have to make a 2nd post to post the rest.

  6. #206
    Salvage Bans
    Join Date
    Jun 2006
    Posts
    829
    BG Level
    5

    Continued from previous post:

    Spoiler: show

    ==================================================
    Module Name : LPK.DLL
    Base Address : 0x77A40000
    Module Size : 0x00009000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Language Pack
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:44 PM
    File Size : 23,552
    Filename : C:\Windows\system32\LPK.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : USP10.dll
    Base Address : 0x76590000
    Module Size : 0x0007D000
    Version : 1.0626.6001.18000 (longhorn_rtm.080118-1840)
    Description : Uniscribe Unicode script processor
    Company : Microsoft Corporation
    Product Name : Microsoft(R) Uniscribe Unicode script processor
    Modified Date : 1/18/2008 11:36:48 PM
    File Size : 501,760
    Filename : C:\Windows\system32\USP10.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : comctl32.dll
    Base Address : 0x74F00000
    Module Size : 0x0019E000
    Version : 6.10 (longhorn_rtm.080118-1840)
    Description : User Experience Controls Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:26:36 PM
    File Size : 1,684,480
    Filename : C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdb aa5a083979cc\comctl32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : Hook.dll
    Base Address : 0x02600000
    Module Size : 0x001AF000
    Version : 3, 4, 1, 0
    Description : Windower Hook
    Company : Windower Development Team
    Product Name : Windower
    Modified Date : 10/31/2008 1:57:46 AM
    File Size : 1,678,336
    Filename : C:\Program Files\Archbell\Hook.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : CLBCatQ.DLL
    Base Address : 0x76010000
    Module Size : 0x00084000
    Version : 2001.12.6931.18000 (longhorn_rtm.080118-1840)
    Description : COM+ Configuration Catalog
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:54 PM
    File Size : 523,776
    Filename : C:\Windows\system32\CLBCatQ.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : rsaenh.dll
    Base Address : 0x75340000
    Module Size : 0x0003B000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft Enhanced Cryptographic Provider
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:38:04 PM
    File Size : 242,744
    Filename : C:\Windows\system32\rsaenh.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : winbrand.dll
    Base Address : 0x75400000
    Module Size : 0x000D7000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows Branding Resources
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:13 AM
    File Size : 869,376
    Filename : C:\Windows\system32\winbrand.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : dsound.dll
    Base Address : 0x703E0000
    Module Size : 0x00070000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DirectSound
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:08 PM
    File Size : 444,416
    Filename : C:\Windows\system32\dsound.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : POWRPROF.dll
    Base Address : 0x752A0000
    Module Size : 0x0001A000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Power Profile Helper DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:08 PM
    File Size : 97,280
    Filename : C:\Windows\system32\POWRPROF.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : msiltcfg.dll
    Base Address : 0x71FB0000
    Module Size : 0x00007000
    Version : 4.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows Installer Configuration API Stub
    Company : Microsoft Corporation
    Product Name : Windows Installer - Unicode
    Modified Date : 11/2/2006 4:46:07 AM
    File Size : 15,872
    Filename : C:\Windows\system32\msiltcfg.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : msi.dll
    Base Address : 0x73BB0000
    Module Size : 0x00202000
    Version : 4.0.6001.18000
    Description : Windows Installer
    Company : Microsoft Corporation
    Product Name : Windows Installer - Unicode
    Modified Date : 1/18/2008 11:35:12 PM
    File Size : 2,085,888
    Filename : C:\Windows\system32\msi.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : polcore.dll
    Base Address : 0x02EA0000
    Module Size : 0x00451000
    Version : 1.18.12
    Description : PlayOnline Viewer POLCore Module
    Company : SQUARE ENIX CO., LTD.
    Product Name : PlayOnline Viewer
    Modified Date : 4/17/2009 12:56:49 PM
    File Size : 547,328
    Filename : C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\polcore.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : DINPUT8.dll
    Base Address : 0x6EA50000
    Module Size : 0x00033000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Microsoft DirectInput
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:06 PM
    File Size : 159,232
    Filename : C:\Windows\system32\DINPUT8.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WS2_32.dll
    Base Address : 0x77A90000
    Module Size : 0x0002D000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows Socket 2.0 32-Bit DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:37:10 PM
    File Size : 179,200
    Filename : C:\Windows\system32\WS2_32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : NSI.dll
    Base Address : 0x77A50000
    Module Size : 0x00006000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : NSI User-mode interface DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:35:58 PM
    File Size : 8,192
    Filename : C:\Windows\system32\NSI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : HID.DLL
    Base Address : 0x74960000
    Module Size : 0x00009000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Hid User Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:05 AM
    File Size : 22,016
    Filename : C:\Windows\system32\HID.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : app.dll
    Base Address : 0x03CE0000
    Module Size : 0x00B7B000
    Version : 1.18.12
    Description : PlayOnline Viewer App Module
    Company : SQUARE ENIX CO., LTD.
    Product Name : PlayOnline Viewer
    Modified Date : 4/17/2009 12:56:51 PM
    File Size : 4,320,256
    Filename : C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\app.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : IPHLPAPI.DLL
    Base Address : 0x75810000
    Module Size : 0x00019000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : IP Helper API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:36 PM
    File Size : 91,648
    Filename : C:\Windows\system32\IPHLPAPI.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : dhcpcsvc.DLL
    Base Address : 0x757D0000
    Module Size : 0x00035000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DHCP Client Service
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:04 PM
    File Size : 204,288
    Filename : C:\Windows\system32\dhcpcsvc.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : DNSAPI.dll
    Base Address : 0x75A60000
    Module Size : 0x0002C000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DNS Client API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:06 PM
    File Size : 165,888
    Filename : C:\Windows\system32\DNSAPI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINNSI.DLL
    Base Address : 0x757C0000
    Module Size : 0x00007000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Network Store Information RPC interface
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:56 PM
    File Size : 14,848
    Filename : C:\Windows\system32\WINNSI.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : dhcpcsvc6.DLL
    Base Address : 0x75790000
    Module Size : 0x00021000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DHCPv6 Client
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:04 PM
    File Size : 128,000
    Filename : C:\Windows\system32\dhcpcsvc6.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINTRUST.dll
    Base Address : 0x74AE0000
    Module Size : 0x0002D000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft Trust Verification APIs
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:58 PM
    File Size : 171,520
    Filename : C:\Windows\System32\WINTRUST.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : CRYPT32.dll
    Base Address : 0x758C0000
    Module Size : 0x000F1000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Crypto API32
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:02 PM
    File Size : 977,408
    Filename : C:\Windows\System32\CRYPT32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : MSASN1.dll
    Base Address : 0x75A20000
    Module Size : 0x00012000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : ASN.1 Runtime APIs
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:06 AM
    File Size : 59,904
    Filename : C:\Windows\System32\MSASN1.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : imagehlp.dll
    Base Address : 0x77A60000
    Module Size : 0x00029000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows NT Image Helper
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:34 PM
    File Size : 153,088
    Filename : C:\Windows\system32\imagehlp.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : NTMARTA.DLL
    Base Address : 0x752C0000
    Module Size : 0x00021000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows NT MARTA provider
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:00 PM
    File Size : 121,344
    Filename : C:\Windows\system32\NTMARTA.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WLDAP32.dll
    Base Address : 0x77350000
    Module Size : 0x0004A000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Win32 LDAP API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:58 PM
    File Size : 289,280
    Filename : C:\Windows\system32\WLDAP32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SAMLIB.dll
    Base Address : 0x75A40000
    Module Size : 0x00011000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : SAM Library DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:20 PM
    File Size : 57,344
    Filename : C:\Windows\system32\SAMLIB.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : nvd3dum.dll
    Base Address : 0x04860000
    Module Size : 0x005E6000
    Version : 7.15.11.8250
    Description : NVIDIA Compatible Vista WDDM D3D Driver, Version 182.50
    Company : NVIDIA Corporation
    Product Name : NVIDIA Windows Vista WDDM driver
    Modified Date : 3/27/2009 10:03:00 AM
    File Size : 6,082,560
    Filename : C:\Windows\system32\nvd3dum.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ncrypt.dll
    Base Address : 0x75730000
    Module Size : 0x00035000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows cryptographic library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:35:36 PM
    File Size : 204,288
    Filename : C:\Windows\system32\ncrypt.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : BCRYPT.dll
    Base Address : 0x756E0000
    Module Size : 0x00045000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows Cryptographic Primitives Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:48 PM
    File Size : 274,432
    Filename : C:\Windows\system32\BCRYPT.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : GPAPI.dll
    Base Address : 0x75320000
    Module Size : 0x00015000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Group Policy Client API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:24 PM
    File Size : 75,264
    Filename : C:\Windows\system32\GPAPI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : slc.dll
    Base Address : 0x75880000
    Module Size : 0x0003A000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Software Licensing Client Dll
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:12 PM
    File Size : 225,792
    Filename : C:\Windows\system32\slc.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : cryptnet.dll
    Base Address : 0x6D9F0000
    Module Size : 0x0001B000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Crypto Network Related API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:02 PM
    File Size : 97,792
    Filename : C:\Windows\system32\cryptnet.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SensApi.dll
    Base Address : 0x71C60000
    Module Size : 0x00006000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : SENS Connectivity API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:12 AM
    File Size : 8,704
    Filename : C:\Windows\system32\SensApi.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : Cabinet.dll
    Base Address : 0x74C10000
    Module Size : 0x00015000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft® Cabinet File API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:50 PM
    File Size : 71,680
    Filename : C:\Windows\system32\Cabinet.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : D3DIM700.DLL
    Base Address : 0x6C640000
    Module Size : 0x000CC000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft Direct3D
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:02 PM
    File Size : 816,128
    Filename : C:\Windows\system32\D3DIM700.DLL
    File Attributes : A
    ==================================================



    HijackThis:

    Spoiler: show

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:07:24 AM, on 8/24/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18813)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\DNA\btdna.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SndVol.exe
    C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    C:\Windows\System32\calc.exe
    C:\Users\Peter\Downloads\showmodules.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e" -launchedbylogin
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O13 - Gopher Prefix:
    O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
    O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe

    --
    End of file - 5461 bytes

  7. #207
    Brown Recluse
    Sweaty Dick Punching Enthusiast

    Join Date
    May 2006
    Posts
    26,982
    BG Level
    10
    FFXI Server
    Unicorn

    Quote Originally Posted by tarumalphius View Post
    Just found this linked on slashdot...don't know if it has been mentioned yet but I didn't see it so here ya go:

    How Hackers Snatch Real-Time Security ID Numbers - Bits Blog - NYTimes.com

    Basically says there are now realtime keyloggers...your token is useless.
    So are we at a greater risk using the tokens? Will Hackers be looking for token usage and prey on those people?

  8. #208
    Mithra Ero-Sensei
    Sex Manthra

    Join Date
    Nov 2005
    Posts
    11,547
    BG Level
    9
    FFXIV Character
    Erosensei Gulkeeva
    FFXIV Server
    Gilgamesh
    FFXI Server
    Cerberus
    WoW Realm
    Magtheridon

    Quote Originally Posted by Jotaru View Post
    they'd still get relative motion

    I had my password emailed to me in a mumbo jumbo mix of about 500 characters, and would copy+paste just the 6 that were my password into the box. Win.
    http://www.neko-sentai.com/images6sr1/1.jpg
    http://www.neko-sentai.com/images6sr1/3.jpg
    http://www.neko-sentai.com/images6sr1/4.jpg

    Programs out there can easily see what you do, they can be set to take "screenshots" of what you do, even video record

  9. #209
    New Odin
    Join Date
    Jul 2006
    Posts
    8,664
    BG Level
    8
    FFXIV Character
    Sparthia Abysseant
    FFXIV Server
    Excalibur
    FFXI Server
    Lakshmi

    Quote Originally Posted by Spekkio
    SE needs to stop thinking of account restoration like they do item restoration: a favor. they're not doing us a favor. they're not being nice. they're doing their JOB to keep us paying them. if i'd lost every sellable item on my account and every gil in my inventory and i couldn't get it restored, i'm done. i have a relic horn, i could continue playing with nothing more than that, but i think i'd feel so sickly violated by both the RMT and SE's inaction that i'd just cut my losses and give up.

    players who have been attacked once and had their accounts rolled back should not be forced to live in fear that the next compromise of their account becomes terminal. players who have just been attacked the first time should not have to be concerned if their account will be returned to them or if SE will simply declare without recourse that they didn't feel there was enough evidence and dismiss the player. when SE realizes that they can't blame the victim (no matter how many of the victims carelessly use IE) we'll be in a much better place.
    It may be time that SE considers amending the one time restore policy to multiple times depending on situation.

    Im sure the counter-argument would be that SE would then have people crying wolf multiple times in an attempt to profit but is that worth leaving your entire playerbase out in the cold?

    It isn't like SE treats you well during the entire restore process (calls arent toll-free, you have to sit on hold possibly for hours, restore process could take months etc) but the option to restore (for people that have been restored once before) after something new pops up and ganks some people before preventative measures arise would be a step in the right direction.

    The playerbase is now on the forefront of a 4-pronged attack:

    -RMT tells offering to sell gil
    -RMT ads offering to buy gil
    -SE phantom bans
    -Phishing /tells

    Let's add:
    -Smash and grab RMT tactics

    I really don't want to see what this holiday season holds in store for the players....what's next?

  10. #210
    New Spam Forum
    Join Date
    Aug 2008
    Posts
    161
    BG Level
    3
    FFXI Server
    Sylph

    So has there been enough information given by the people claiming to have been hacked so far to find a common link between them all? Can't really blame IE if people are being hit with firefox + noscript. Maybe people are forgetting they visited websites they might have added permissions to. =(

    I hate this paranoid feeling of sitting here at school with nothing to do with my modem plugged in at home and a good portion of my LS bank just sitting there waiting to be taken away by god knows what.

    I'm still somewhat a skeptic and think this could just be a joke that's gone out of hand, because I simply can not believe SE would not even post that they are investigating the issue. As much as people might like to complain about poor customer service, I can not imagine anybody letting a major security flaw like this go on unanswered.

  11. #211
    Sea Torques
    Join Date
    Oct 2006
    Posts
    731
    BG Level
    5

    Quote Originally Posted by Dimmauk View Post
    So are we at a greater risk using the tokens? Will Hackers be looking for token usage and prey on those people?
    No because the same keylogger will work whether or not you have a token. Plus the token restricts them to only stealing your sellable items and gil rather than your entire account.

    Plus if it's real time keylogging, you can prevent a hack by not logging back in after they boot you from ffxi.

  12. #212
    New Spam Forum
    Join Date
    Oct 2006
    Posts
    188
    BG Level
    3
    FFXI Server
    Phoenix

    I would imagine that the paranoid could always just attempt to log in to their accounts twice as a counter measure to this. Once with an incorrect one time password and then with a correct one time password after assuring that their POL doesn't crash.

    The technology SE *bought* for their game has been considered good enough for the banking industry for quite some time so badmouthing SE is rather lame. Clearly this type of attack is brand new and aimed specifically at circumventing security token technology.

  13. #213
    Relic Shield
    Join Date
    Oct 2006
    Posts
    1,600
    BG Level
    6
    FFXI Server
    Odin

    Quote Originally Posted by Narse View Post
    Continued from previous post:

    Spoiler: show

    ==================================================
    Module Name : LPK.DLL
    Base Address : 0x77A40000
    Module Size : 0x00009000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Language Pack
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:44 PM
    File Size : 23,552
    Filename : C:\Windows\system32\LPK.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : USP10.dll
    Base Address : 0x76590000
    Module Size : 0x0007D000
    Version : 1.0626.6001.18000 (longhorn_rtm.080118-1840)
    Description : Uniscribe Unicode script processor
    Company : Microsoft Corporation
    Product Name : Microsoft(R) Uniscribe Unicode script processor
    Modified Date : 1/18/2008 11:36:48 PM
    File Size : 501,760
    Filename : C:\Windows\system32\USP10.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : comctl32.dll
    Base Address : 0x74F00000
    Module Size : 0x0019E000
    Version : 6.10 (longhorn_rtm.080118-1840)
    Description : User Experience Controls Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:26:36 PM
    File Size : 1,684,480
    Filename : C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdb aa5a083979cc\comctl32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : Hook.dll
    Base Address : 0x02600000
    Module Size : 0x001AF000
    Version : 3, 4, 1, 0
    Description : Windower Hook
    Company : Windower Development Team
    Product Name : Windower
    Modified Date : 10/31/2008 1:57:46 AM
    File Size : 1,678,336
    Filename : C:\Program Files\Archbell\Hook.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : CLBCatQ.DLL
    Base Address : 0x76010000
    Module Size : 0x00084000
    Version : 2001.12.6931.18000 (longhorn_rtm.080118-1840)
    Description : COM+ Configuration Catalog
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:54 PM
    File Size : 523,776
    Filename : C:\Windows\system32\CLBCatQ.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : rsaenh.dll
    Base Address : 0x75340000
    Module Size : 0x0003B000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft Enhanced Cryptographic Provider
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:38:04 PM
    File Size : 242,744
    Filename : C:\Windows\system32\rsaenh.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : winbrand.dll
    Base Address : 0x75400000
    Module Size : 0x000D7000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows Branding Resources
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:13 AM
    File Size : 869,376
    Filename : C:\Windows\system32\winbrand.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : dsound.dll
    Base Address : 0x703E0000
    Module Size : 0x00070000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DirectSound
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:08 PM
    File Size : 444,416
    Filename : C:\Windows\system32\dsound.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : POWRPROF.dll
    Base Address : 0x752A0000
    Module Size : 0x0001A000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Power Profile Helper DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:08 PM
    File Size : 97,280
    Filename : C:\Windows\system32\POWRPROF.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : msiltcfg.dll
    Base Address : 0x71FB0000
    Module Size : 0x00007000
    Version : 4.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows Installer Configuration API Stub
    Company : Microsoft Corporation
    Product Name : Windows Installer - Unicode
    Modified Date : 11/2/2006 4:46:07 AM
    File Size : 15,872
    Filename : C:\Windows\system32\msiltcfg.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : msi.dll
    Base Address : 0x73BB0000
    Module Size : 0x00202000
    Version : 4.0.6001.18000
    Description : Windows Installer
    Company : Microsoft Corporation
    Product Name : Windows Installer - Unicode
    Modified Date : 1/18/2008 11:35:12 PM
    File Size : 2,085,888
    Filename : C:\Windows\system32\msi.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : polcore.dll
    Base Address : 0x02EA0000
    Module Size : 0x00451000
    Version : 1.18.12
    Description : PlayOnline Viewer POLCore Module
    Company : SQUARE ENIX CO., LTD.
    Product Name : PlayOnline Viewer
    Modified Date : 4/17/2009 12:56:49 PM
    File Size : 547,328
    Filename : C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\polcore.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : DINPUT8.dll
    Base Address : 0x6EA50000
    Module Size : 0x00033000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Microsoft DirectInput
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:06 PM
    File Size : 159,232
    Filename : C:\Windows\system32\DINPUT8.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WS2_32.dll
    Base Address : 0x77A90000
    Module Size : 0x0002D000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows Socket 2.0 32-Bit DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:37:10 PM
    File Size : 179,200
    Filename : C:\Windows\system32\WS2_32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : NSI.dll
    Base Address : 0x77A50000
    Module Size : 0x00006000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : NSI User-mode interface DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:35:58 PM
    File Size : 8,192
    Filename : C:\Windows\system32\NSI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : HID.DLL
    Base Address : 0x74960000
    Module Size : 0x00009000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Hid User Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:05 AM
    File Size : 22,016
    Filename : C:\Windows\system32\HID.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : app.dll
    Base Address : 0x03CE0000
    Module Size : 0x00B7B000
    Version : 1.18.12
    Description : PlayOnline Viewer App Module
    Company : SQUARE ENIX CO., LTD.
    Product Name : PlayOnline Viewer
    Modified Date : 4/17/2009 12:56:51 PM
    File Size : 4,320,256
    Filename : C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\app.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : IPHLPAPI.DLL
    Base Address : 0x75810000
    Module Size : 0x00019000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : IP Helper API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:36 PM
    File Size : 91,648
    Filename : C:\Windows\system32\IPHLPAPI.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : dhcpcsvc.DLL
    Base Address : 0x757D0000
    Module Size : 0x00035000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DHCP Client Service
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:04 PM
    File Size : 204,288
    Filename : C:\Windows\system32\dhcpcsvc.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : DNSAPI.dll
    Base Address : 0x75A60000
    Module Size : 0x0002C000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DNS Client API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:06 PM
    File Size : 165,888
    Filename : C:\Windows\system32\DNSAPI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINNSI.DLL
    Base Address : 0x757C0000
    Module Size : 0x00007000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Network Store Information RPC interface
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:56 PM
    File Size : 14,848
    Filename : C:\Windows\system32\WINNSI.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : dhcpcsvc6.DLL
    Base Address : 0x75790000
    Module Size : 0x00021000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : DHCPv6 Client
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:04 PM
    File Size : 128,000
    Filename : C:\Windows\system32\dhcpcsvc6.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINTRUST.dll
    Base Address : 0x74AE0000
    Module Size : 0x0002D000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft Trust Verification APIs
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:58 PM
    File Size : 171,520
    Filename : C:\Windows\System32\WINTRUST.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : CRYPT32.dll
    Base Address : 0x758C0000
    Module Size : 0x000F1000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Crypto API32
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:02 PM
    File Size : 977,408
    Filename : C:\Windows\System32\CRYPT32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : MSASN1.dll
    Base Address : 0x75A20000
    Module Size : 0x00012000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : ASN.1 Runtime APIs
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:06 AM
    File Size : 59,904
    Filename : C:\Windows\System32\MSASN1.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : imagehlp.dll
    Base Address : 0x77A60000
    Module Size : 0x00029000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows NT Image Helper
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:34 PM
    File Size : 153,088
    Filename : C:\Windows\system32\imagehlp.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : NTMARTA.DLL
    Base Address : 0x752C0000
    Module Size : 0x00021000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Windows NT MARTA provider
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:00 PM
    File Size : 121,344
    Filename : C:\Windows\system32\NTMARTA.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WLDAP32.dll
    Base Address : 0x77350000
    Module Size : 0x0004A000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Win32 LDAP API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:58 PM
    File Size : 289,280
    Filename : C:\Windows\system32\WLDAP32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SAMLIB.dll
    Base Address : 0x75A40000
    Module Size : 0x00011000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : SAM Library DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:20 PM
    File Size : 57,344
    Filename : C:\Windows\system32\SAMLIB.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : nvd3dum.dll
    Base Address : 0x04860000
    Module Size : 0x005E6000
    Version : 7.15.11.8250
    Description : NVIDIA Compatible Vista WDDM D3D Driver, Version 182.50
    Company : NVIDIA Corporation
    Product Name : NVIDIA Windows Vista WDDM driver
    Modified Date : 3/27/2009 10:03:00 AM
    File Size : 6,082,560
    Filename : C:\Windows\system32\nvd3dum.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ncrypt.dll
    Base Address : 0x75730000
    Module Size : 0x00035000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows cryptographic library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:35:36 PM
    File Size : 204,288
    Filename : C:\Windows\system32\ncrypt.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : BCRYPT.dll
    Base Address : 0x756E0000
    Module Size : 0x00045000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Windows Cryptographic Primitives Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:48 PM
    File Size : 274,432
    Filename : C:\Windows\system32\BCRYPT.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : GPAPI.dll
    Base Address : 0x75320000
    Module Size : 0x00015000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : Group Policy Client API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:24 PM
    File Size : 75,264
    Filename : C:\Windows\system32\GPAPI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : slc.dll
    Base Address : 0x75880000
    Module Size : 0x0003A000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Software Licensing Client Dll
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:36:12 PM
    File Size : 225,792
    Filename : C:\Windows\system32\slc.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : cryptnet.dll
    Base Address : 0x6D9F0000
    Module Size : 0x0001B000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Crypto Network Related API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:02 PM
    File Size : 97,792
    Filename : C:\Windows\system32\cryptnet.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SensApi.dll
    Base Address : 0x71C60000
    Module Size : 0x00006000
    Version : 6.0.6000.16386 (vista_rtm.061101-2205)
    Description : SENS Connectivity API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 11/2/2006 4:46:12 AM
    File Size : 8,704
    Filename : C:\Windows\system32\SensApi.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : Cabinet.dll
    Base Address : 0x74C10000
    Module Size : 0x00015000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft® Cabinet File API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:33:50 PM
    File Size : 71,680
    Filename : C:\Windows\system32\Cabinet.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : D3DIM700.DLL
    Base Address : 0x6C640000
    Module Size : 0x000CC000
    Version : 6.0.6001.18000 (longhorn_rtm.080118-1840)
    Description : Microsoft Direct3D
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 1/18/2008 11:34:02 PM
    File Size : 816,128
    Filename : C:\Windows\system32\D3DIM700.DLL
    File Attributes : A
    ==================================================



    HijackThis:

    Spoiler: show

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:07:24 AM, on 8/24/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18813)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\DNA\btdna.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SndVol.exe
    C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    C:\Windows\System32\calc.exe
    C:\Users\Peter\Downloads\showmodules.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e" -launchedbylogin
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O13 - Gopher Prefix:
    O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
    O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
    O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe

    --
    End of file - 5461 bytes

    nothing sticks out to me...

  14. #214
    New Spam Forum
    Join Date
    Jul 2008
    Posts
    153
    BG Level
    3

    If we say his name three times will he appear?

    hmm....

    It seems a third possibility for the end of ffxi has arisen.

    I certainly hope individuals that are being hacked and have used their "one time rollback/restore" are not considering buying gil in order to repurchase their items. I suppose that would complete the cycle.

  15. #215
    Salvage Bans
    Join Date
    Jun 2006
    Posts
    829
    BG Level
    5

    Second system, Windows XP 32 bit

    CurrProcess:

    Spoiler: show

    ==================================================
    Module Name : AcGenral.DLL
    Base Address : 0x6F880000
    Module Size : 0x001CA000
    Version : 5.1.2600.5512 (xpsp.080413-2105)
    Description : Windows Compatibility DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:11:48 PM
    File Size : 1,852,928
    Filename : C:\WINDOWS\AppPatch\AcGenral.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ADVAPI32.dll
    Base Address : 0x77DD0000
    Module Size : 0x0009B000
    Version : 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)
    Description : Advanced Windows 32 Base API
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 2/9/2009 7:10:48 AM
    File Size : 617,472
    Filename : C:\WINDOWS\system32\ADVAPI32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : comctl32.dll
    Base Address : 0x773D0000
    Module Size : 0x00103000
    Version : 6.0 (xpsp.080413-2105)
    Description : User Experience Controls Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:51 PM
    File Size : 1,054,208
    Filename : C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : comdlg32.dll
    Base Address : 0x763B0000
    Module Size : 0x00049000
    Version : 6.00.2900.5512 (xpsp.080413-2105)
    Description : Common Dialogs DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:11:51 PM
    File Size : 276,992
    Filename : C:\WINDOWS\system32\comdlg32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : GDI32.dll
    Base Address : 0x77F10000
    Module Size : 0x00049000
    Version : 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932)
    Description : GDI Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 10/23/2008 7:36:14 AM
    File Size : 286,720
    Filename : C:\WINDOWS\system32\GDI32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : IMM32.DLL
    Base Address : 0x76390000
    Module Size : 0x0001D000
    Version : 5.1.2600.5512 (xpsp.080413-2105)
    Description : Windows XP IMM32 API Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:11:54 PM
    File Size : 110,080
    Filename : C:\WINDOWS\system32\IMM32.DLL
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : kernel32.dll
    Base Address : 0x7C800000
    Module Size : 0x000F6000
    Version : 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317)
    Description : Windows NT BASE API Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 3/21/2009 9:06:58 AM
    File Size : 989,696
    Filename : C:\WINDOWS\system32\kernel32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : MSACM32.dll
    Base Address : 0x77BE0000
    Module Size : 0x00015000
    Version : 5.1.2600.5512 (xpsp.080413-0845)
    Description : Microsoft ACM Audio Filter
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:11:58 PM
    File Size : 71,680
    Filename : C:\WINDOWS\System32\MSACM32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : msvcrt.dll
    Base Address : 0x77C10000
    Module Size : 0x00058000
    Version : 7.0.2600.5512 (xpsp.080413-2111)
    Description : Windows NT CRT DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:01 PM
    File Size : 343,040
    Filename : C:\WINDOWS\system32\msvcrt.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : NOTEPAD.EXE
    Base Address : 0x01000000
    Module Size : 0x00014000
    Version : 5.1.2600.5512 (xpsp.080413-2105)
    Description : Notepad
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:29 PM
    File Size : 69,120
    Filename : C:\WINDOWS\system32\NOTEPAD.EXE
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ntdll.dll
    Base Address : 0x7C900000
    Module Size : 0x000B2000
    Version : 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)
    Description : NT Layer DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 2/9/2009 7:10:48 AM
    File Size : 714,752
    Filename : C:\WINDOWS\system32\ntdll.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ole32.dll
    Base Address : 0x774E0000
    Module Size : 0x0013D000
    Version : 5.1.2600.5512 (xpsp.080413-2108)
    Description : Microsoft OLE for Windows
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:02 PM
    File Size : 1,287,168
    Filename : C:\WINDOWS\system32\ole32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : OLEAUT32.dll
    Base Address : 0x77120000
    Module Size : 0x0008B000
    Version : 5.1.2600.5512
    Description :
    Company : Microsoft Corporation
    Product Name :
    Modified Date : 4/13/2008 7:12:02 PM
    File Size : 551,936
    Filename : C:\WINDOWS\system32\OLEAUT32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : RPCRT4.dll
    Base Address : 0x77E70000
    Module Size : 0x00092000
    Version : 5.1.2600.5795 (xpsp_sp3_gdr.090415-1241)
    Description : Remote Procedure Call Runtime
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/15/2009 9:51:25 AM
    File Size : 585,216
    Filename : C:\WINDOWS\system32\RPCRT4.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : Secur32.dll
    Base Address : 0x77FE0000
    Module Size : 0x00011000
    Version : 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305)
    Description : Security Support Provider Interface
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 6/25/2009 3:25:26 AM
    File Size : 56,832
    Filename : C:\WINDOWS\system32\Secur32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SHELL32.dll
    Base Address : 0x7C9C0000
    Module Size : 0x00817000
    Version : 6.00.2900.5622 (xpsp_sp3_gdr.080617-1319)
    Description : Windows Shell Common Dll
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 6/17/2008 2:02:19 PM
    File Size : 8,461,312
    Filename : C:\WINDOWS\system32\SHELL32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : ShimEng.dll
    Base Address : 0x5CB70000
    Module Size : 0x00026000
    Version : 5.1.2600.5512 (xpsp.080413-2105)
    Description : Shim Engine DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:05 PM
    File Size : 65,024
    Filename : C:\WINDOWS\System32\ShimEng.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : SHLWAPI.dll
    Base Address : 0x77F60000
    Module Size : 0x00076000
    Version : 6.00.2900.5512 (xpsp.080413-2105)
    Description : Shell Light-weight Utility Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:05 PM
    File Size : 474,112
    Filename : C:\WINDOWS\system32\SHLWAPI.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : USER32.dll
    Base Address : 0x7E410000
    Module Size : 0x00091000
    Version : 5.1.2600.5512 (xpsp.080413-2105)
    Description : Windows XP USER API Client DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:08 PM
    File Size : 578,560
    Filename : C:\WINDOWS\system32\USER32.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : USERENV.dll
    Base Address : 0x769C0000
    Module Size : 0x000B4000
    Version : 5.1.2600.5512 (xpsp.080413-2113)
    Description : Userenv
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:08 PM
    File Size : 727,040
    Filename : C:\WINDOWS\system32\USERENV.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : UxTheme.dll
    Base Address : 0x5AD70000
    Module Size : 0x00038000
    Version : 6.00.2900.5512 (xpsp.080413-2105)
    Description : Microsoft UxTheme Library
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:08 PM
    File Size : 218,624
    Filename : C:\WINDOWS\System32\UxTheme.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : VERSION.dll
    Base Address : 0x77C00000
    Module Size : 0x00008000
    Version : 5.1.2600.5512 (xpsp.080413-2105)
    Description : Version Checking and File Installation Libraries
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:08 PM
    File Size : 18,944
    Filename : C:\WINDOWS\system32\VERSION.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINMM.dll
    Base Address : 0x76B40000
    Module Size : 0x0002D000
    Version : 5.1.2600.5512 (xpsp.080413-0845)
    Description : MCI API DLL
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:09 PM
    File Size : 176,128
    Filename : C:\WINDOWS\System32\WINMM.dll
    File Attributes : A
    ==================================================

    ==================================================
    Module Name : WINSPOOL.DRV
    Base Address : 0x73000000
    Module Size : 0x00026000
    Version : 5.1.2600.5512 (xpsp.080413-0852)
    Description : Windows Spooler Driver
    Company : Microsoft Corporation
    Product Name : Microsoft® Windows® Operating System
    Modified Date : 4/13/2008 7:12:45 PM
    File Size : 146,432
    Filename : C:\WINDOWS\system32\WINSPOOL.DRV
    File Attributes : A
    ==================================================


    Post character limit, Hijackthis on another post.

  16. #216
    Salvage Bans
    Join Date
    Jun 2006
    Posts
    829
    BG Level
    5

    Hijackthis:

    Spoiler: show

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:58:22 AM, on 8/24/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Smc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Symantec AntiVirus\SmcGui.exe
    C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
    C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Trillian\trillian.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Alan\My Documents\Downloads\showmodules.exe
    C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\sw g.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
    O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUt il.exe -p
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
    O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/pote_x.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1130696462281
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1228581787796
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Smc.exe
    O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\SNAC.EXE
    O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O24 - Desktop Component 0: (no name) - C:\Documents and Settings\Alan\Desktop\Violay_left.bmp
    O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Alan\Desktop\Violay_right.bmp

    --
    End of file - 9245 bytes

  17. #217
    Melee Summoner
    Join Date
    Jun 2009
    Posts
    29
    BG Level
    1
    FFXI Server
    Quetzalcoatl

    Quote Originally Posted by Spekkio View Post
    ...
    i'd feel so sickly violated by both the RMT and SE's inaction that i'd just cut my losses and give up.

    players who have been attacked once and had their accounts rolled back should not be forced to live in fear that the next compromise of their account becomes terminal. players who have just been attacked the first time should not have to be concerned if their account will be returned to them or if SE will simply declare without recourse that they didn't feel there was enough evidence and dismiss the player. when SE realizes that they can't blame the victim (no matter how many of the victims carelessly use IE) we'll be in a much better place.
    this is where I am now, I live in fear, to the point where am thinking about setting up a computer just to play game only, no browsing or any other activities. Also super paranoid about anytime i feel like the virus is back, if my calc opens a little slower my mind is racing.

    But i also think if we are force to live in fear, then really am i really having fun anymore? I pay 30$/month to SE to provide me with entertainment, I hardly slept lastnight anxious about contacting SE monday morning. Currently i am on the path of "i'd feel so sickly violated by both the RMT and SE's inaction that i'd just cut my losses and give up." I am not having fun anymore, y play. I use FF to get away from the RL, now I am right smack back in RL with the same types of worries.

    I wonder how they deal with inflation when they restore, they pump more gils into the economy. I blame gil buyers!

  18. #218
    Aselin
    Guest

    To the one who posted their HiJack This log, remove this line:
    O1 - Hosts: ::1 localhost
    O13 - Gopher Prefix:

    I haven't found anything else in your post that raises red flags other than that.

    Though, I'm still going through it a second time to check.

  19. #219
    Salvage Bans
    Join Date
    Jun 2006
    Posts
    829
    BG Level
    5

    Quote Originally Posted by Aselin View Post
    To the one who posted their HiJack This log, remove this line:
    O1 - Hosts: ::1 localhost
    O13 - Gopher Prefix:

    I haven't found anything else in your post that raises red flags other than that.

    Though, I'm still going through it a second time to check.
    Removed it. Thanks. I Appreciate the look through.

  20. #220

    if this is sophisticated enough to hijack a session live (again, i'm guessing not, but that's the only viable method i can think of to explain the partial DC and recover effect that was described above) would it be that much of a surprise to find out that they're using RK style obfuscation techniques to avoid detection? hooking the OS kernel to hide RK processes and files has been around for a decade, but most of the prior attacks appeared to be sloppy hack jobs by an attacker with limited expertise. if instead the RMT hired "professionals" to engineer this attack, it would not surprise me if they added the usual packing/RK tricks to minimize the threat of detection.

    as for if session relocation is possible, if the above poster was able to action on their session from a different IP, that tends to indicate that it is possible to pull it off, if you can keep the server from firing a disconnect. if it's just checking for a keepalive from the original IP, either the attacker's software on the victim PC could deliver that or they might even be able to forge the keepalive to keep the session running till they can pilfer the contents of the account. without seeing any kind of connection logs, traffic capture, or anything beyond vague symptoms at this point though, this is all wild speculation.

Closed Thread
Page 11 of 47 FirstFirst ... 9 10 11 12 13 21 ... LastLast

Similar Threads

  1. What in the fuck is going on with Ancient Currency prices?
    By Avarice in forum FFXI: Everything
    Replies: 22
    Last Post: 2009-01-12, 04:21
  2. Ok what the hell is up with Roc?
    By S N K in forum FFXI: Everything
    Replies: 49
    Last Post: 2008-06-28, 21:00
  3. Oldschool players with JP Accounts & The new Expansion
    By Lyramion in forum FFXI: Everything
    Replies: 39
    Last Post: 2007-11-24, 00:31