Item Search
     
BG-Wiki Search
Page 17 of 47 FirstFirst ... 7 15 16 17 18 19 27 ... LastLast
Results 321 to 340 of 931
  1. #321
    Falcom is better than SE. Change my mind.
    Join Date
    Jun 2006
    Posts
    17,291
    BG Level
    9

    Hmm, starting to look like Ase was right about that Proxy Override line being suspicious.

  2. #322
    S N K
    Join Date
    May 2006
    Posts
    2,664
    BG Level
    7
    FFXI Server
    Sylph

    I would rather SE take the Sonomaa suggestion and ban all of China from the servers. This is really fucking stupid.

  3. #323
    An exploitable mess of a card game
    Join Date
    Sep 2008
    Posts
    13,197
    BG Level
    9
    FFXIV Character
    Gouka Mekkyaku
    FFXIV Server
    Gilgamesh
    FFXI Server
    Diabolos

    So how would I check for this on my PC? I play on PS3, but frequent Wiki for info, so it's possible for me to have w/e it is and not see the effects.

  4. #324
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    It's a paste formatting issue, it displays correctly in my log. My laptop that I "infected" purposefully to test with does not use google toolbar. I did normal format, default install of XP, fully updated it via windows update, installed Java and Flashplayer, then began testing. I'm currently in the process of reformatting the machine again to try to duplicate it.

  5. #325
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    Quote Originally Posted by Yugl View Post
    So how would I check for this on my PC? I play on PS3, but frequent Wiki for info, so it's possible for me to have w/e it is and not see the effects.
    Get a copy of Hijack this, (it's free, google is your friend), and look for the following line in the log:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local

    This is not a 100% confirmed thing, as we're still trying to figure out what it is, or where it's coming from, but it seems to be a common line in everyone who's been hacked so far.

  6. #326
    THAT MACHINE IS NOT A SIR, YOU HAVE TO CALL IT "MR. MACHINE"
    Join Date
    Jul 2006
    Posts
    1,204
    BG Level
    6
    FFXI Server
    Caitsith

    Quote Originally Posted by S N K View Post
    I would rather SE take the Sonomaa suggestion and ban all of China from the servers. This is really fucking stupid.
    Allowing us to put personal limits on what regions our accounts can be accessed from would be nice too

  7. #327
    Sandworm Swallows
    Join Date
    Jul 2008
    Posts
    7,147
    BG Level
    8

    Quote Originally Posted by Tempyst View Post
    Allowing us to put personal limits on what regions our accounts can be accessed from would be nice too
    Yeah but would that really help? For all we know these hackers could be china or canada-based. I know a good bunch of RMT live in California, too. And isn't there a way to make it look like they're interneting from somewhere in the US even if they're situated in China? If they're going so far as to hack around the tokens, I can't see how they wouldn't find a way around that too - it would be just another security measure that may or may not help, and I bet a lot of stupid people would fail at using it, too.

  8. #328
    We wear wine red on Wednesdays

    Join Date
    Sep 2006
    Posts
    2,241
    BG Level
    7
    FFXIV Character
    Marius Krieg
    FFXIV Server
    Balmung
    FFXI Server
    Fenrir

    I pretty much sit here and troll all over BG while keeping Wiki open for info on my laptop all day long, but I play on PS2.

    I just ran Hijack this and I don't have the entry (Though I did have that host something or other line that was highlighted a few posts back and got rid of, thanks for that).

    I'm gunna go through wiki a bit and run HT again. Maybe Alla too.

  9. #329
    An exploitable mess of a card game
    Join Date
    Sep 2008
    Posts
    13,197
    BG Level
    9
    FFXIV Character
    Gouka Mekkyaku
    FFXIV Server
    Gilgamesh
    FFXI Server
    Diabolos

    I only have the line with internet as one word (If I'm doing this right). Not posting the entire log in case there's personal stuff I shouldn't be posting (Someone mentioned this earlier).

  10. #330
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Yugl View Post
    I only have the line with internet as one word (If I'm doing this right). Not posting the entire log in case there's personal stuff I shouldn't be posting (Someone mentioned this earlier).
    Sorry about my question regarding that if it confused you. There was a confirmation that the space in the name was just formatting from pasting it here in the forum.

  11. #331
    Melee Summoner
    Join Date
    Feb 2008
    Posts
    29
    BG Level
    1
    FFXI Server
    Bismarck

    Hmm. I ran a HJT scan on my machine, couldn't find the suspicious line.
    I'd say I've been all over wiki the past couple of days, too.
    For reference, I'll post my HJT log:
    Spoiler: show

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:30:36 AM, on 8/25/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16850)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program

    Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
    C:\Program Files\Common Files\Symantec

    Shared\ccEvtMgr.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    F:\User Programs\Java\bin\jqs.exe
    D:\User Programs\Norton\Norton AntiVirus\navapsvc.exe
    F:\User Programs\CDBurnerXP\NMSAccessU.exe
    D:\User Programs\Norton\Norton Utilities\NPROTECT.EXE
    D:\USERPR~1\Norton\SPEEDD~1\nopdb.exe
    F:\User Programs\WindowBlinds\wbload.exe
    C:\Program Files\Microsoft SQL

    Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Common Files\Symantec Shared\Security

    Center\SymWSC.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\LTSMMSG.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\DOCUME~1\****~1.*****\LOCALS~1\Temp\{36C3918E-6F74-485

    2-88F4-C7C1ABC8E92A}\See Through Time.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\WINDOWS\System32\LVComsX.exe
    D:\User Programs\Firefox\firefox.exe
    F:\User Programs\DAP\DAP.EXE
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    F:\User Programs\Hijack This\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Search Bar =

    http://red.clientapps.yahoo.com/customize/ie/defaults/s

    b/ymsgr/*Yahoo! SearchBar Home Page
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Search Page =

    http://red.clientapps.yahoo.com/customize/ie/defaults/s

    p/ymsgr/*Yahoo!
    R0 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Start Page = Yahoo!
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Default_Page_URL =

    http://red.clientapps.yahoo.com/customize/ie/defaults/s

    tp/ymsgr*http://my.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Default_Search_URL =

    http://red.clientapps.yahoo.com/customize/ie/defaults/s

    u/ymsgr/*Yahoo!
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Search Bar =

    http://red.clientapps.yahoo.com/customize/ie/defaults/s

    b/ymsgr/*Yahoo! SearchBar Home Page
    R0 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Start Page =

    MSN.com
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\SearchURL,(Default) =

    http://red.clientapps.yahoo.com/customize/ie/defaults/s

    u/ymsgr/*Yahoo!
    R1 - HKCU\Software\Microsoft\Internet Connection

    Wizard,ShellNext =

    Product Registration

    001&ctry=00000409&os=5&src=1
    R3 - URLSearchHook: Yahoo! Toolbar -

    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    N3 - Netscape 7: user_pref("browser.startup.homepage",

    "http://home.netscape.com/bookmark/7_2/home.html");

    (C:\Documents and Settings\********\Application

    Data\Mozilla\Profiles\default\vnjknoxi.slt\prefs.j s)
    N3 - Netscape 7:

    user_pref("browser.search.defaultengine",

    "engine://D%3A%5CUSERPR%7E1%5CNETSCA%7E1%5Csearchplugin

    s%5CSBWeb_01.src"); (C:\Documents and Settings\*****\Application

    Data\Mozilla\Profiles\default\vnjknoxi.slt\prefs.j s)
    O2 - BHO: AcroIEHlprObj Class -

    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

    Files\adobe\acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Spybot-S&D IE Protection -

    {53707962-6F74-2D53-2644-206D7942484F} -

    F:\USERPR~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper -

    {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\Office

    2007\Office12\GrooveShellExtensions.dll
    O2 - BHO: Windows Live Sign-in Helper -

    {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program

    Files\Common Files\Microsoft Shared\Windows

    Live\WindowsLiveLogin.dll
    O2 - BHO: CNavExtBho Class -

    {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\User

    Programs\Norton\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper -

    {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\User

    Programs\Java\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl -

    {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\User

    Programs\Java\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Norton AntiVirus -

    {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\User

    Programs\Norton\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common

    Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common

    Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SmcService]

    D:\USERPR~1\SYGATE~1\smc.exe -startgui
    O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\User

    Programs\Java\bin\jusched.exe
    O4 - Startup: See through time.lnk = F:\User

    Programs\Gadgets\See Through Time\See Through Time.exe
    O8 - Extra context menu item: &Clean Traces - F:\User

    Programs\DAP\Privacy Package\dapcleanerie.htm
    O8 - Extra context menu item: &Download with &DAP -

    F:\User Programs\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP -

    F:\User Programs\DAP\dapextie2.htm
    O8 - Extra context menu item: E&xport to Microsoft

    Excel - res://F:\OFFICE~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Send to OneNote -

    {2670000A-7350-4f3c-8081-5663EE0C6C49} -

    F:\OFFICE~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote -

    {2670000A-7350-4f3c-8081-5663EE0C6C49} -

    F:\OFFICE~1\Office12\ONBttnIE.dll
    O9 - Extra button: Research -

    {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

    F:\OFFICE~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) -

    {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

    F:\USERPR~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy

    Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}

    - F:\USERPR~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) -

    {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

    {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet

    Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}

    (WUWebControl Class) -

    http://update.microsoft.com/windowsupdate/v6/V5Controls

    /en/x86/client/wuweb_site.cab?1188364393282
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}

    (MUWebControl Class) -

    http://www.update.microsoft.com/microsoftupdate/v6/V5Co

    ntrols/en/x86/client/muweb_site.cab?1188584585180
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}

    (MessengerStatsClient Class) -

    http://messenger.zone.msn.com/binary/MessengerStatsPACl

    ient.cab56907.cab
    O17 -

    HKLM\System\CCS\Services\Tcpip\..\{B9121C6F-1D0F-4815-9

    206-F34C327EC3F6}: NameServer = 64.136.173.8

    64.136.164.66
    O18 - Protocol: grooveLocalGWS -

    {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\Office

    2007\Office12\GrooveSystemServices.dll
    O23 - Service: ATI Smart - Unknown owner -

    C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler -

    Symantec Corporation - C:\Program

    Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision -

    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    O23 - Service: C-DillaSrv - C-Dilla Ltd -

    C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
    O23 - Service: Symantec Event Manager (ccEvtMgr) -

    Symantec Corporation - C:\Program Files\Common

    Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service

    (ccPwdSvc) - Symantec Corporation - C:\Program

    Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Creative Service for CDROM Access -

    Creative Technology Ltd -

    C:\WINDOWS\System32\CTSvcCDA.EXE
    O23 - Service: Java Quick Starter

    (JavaQuickStarterService) - Sun Microsystems, Inc. -

    F:\User Programs\Java\bin\jqs.exe
    O23 - Service: LiveUpdate - Symantec Corporation -

    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto Protect Service

    (navapsvc) - Symantec Corporation - D:\User

    Programs\Norton\Norton AntiVirus\navapsvc.exe
    O23 - Service: NMSAccessU - Unknown owner - F:\User

    Programs\CDBurnerXP\NMSAccessU.exe
    O23 - Service: Norton Unerase Protection

    (NProtectService) - Symantec Corporation - D:\User

    Programs\Norton\Norton Utilities\NPROTECT.EXE
    O23 - Service: ScriptBlocking Service (SBService) -

    Symantec Corporation -

    C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Sygate Personal Firewall Pro

    (SmcService) - Sygate Technologies, Inc. - D:\User

    Programs\Sygate Firewall\smc.exe
    O23 - Service: Symantec Network Drivers Service

    (SNDSrvc) - Symantec Corporation - C:\Program

    Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Speed Disk service - Symantec

    Corporation - D:\USERPR~1\Norton\SPEEDD~1\nopdb.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony

    Corporation - C:\Program Files\Common Files\Sony

    Shared\AVLib\SPTISRV.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec

    Corporation - C:\Program Files\Common Files\Symantec

    Shared\Security Center\SymWSC.exe
    O24 - Desktop Component 0: (no name) -


    --
    End of file - 9884 bytes



    Obviously, I use firefox only. IE is installed on this machine, but it's never at any site except microsoft updates. I don't have NoScript in firefox, but I am using AdBlock Plus. I've had it blocking pics (even the top banner on ffxiah.com) so that basically ah.com is ONLY text for me. I can't even view screenshots people posted because it blocks them all. Same on wiki, except I left the top banner on. I did, however, block the side banner ads and bottom banner ads.

    Perhaps checking sources on these banner ads on a machine that doesn't have FF installed (or any valuable data stored on it for that matter) would be a good course of action at this point. It's 5am, and I'll be in class the better part of today plus salvage when I get home, but, I'll gladly lend a hand to this issue when time permits.

    Best wishes to anyone who got robbed. If you were trying to buy gil, sorry about your shitty luck. If you weren't, I sincerely hope you get everything back. In the meantime, my suggestion is firefox only, adblock plus + noscript, with adblock plus killing most of the non-critical viewing content on wiki and ah.com (that is, banner ads, pictures, etc.).
    And, as added protection, I'd suggest Ad-Aware scans (free tool last I checked from lavasoft, google is your friend finding these things), CCleaner, Spybot S&D, and.. that's all I can think of at the moment. Hope that helps people at least avoid this mess.

  12. #332
    Cerberus
    Join Date
    Oct 2006
    Posts
    414
    BG Level
    4

    I've been doing some digging into this mysterious line ever since finding it on my secondary pc.

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local

    The interesting thing is that on mine, it showed as Internet Settings (no space between t and e), yet many posts here show it WITH space, and so do google searches, it's not just a formatting thing.

    Still, my searches have turned up empty of any threat implied by that line alone. For it to really be a sign of vulnerability it should be accompanied by a second line as well, similar to:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 127.0.0.1:8080

    The absence of such a line usually means that there is no local proxy process running.

  13. #333
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Aihree View Post
    I've been doing some digging into this mysterious line ever since finding it on my secondary pc.

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local

    The interesting thing is that on mine, it showed as Internet Settings (no space between t and e), yet many posts here show it WITH space, and so do google searches, it's not just a formatting thing.

    Still, my searches have turned up empty of any threat implied by that line alone. For it to really be a sign of vulnerability it should be accompanied by a second line as well, similar to:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 127.0.0.1:8080


    The absence of such a line usually means that there is no local proxy process running.
    Is it possible people are not including the address in their posts of HT logs because it is private info? I am referring to the 127.0.0.1:8080 you posted for example.
    As for the space being an actual part of the line vs only occurring because it was pasted and formatting broken: I brought it up because in this thread a couple people mentioned it. I am uncertain why it was ruled out, but since the person knew more about this kind of thing than I do, I accepted it.

  14. #334
    Melee Summoner
    Join Date
    Feb 2008
    Posts
    29
    BG Level
    1
    FFXI Server
    Bismarck

    After googling the line itself, I'm seeing 2 sets of possible results, one with and one without the spacing in Int ernet (Internet and Int ernet results).
    Skimming, it seems the Int ernet line is related to spyware/malware.
    See: mywebsearch problem - PC Help Forum

    It could still be a formatting issue. Since those logs are posted into forums, and google will just parse the text when performing the search, it's entirely possible we're seeing false-positives for "Int ernet" due to general copy+paste formatting issue.

    Although, in lots of instances, spyware/malware will insert something that looks completely normal, until further analyzed. In this case, we have the variance of "Internet" and "Int ernet".

    Now, I doubt randomly obtained spyware is now specifically targeting FFXI accounts, but it is highly possibly someone (RMT?) have obtained scripts already written by hackers to infect PCs with malware, and modified it to target FFXI players via community website ad banners.

  15. #335
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Sabertiger View Post
    After googling the line itself, I'm seeing 2 sets of possible results, one with and one without the spacing in Int ernet (Internet and Int ernet results).
    Skimming, it seems the Int ernet line is related to spyware/malware.
    See: mywebsearch problem - PC Help Forum

    Now, I doubt randomly obtained spyware is now specifically targeting FFXI accounts, but it is highly possibly someone (RMT?) have obtained scripts already written by hackers to infect PCs with malware, and modified it to target FFXI players via community website ad banners.

    Someone posted that the spacing was not present on their HJT log, only after pasting it into the forums, maybe others with the line can confirm this?
    Since I am bored, I will go and do a count of all the HJT logs in this thread and see how many have spacing vs none.

  16. #336
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    It's a line break problem when pasting it into the forums, heres a clip of the screenshot from my log, compare it with the break in the text in my previous post.

    http://img511.imageshack.us/img511/4595/hjtlog.png

    And I fully agree, this could be an older script/exploit adapted to deliver this new FFXI "hack" payload. It's actually pretty common in terms of internet security, they're called "variants", and sending in trojans with custom coded payloads for specific purposes is an old concept.

  17. #337
    Melee Summoner
    Join Date
    Feb 2008
    Posts
    29
    BG Level
    1
    FFXI Server
    Bismarck

    Since Aihree pretty plainly stated there was no spacing on their log, I'd lean more towards the formatting issue. It wouldn't be the first time something got jerked around while pasting into a forum. I'm also pretty sure someone stated on a recent page that their log also had no spacing.

    EDIT: Or not, since Akisu was kind enough to post a screen shot of their log without the spacing.

    So, now the question is, if it is a malicious script modified to target FFXI players, where exactly is it? /sigh.

  18. #338
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Thank you Akisu for the pic ruling out the spacing issue

  19. #339
    New Spam Forum
    Join Date
    Aug 2008
    Posts
    161
    BG Level
    3
    FFXI Server
    Sylph

    So I ran hijackthis and I'm getting the same line as other people but my account hasn't been compromised yet.

    In my log there is no space, but you're saying that's just a formatting error due to the forums right?

    So pretty much, what should I do at this point? Should I just backup files and reformat? If so, is it ok to copy my POL folder onto my external HDD to just put back after reformatting or should I just do a fresh install?

    Also, since I ran hijackthis and saw that line in the log I simply logged off of FF for now, I should be fine until I figure out what to do, right?

    Also, how come when I run hijackthis and superantispybot AVG detects them both as generic trojan 14ABVT?

    Actually, this may be an opportunity for me to possibly help determine what site(s) are bad if I'm just going to reformat anyway. >_>

  20. #340
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    Ready the wall of text!.... Here goes....

    I'm 90% sure it's the adverts Wiki has been displaying. I've been checking different ad-banners, and occasionally I'll get broken ad-banners. Blank banners that generate this error: (I've removed the URL to prevent people from clicking randomly, incase it is a tainted script address.)

    Spoiler: show

    Message: Could not complete the operation due to error 800a03e8.
    Line: 49
    Char: 337
    Code: 0
    URI: ....brokenURLgo!...googleadservices...something.../gampad/google_ads.js


    After looking up the code, it's a bug in the script itself, which makes me wonder how a google script manages to break itself. The ad-bars that are in error are WoW banners, which would also make sense because WoW has also been having accounts hacked lately. Perhaps the problem is in this "gamepad" ad-banner type from Google?

    Wiki's front page also seems to be spewing other broken script errors, and as far as the code goes, without seeing the backend of the scripts they have set up, I can't really make heads or tails of it. But I do know that any website that throws that many error codes out has some serious problems with their scripts, and you usually see something like this with sloppy, quick code jobs, pre-debug. (Or maybe a quick hack into the scripts to add some kind of exploit, which in turn broke the functionality of the scripts themselves?)

    Here's some of the other random errors it's tossing out: (Again, broken all the URLs... just in case... if someone wants to bravely check them as well, toss me a PM, and I can provide you with the full URLs)

    Spoiler: show

    Message: 'flyTabs' is null or not an object
    Line: 577
    Char: 188
    Code: 0
    URI: /wikia/StaticChute/?type=js&packages=monaco_anon_article_js&checksum= 9160d8eec21fb6a085c4a5cf962aebec

    ^^^ Checksum error code?

    Message: Object doesn't support this property or method
    Line: 4857
    Char: 5
    Code: 0
    URI: /prototype.js&action=raw&ctype=text/javascript


    Again, these errors are generated exclusively on pages that use the google ad banners, from the "gamepad" section of google ad services.

    It's very possible that this is just bad coding on Wiki's behalf, but it's also possible someone was screwing around with the script files, I wouldn't be able to tell for sure without server logs, and I doubt we'll ever see those.

    I did some looking around in the Wiki's forums, apparently under the support section, users have been reporting getting virus notices from adbanners since late July, the only notice they've looked into it was an "I'll pass it along." post from a moderator. The virus they are citing as being found in ad banners is "Trojan:Win32/FakeXPA". Upon checking the report area of Wikia (Owners of ffxi wiki + many others) there's quite a few notices posted about users having similar issues with tainted adverts.

    KI also had a very large posting about them finding the exact same trojan in ad-banners found on wiki, as well as KI itself, and they are also claiming a banner on BG itself was infected, as there was an old post here about it as well. All of that was also posted at the end of July.

    Perhaps this is the culprit, but the ad-banners are in a time-delay rotation, so you're only getting them displayed every so often? I'm aware that site owners have no real control over the ad-banners displayed, most are page content sensitive and try to target ads for any key words they manage to pick up. Perhaps google is throwing around some tainted ad-banners, it wouldn't be the first time, that's for sure. Just google "google ads trojan," it seems they've been fending off trojans nested inside "fake" google ads that replace real google ads for a long time. Maybe the RMT community is just jumping on the bandwagon for any gamer-related adverts.

Page 17 of 47 FirstFirst ... 7 15 16 17 18 19 27 ... LastLast

Similar Threads

  1. What in the fuck is going on with Ancient Currency prices?
    By Avarice in forum FFXI: Everything
    Replies: 22
    Last Post: 2009-01-12, 05:21
  2. Ok what the hell is up with Roc?
    By S N K in forum FFXI: Everything
    Replies: 49
    Last Post: 2008-06-28, 21:00
  3. Oldschool players with JP Accounts & The new Expansion
    By Lyramion in forum FFXI: Everything
    Replies: 39
    Last Post: 2007-11-24, 01:31