Item Search
     
BG-Wiki Search
Page 18 of 47 FirstFirst ... 8 16 17 18 19 20 28 ... LastLast
Results 341 to 360 of 931
  1. #341
    Melee Summoner
    Join Date
    Feb 2008
    Posts
    29
    BG Level
    1
    FFXI Server
    Bismarck

    Ahh, I've seen a lot of gamepad ads blocked on ah.com. I've been sitting here stepping through those, unblocking, scanning, refreshing, source checking, repeat for each. With the time delayed rotation, it's rather annoying to thoroughly analyze one page.

    I've yet to set my cross-hairs over on wiki, but I'll check out the links if you would PM them over. I'll be back in a bit, breakfast time and going to reboot anyway!

    In response to jamma's post, if you've found this on your PC and logged out, you should be ok.
    If you can get a friend to keep an eye out for your character being online, that would be a plus.
    Also, HJT can access the registry on your machine, so chances are, AVG throws a flag on it because it can modify the registry. As for superantispybot, no idea, never used it. I've had HJT on my machine for years, I can assure you that it is not a trojan.
    As for formatting and reinstalling, that's probably the easier option if you don't have a ton of programs etc. on your PC. Yes, you should be able to copy FF to an external HDD, format, reinstall OS, reinstall FF, then copy the updated files from the external HDD back in. Just don't make the mistake I made once and try to copy them back BEFORE reinstalling the expansions. Opps.

  2. #342
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    Quote Originally Posted by jammalamma View Post
    So I ran hijackthis and I'm getting the same line as other people but my account hasn't been compromised yet.

    In my log there is no space, but you're saying that's just a formatting error due to the forums right?

    So pretty much, what should I do at this point? Should I just backup files and reformat? If so, is it ok to copy my POL folder onto my external HDD to just put back after reformatting or should I just do a fresh install?

    Also, since I ran hijackthis and saw that line in the log I simply logged off of FF for now, I should be fine until I figure out what to do, right?

    Also, how come when I run hijackthis and superantispybot AVG detects them both as generic trojan 14ABVT?

    Actually, this may be an opportunity for me to possibly help determine what site(s) are bad if I'm just going to reformat anyway. >_>
    If you suspect you've been hacked, the best course of action (in my opinion...) is to backup your user folder for FFXI, and any other important files to you, then reformat, and do a new install of playonline/ffxi. The "hack" that's happening to some people is an injection into playonline's executable, so if you back that up, you'll just bring the hacked executable with you to your fresh install.

    As far as using HijackThis, did you get it strait from TrendMicro? It's a free download and not infected, as TrendMicro themselves are an anti-virus company.

    I've never heard of superantispybot. It sounds like a knock off of Spybot-S&D developed by Safer Networking. Again, where did you download it from? lol.

    Assuming both of them were downloaded from the actual websites, it could be a false-positive. Avast Antivirus > AVG in terms of free antivirus software, by far, going off of actual detection rates.

  3. #343
    With milk. With love
    Join Date
    Apr 2005
    Posts
    1,629
    BG Level
    6
    FFXI Server
    Siren
    WoW Realm
    Cenarion Circle

    Ok, not sure if this may be related to the recent hacking news, but this started popping up this morning on both PetFoodAlpha's site (unreachable atm), and on the TTTO website.

    http://www.bluegartr.com/forum/attac...1&d=1251197847

  4. #344
    Hyperion Cross
    Join Date
    Jan 2007
    Posts
    8,908
    BG Level
    8
    FFXIV Character
    Kai Bond
    FFXIV Server
    Gilgamesh

    For the hammering on:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
    If you're paranoid you can go to Internet Options > Connections Tab and click on "LAN Settings" to see.

    If you tick "use a proxy server..." and then click on Advanced you will see a box where it says "Exceptions".

    If you leave it blank, then it will have "local" (or <local>) or something to that variant. If you put anything in the box (a list of addresses) it will end with <local> or local regardless in your Registry or HJ Log.

    This box is just for people who use a proxy server but will to bypass the proxy for whatever purpose (usually internal websites like intranets or other application based site that's internal).

  5. #345
    A. Body
    Join Date
    Jul 2008
    Posts
    4,046
    BG Level
    7
    FFXI Server
    Caitsith

    Banning all of china is an extreme when if the article posted is correct, wasn't even something the chinese made but russian made that was being sold off to other cyberhackers, which can include Amercian groups. What if it's an American doing it? SE should ban all of America too right?

    It's not unlikely that there could be non chinese doing it and just passing themselves off as RMT, hackers and etc aren't completely stupid and will try to hide behind anything possible and since people are willing to buy characters/gear/gil for ridiculous amounts of money..it would attract anyone..if they play FF/WoW or not, if you can make literally thousands on virtual shit, you'll do it..chinese or not. IIRC major RMT operations like IGE is American based, while they may have chinese farmers they're technically an American company.

    As for PS2/PS3/360 users being hacked, if it's what's been posted before, it's definitely that suspicious line in everyone's hijack this log, because I don't think there's been any other major vulnerabilities in the PSN/Live networks lately.

  6. #346
    Falcom is better than SE. Change my mind.
    Join Date
    Jun 2006
    Posts
    17,291
    BG Level
    9

    Kimiko... that's pretty odd. It does look like the RMT are at new tricks.

  7. #347
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    Quote Originally Posted by TheStig View Post
    For the hammering on:



    If you're paranoid you can go to Internet Options > Connections Tab and click on "LAN Settings" to see.

    If you tick "use a proxy server..." and then click on Advanced you will see a box where it says "Exceptions".

    If you leave it blank, then it will have "local" (or <local>) or something to that variant. If you put anything in the box (a list of addresses) it will end with <local> or local regardless in your Registry or HJ Log.

    This box is just for people who use a proxy server but will to bypass the proxy for whatever purpose (usually internal websites like intranets or other application based site that's internal).
    The issue is that the line of code is being created in the registry without user intervention of any kind; and by default does not exist in the registry, and it seems to be a common denominator in people who are "infected" versus those who aren't.

  8. #348
    Puppetmaster
    Join Date
    Nov 2005
    Posts
    72
    BG Level
    2

    Quote Originally Posted by Kimiko View Post
    Ok, not sure if this may be related to the recent hacking news, but this started popping up this morning on both PetFoodAlpha's site (unreachable atm), and on the TTTO website.

    http://www.bluegartr.com/forum/attac...1&d=1251197847
    Isn't that just some .htaccess authentication?

  9. #349
    Bagel
    Join Date
    Jul 2007
    Posts
    1,271
    BG Level
    6
    FFXI Server
    Cerberus

    Can we have some TL;DR sum up at some point, shit loads of info that can be somewhat hard to follow, that would be great thanks.

  10. #350
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Is that just Ganiman's site or something?

  11. #351
    With milk. With love
    Join Date
    Apr 2005
    Posts
    1,629
    BG Level
    6
    FFXI Server
    Siren
    WoW Realm
    Cenarion Circle

    Quote Originally Posted by Shaard View Post
    Isn't that just some .htaccess authentication?
    I would think so, but it also came up on TTTO as well. Told Wyred bout it, he removed the PFA ad on the site which cleared up the issue there. Also, what would Ganiman have to do with the PFA site?

  12. #352
    Falcom is better than SE. Change my mind.
    Join Date
    Jun 2006
    Posts
    17,291
    BG Level
    9

    Quote Originally Posted by Fridell View Post
    Can we have some TL;DR sum up at some point, shit loads of info that can be somewhat hard to follow, that would be great thanks.
    As much as I wish we could we still don't know exactly what's happening. Ase noticed there was a Proxy Override line in people's highjack this logs who were hacked opposed to those who weren't. The issue is that line comes up when you have some proxxy option checked in IE. What I want to know is if the virus checks this box if it's currently off and that's where the exploit is.

    EDIT: Starting here is where that Proxy Override thought started: http://www.bluegartr.com/forum/80487...ml#post3015536

  13. #353
    A. Body
    Join Date
    Jul 2008
    Posts
    4,046
    BG Level
    7
    FFXI Server
    Caitsith

    Quote Originally Posted by Kimiko View Post
    I would think so, but it also came up on TTTO as well. Told Wyred bout it, he removed the PFA ad on the site which cleared up the issue there. Also, what would Ganiman have to do with the PFA site?
    Considering this is a supposed RMT attack, has Ganiman ever been linked to RMT related issues before?

  14. #354
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    Quote Originally Posted by Fridell View Post
    Can we have some TL;DR sum up at some point, shit loads of info that can be somewhat hard to follow, that would be great thanks.
    In summary:

    People are getting their accounts hacked again, similar to how it was happening before, except it also includes people with tokens using Firefox+noscript/etc.

    We've been trying to figure out where/how/why/etc.

    Likely suspects seem to include the ever popular Flash ad-bars displayed everywhere.

    People are taking note of a common line of code in the registry between users who are infected/been hacked:
    "R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local"

    I made a long winded post about some scripts looking odd on the wiki's site, then you asked for a summary.

    /End Summary.

  15. #355
    Hydra
    Join Date
    Jul 2008
    Posts
    103
    BG Level
    3
    FFXI Server
    Unicorn

    There's no space in 'internet' in my log either.

    Also, a friend of mine noticed this similarity in the hjt logs in this thread that were from definate hackings or attempts:

    O1 - Hosts: ::1 localhost

    Not sure if that's anything important. According to her, it seemed to be in the infected logs but wasn't present in clean logs. Might be an extension of what's going on with the proxy override line just above it?

    And I can definately rule out ffxiah or whatnot. Only been to bg, wiki, windower, and a couple of smaller ls-specific forums before picking this up on sunday. Pretty sure it's not the windower site as that doesnt seem to be a common link between hacked players. Gotta be either BG or wiki. And if it's coming from gaming related banners, it could be both, although tbh I have my firefox addons blocking the banner ads.

  16. #356
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by Kimiko View Post
    I would think so, but it also came up on TTTO as well. Told Wyred bout it, he removed the PFA ad on the site which cleared up the issue there. Also, what would Ganiman have to do with the PFA site?
    I do not know what kind of access Gani shares with Pfa but he is fairly easy to contact by posting in the wiki forum section related to wikipedia editing. There is also the irc. If I actually knew what to notify them of I could contact them. Perhaps some one could pm Steak(sp) here on bg to let him know about the issue or ask about it.

  17. #357
    Bagel
    Join Date
    Jul 2007
    Posts
    1,271
    BG Level
    6
    FFXI Server
    Cerberus

    Thanks for summary. Much appreciated.

  18. #358
    Cerberus
    Join Date
    Jun 2007
    Posts
    409
    BG Level
    4

    Spoiler: show

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:34:38 AM, on 8/25/2009
    Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.20583)
    Boot mode: Normal

    Running processes:
    E:\Windows\System32\smss.exe
    E:\Windows\system32\winlogon.exe
    E:\Windows\system32\services.exe
    E:\Windows\system32\lsass.exe
    E:\Windows\system32\Ati2evxx.exe
    E:\Windows\system32\svchost.exe
    E:\Windows\System32\svchost.exe
    E:\Windows\system32\svchost.exe
    E:\Windows\system32\Ati2evxx.exe
    E:\Windows\system32\spoolsv.exe
    E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    E:\Program Files\NetLimiter 2 Pro\nlsvc.exe
    E:\Windows\system32\oodag.exe
    E:\Program Files\CyberLink\Shared files\RichVideo.exe
    E:\Windows\system32\svchost.exe
    E:\Program Files\NetLimiter 2 Pro\NLClient.exe
    E:\Windows\SOUNDMAN.EXE
    E:\Program Files\Cyberlink\Shared Files\brs.exe
    E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    E:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    E:\Windows\system32\rundll32.exe
    E:\Windows\system32\oodtray.exe
    E:\Windows\system32\ctfmon.exe
    E:\Program Files\Skype\Phone\Skype.exe
    E:\Program Files\Microsoft ActiveSync\Wcescomm.exe
    E:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
    E:\PROGRA~1\MI3AA1~1\rapimgr.exe
    E:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
    E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    E:\Program Files\Radmin\radmin.exe
    E:\Program Files\Skype\Plugin Manager\skypePM.exe
    E:\Program Files\Pidgin\pidgin.exe
    E:\Windows\explorer.exe
    E:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    E:\Program Files\Mozilla Firefox\firefox.exe
    G:\Users\Kaces.DARK\Desktop\FlashFXP.v3.4.1.1179.W inALL-LOVE\flashfxp.exe
    E:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\devenv.exe
    E:\Program Files\Winamp\winamp.exe
    E:\Program Files\uTorrent\uTorrent.exe
    C:\MPC HC\Guru3D.com\Setup\Mplayer - 32-bit\mplayerc.exe
    E:\Windows\system32\SNDVOL32.EXE
    E:\Documents and Settings\Kaces\Desktop\HiJackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/intl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = Customize Your Settings
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
    O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - E:\Program Files\Orbitdownloader\orbitcth.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - E:\Program Files\Orbitdownloader\GrabPro.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [OSSelectorReinstall] E:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [BDRegion] E:\Program Files\Cyberlink\Shared Files\brs.exe
    O4 - HKLM\..\Run: [RemoteControl] "E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "E:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "E:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [OODefragTray] E:\Windows\system32\oodtray.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKCU\..\Run: [ctfmon.exe] E:\Windows\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Skype] "E:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [H/PC Connection Agent] "E:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
    O4 - HKCU\..\Run: [AtiTrayTools] "E:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
    O4 - HKCU\..\Run: [scheduler_monitor] E:\Program Files\ReaConverter 5.5 Pro\init_scheduler.exe
    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
    O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
    O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = E:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
    O8 - Extra context menu item: &Download by Orbit - res://E:\Program Files\Orbitdownloader\orbitmxt.dll/201
    O8 - Extra context menu item: &Grab video by Orbit - res://E:\Program Files\Orbitdownloader\orbitmxt.dll/204
    O8 - Extra context menu item: Append to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Do&wnload selected by Orbit - res://E:\Program Files\Orbitdownloader\orbitmxt.dll/203
    O8 - Extra context menu item: Down&load all by Orbit - res://E:\Program Files\Orbitdownloader\orbitmxt.dll/202
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\Windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\Windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
    O23 - Service: Apple Mobile Device - Apple, Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\Windows\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: CNFNQ - Sysinternals - Windows Sysinternals: Documentation, downloads and additional resources - E:\DOCUME~1\Kaces\LOCALS~1\Temp\CNFNQ.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NetLimiter (nlsvc) - Locktime Software - E:\Program Files\NetLimiter 2 Pro\nlsvc.exe
    O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - E:\Windows\system32\oodag.exe
    O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - E:\Program Files\ReaConverter 5.5 Pro\rcp_scheduler.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - E:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: Remote Administrator Service (r_server) - Unknown owner - E:\Windows\system32\r_server.exe

    --
    End of file - 10990 bytes


    nothing seems to be out of place but this is my machine and it has that proxy line as well ;o

    i run 1 tokened account + 2 untokened mules with quite a few valuables but they don't seem to be missing anything, nor does my machine seem unstable as when mafai's friend had it happening. nothing's happened to any of my accounts, as of yet anyway.

    got a few errands to run this morning, so i'll be back to run some tests per rootkit/process injection.

    if anyone's on, can they check what their filesizes are for these files.

    Size(Not Size on disk):

    pol.exe 1.52MB (1,600,000 bytes)
    polboot.exe 56.0 KB (57,344 bytes)

  19. #359
    Puppetmaster
    Join Date
    Jul 2008
    Posts
    50
    BG Level
    2
    FFXI Server
    Phoenix

    Quote Originally Posted by Destinye View Post
    Considering this is a supposed RMT attack, has Ganiman ever been linked to RMT related issues before?
    You could if you grasp a bit, atleast from my knowledge, as ffxiclopedia was one of the main sources from the previous hack wave of flash exploited ad-banners. Then again, ffxiclopedia was sold to wikia I believe, so that would be on Wikia's head, I don't know the timeline.

    Anyone know? lol.

    Quote Originally Posted by Nymphadora
    There's no space in 'internet' in my log either.

    Also, a friend of mine noticed this similarity in the hjt logs in this thread that were from definate hackings or attempts:

    O1 - Hosts: ::1 localhost

    Not sure if that's anything important. According to her, it seemed to be in the infected logs but wasn't present in clean logs. Might be an extension of what's going on with the proxy override line just above it?

    And I can definately rule out ffxiah or whatnot. Only been to bg, wiki, windower, and a couple of smaller ls-specific forums before picking this up on sunday. Pretty sure it's not the windower site as that doesnt seem to be a common link between hacked players. Gotta be either BG or wiki. And if it's coming from gaming related banners, it could be both, although tbh I have my firefox addons blocking the banner ads.
    I'm fairly sure that the spacing between what people were pasting from their logs was just a copy/paste problem, not actually there in everyone's logs.

    Also, a post on ffxiclopedia's forums mentioned that windower's site, FFOChat, and eorzeapedia were all down yesterday around 11:00pm-11:30pm, but don't take my word for that, just quoting what I'm reading off of ffxiclopedia's forums at the moment. They were all displaying a "general error" message that was citing issues connecting to the database, which is "a problem with shared hosting." However, I don't believe they are all hosted from the same place.... ?

  20. #360
    Hydra
    Join Date
    Jul 2008
    Posts
    103
    BG Level
    3
    FFXI Server
    Unicorn

    Quote Originally Posted by Corrderio View Post
    As much as I wish we could we still don't know exactly what's happening. Ase noticed there was a Proxy Override line in people's highjack this logs who were hacked opposed to those who weren't. The issue is that line comes up when you have some proxxy option checked in IE. What I want to know is if the virus checks this box if it's currently off and that's where the exploit is.

    EDIT: Starting here is where that Proxy Override thought started: http://www.bluegartr.com/forum/80487...ml#post3015536
    Problem here is that I don't have any proxy options checked. Box left unchecked, no proxy address specified and all of those options are left grayed out on my infected machine. [edit, just noticed you were talking about IE. Not sure if it would be the same in firefox though?]


    Quote Originally Posted by Akisu View Post
    You could if you grasp a bit, atleast from my knowledge, as ffxiclopedia was one of the main sources from the previous hack wave of flash exploited ad-banners. Then again, ffxiclopedia was sold to wikia I believe, so that would be on Wikia's head, I don't know the timeline.

    Anyone know? lol.



    I'm fairly sure that the spacing between what people were pasting from their logs was just a copy/paste problem, not actually there in everyone's logs.

    Also, a post on ffxiclopedia's forums mentioned that windower's site, FFOChat, and eorzeapedia were all down yesterday around 11:00pm-11:30pm, but don't take my word for that, just quoting what I'm reading off of ffxiclopedia's forums at the moment. They were all displaying a "general error" message that was citing issues connecting to the database, which is "a problem with shared hosting." However, I don't believe they are all hosted from the same place.... ?
    Didn't know anything about that. Could possibly sound suspicious if so. I was only on windower's site Sunday evening and a lot of the others infected didn't seem to have that in common. Although if it's the banner ads, they could be popping up everywhere.

    And no, don't think those sites are hosted from the same place to my knowledge. Eorzeapedia is an extension of ffxiclopedia aimed at ff14. Don't think windower or the chat are at all connected. Someone could probably check into it?

Page 18 of 47 FirstFirst ... 8 16 17 18 19 20 28 ... LastLast

Similar Threads

  1. What in the fuck is going on with Ancient Currency prices?
    By Avarice in forum FFXI: Everything
    Replies: 22
    Last Post: 2009-01-12, 05:21
  2. Ok what the hell is up with Roc?
    By S N K in forum FFXI: Everything
    Replies: 49
    Last Post: 2008-06-28, 21:00
  3. Oldschool players with JP Accounts & The new Expansion
    By Lyramion in forum FFXI: Everything
    Replies: 39
    Last Post: 2007-11-24, 01:31