So for any of the testbeds that are getting the proxy change, is anything else getting modified (such as hosts file)
P.S. and whats up with LBR or PFA? PFA just has a blank page with "It works!"
He's not debating it, but basically too many people arrive here on their high horses are literally shocked that they're hacked or they might be hacked and they use FF and everything. They seem to open their posts with "I use FF" (and relevant add ons) as if it's some uber security blanket.
Then we need more information from people who have actually been hacked, not just paranoid people who got d/ced for one reason or another.
If you've been hacked: Event viewer logs from when pol.exe crashed, and process explorer logs with pol running would be very helpful. Also submit pol.exe and polboot.exe to a multiengine antivirus like virscan.org
Alright, since people are having issues with other people mentioning the HJT logs with proxy stuff... Here's a long winded explanation- skip this post if you just plain don't care about it, or don't feel like reading a detailed explanation.
First of all, the proxyoverride: *.local stuff.
Two things: I found two catagories of programs that install this line. One of which is adobe products. Dreamweaver, Photoshop, things of that sort. It has to do with the authentication service also installed with it. Another program that adds this line to the registry are some of the "accelerators" used and packaged with IE8, and some of the MSN Live garbage like Live Blogger (which you could argue in itself is bloat/malware). Some OEM software install packagaes (the basic configurations on a Dell or HP restore disk installs) also add modifications to proxy lines.
Basicly... for those who still don't understand what this line means... I'll explain it.
R1 items are created Registry values.R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
....
O1 - Hosts :: 1 Local Host (or similar)
O1 items are Hostsfile redirections.
Overriding a Proxy address and looping it back to the local host (your machine) is redundant, and from my point of view, the only reason you would loop information back to the source is to run it into a seperate service or program, and just give it a way to find it by defining a port. It seems like a very sloppy way of doing things, but I've seen worse code released in final versions of application.
The reason some trojans like this little trick, is because you can intercept/reroute information back to another program, which can use it in whatever way it sees fit.
So saying the information is only going back to your own machine, and it makes it perfectly fine as such, is as bad as saying "delete this and you'll be fine!" without actually knowing what it is you're dealing with. Assuming it's legit program related, sure, it's fine to be there. Likewise, under the assumption (which some evidence seems to point at for infected users,) that it's looping the information back through a resident "program" which is sending it out by other means.... well, prove to me it's not, instead of saying it's perfectly fine.
As it stands right now, every machine that's been infected has the line of code in the HJT log, that I'm aware of anyway, (can someone double check this from previous posts?) Other people also have it who haven't been hacked; which could be false positives, as they could have things installed that legitimately use the proxy setting.
Jumping to extremes and assuming you're hacked because you found the line of code is paranoid, but then again; I was under the assumptions we were posting our findings and trying to find similarities on the software level of hacked users, which is exactly the purpose of the posts I've been making.
....
The host file redirections are normal, for whatever reason, Microsoft sees fit to have data loop back through the machine (localhost).
The only time you would need to worry is if you saw something like this...
If you see something like this, you have a browser hijacker, which is what the "phishing websites" that SE warned about, and that previously mentioned trojan was adding.O1 - Hosts: <IP address here> "website A"
**Just an example**
O1 - Hosts: 123.456.789.0 playonline.com
What this means is that every time you try to access "website A", you get redirected to the ip address, which could potentially be a hacked/fake website. As in the example, anyone accessing playonline would be sent to "123.456.789.0" instead.
This is a common way people get scammed with bank account logins and such. If I recall correctly, there was a trojan floating around a few years back that did a redirect for the social security website, and quite a few people had their personal information stolen.
....
The best way to find out if the proxy line in the logs is related to anything, is just as Solefald said; post logs, and check your executables. If can be confirmed it has nothing to do with anything here, that's just one more thing to cross of the list.
Yes exactly. People simply need to understand that having that line does NOT necessarily mean they are infected, as a there are a number of legitimate reasons that line could be there.
But if it is not there by default, and then it suddenly appears one day, having not installed or changed anything to your knowledge, but after visiting an FFXI-related site, you may want to look into it. Because as it stands now, it is believed that the malicious code used to grab the account info does indeed need that line to be there to function, and in fact adds the line itself upon infection (assuming it's not already there).
But again, the presence of that line alone does NOT equate to "ZOMG I'm infected!"
I suppose you could say it's a step in the right direction, but it's a very very vague generalization to say that anyone that has this line is vulnerable. Someone said before that some ISP CD's add this line along with other things.
The biggest step thus far has been that dll file that someone posted back a couple pages ago that was identified as infected.
Yes, it is simply a very common logic mistake. If P then Q, does NOT guarantee that if Q then P.
"All infected PCs have that line" (while observationally true), does NOT indicate that "all PCs with that line are infected."
That's the thing I think people who were hacked should be looking for in their event log.==============
AppName: pol.exe AppVer: 1.18.12.0 ModName: flasha32.dll
ModVer: 0.0.0.0 Offset: 0000476d
==============
I never said anyone who has that line is vulnerable, I just said it's a common item, as I've said way back on page... well... 8+ a few times.
The dll was a step in the right direction, but as I had also mentioned, google ads have confirmed reports of having recently tainted adverts, there was trouble tickets logged into google ads, as well as for Wikia itself for both ffxiclopedia (a single ticket, submitted by someone who notified an admin on their forums), as well as several from the WoW wikia page. The common factor there would be they all use the google ads from the "gamepad" catagory of google ads.
That would also mean anyone else who used google ads would have been vulnerable. Like I also previously posted, the very same ads were generating script errors, and if a script is written correctly, they shouldn't generate errors. This morning I've been trying to track down those ads, but it seems like some of them have been pulled from google's ad listing already, as I can't get them to show up after 500+ page reloads.
If the DLL is the payload, then the advert could have been the delivery package. Does anyone actually have a copy of the "flasha32.dll" file? I'd like to take a look at it if possible.
Yea, I'd love to take a look at it too. I tried to get in contact with the person I know that was hacked, but he's already formatted his computer so I guess I won't be getting that from him.
I searched the ghost I made of the infected drive before I formatted the laptop again, and I wasn't able to find the dll, so anyone who has it, please send me a PM, maybe we can get something from the .dll file.
A simple googly search for that file wielded this page, some h ttp://www.superantispyware.com (I spaced out link on purpose, not that it's any bad from what I could see, but hey, I rather shield myself from potential abuse) site which sounds like a load of shit (too generic sounding) on why it's bad, it's listed as Adware (Adware.Vundo/Variant) and a bunch of JP FFXI websites which unfortunately I cannot read.
In general, which is safer when entering my SE PW:
1. Using the virtual keyboard and moving it a couple times while clicking my PW in
or
2. Typing it into a program protected by KeyScrambler Pro QFX Software - Anti-Keylogging Software and More and then cut and pasting it into POL?
I'm pretty sure the clipboard isn't encrypted or anything so that would be kind of pointless. These attacks are probably aimed at simple keylogging that but if people did start using this method, I'm sure it would become a target also.
What does this achieve? lol
You said your account was partially emptied? Is this because you had your friend watch you after txting them to call a gm for lock?
I appreciate the work people are doing. If one has the knowledge to test things at least trying to resolve it is better than sitting round waiting for some one to do something.
My most likely completely empty and baseless theory that some of the ffxi key loggers that account for virtual keyboard only account for it's default positioning and therefore have skewed results if you click at a certain position other than the default.
/opens up the floodgates to be called an idiot, moron, noob, etc.
No, I was saying if this script has the potential to allow someone access to my account in order to steal everything they can sell and leave me with a half empty account, then it's worthy of alarm.
Izzy, if you would please reread my post, I never said, implied or explicitly, that anyone should believe they're completely safe just by removing the registry entry. If anyone got that idea, then sorry, you misunderstood. I said: "I've been unable to reinfect the PC after removing it, and the removal seems to have zero effect on anything else." If, somehow, you can construe this to mean, "ok, so I remove it and I'm safe" then you have a poorly formed idea of computer security in general. I don't see anyone else posting with that confusion, or anyone else even posting saying they removed that line (not via reformat) and haven't seen it come back.
I didn't have process explorer installed on either PC at the time this happened, but browsing the event logs, I'm not seeing anything out of the ordinary yet. I'll keep looking and post them in a few minutes so others can take a look.
cdgreg, that's actually very similar to a method a friend was telling me about. I hadn't thought of it, but, if the loggers are just recording x,y positions of the mouse pointer, then by moving the keyboard, the x,y of the keys is changed. However, doing this on the user end, to the best of my knowledge, would have no increased effect on your security. In short, if they can record where you click, if you hold the click, and move while holding the click, then they can replay the exact actions, moving the keyboard to the same x,y positions you've changed it to, and thus finding the same keys regardless. It's a bit more work involved in figuring out the keys, but with someone using, say, AutoHotKey and enough knowledge, it's completely possible.
The method a friend was describing was actually from MapleStory. He said when they log in and type their password on a virtual keyboard, the keyboard is changed after every entry. That is, the same key is not at the same x,y position on screen after each letter/number is clicked. Using a scrambled method like that would mean the hacker would have to interrupt your connection to steal your account or be able to decrypt the scrambler. Leave it to SE to think of things last, right?
In all fairness to SE, I do appreciate the GM locking my account so quickly after POL crashed as the log in information was being verified.
To the people saying things like, "oh you guys come in on your high horse with FF and can't believe you're hacked." this is very, very far from the mark in my case. I never assume I'm safe just because I use firefox, but the security is good, the ad-ons can make it better, and having a firewall that works is one step more. The firewall is an independent variable in this case, since it will work with IE or Firefox. Oh, and don't read my posts previously as "I was on FF" to mean "I was on Firefox." I was using firefox when this happened, but FF meant POL, the game itself, not firefox. If I intended to say firefox, I said firefox, not FF.
Updating:
I searched for the .dll that someone found infected. Haven't found it on any of my drives yet.
Currently, I'm submitting pol.exe, polboot.exe, polhook.dll, FFXi.dll, FFXiMain.dll, FFXiResource.dll, ImeUiDll.dll, polboot.exe.manifest to Jotti's malware scan. I'll submit to the other site once finished there.
Spoiler: show
All of the scans came up clean on Jotti's.
Event viewer will take a long, long time to sort. I've kept a huge log, though I can narrow it down to a small time frame, I'd still have to get it in a format more suited for posting, or uploading a file that isn't more than a few KB.
Relax a bit... I doubt you were hacked. Also, this is becoming FFXI's very own swine flu at this rate, except that only affected one certain user on BG.
A few who joined in on the fun a couple of months back will know what I mean.
It could be a number of other things, granted. It's just been alarming that it all happened at once for me. Others were affected, and towards the beginning of the thread said they actually came back to stripped accounts. It didn't happen to me, but... the circumstances described did.
Sure, random disconnect from ISP happens. Ok, so this registry entry is like kicking a dead horse. Sure, POL can crash on a separate machine for other reasons. I've had POL crash before, disconnected before, and seen plenty of registry entries that actually did relate to malware. However, seeing what was described here, then seeing my net get killed (which was a new one in this thread I think?), running the HJT scan and seeing that entry as a new entry, that is, it literally wasn't there 2 minutes prior, and then having POL crash while verifying log in information, was rather suspicious. I, for one, have never had POL crash prior to actually loading into the account. Something just didn't feel right, and, as I'm sure you know your machines well, you know that when something just doesn't seem right on them, it probably isn't.