So, what is exactly happening at the moment that is fact?
Passwords being changed without security token ID?
Is it even possible to change your password without doing it through PlayOnline Client?
So, what is exactly happening at the moment that is fact?
Passwords being changed without security token ID?
Is it even possible to change your password without doing it through PlayOnline Client?
I have Norton 360 was wondering if is necessary for me to download Spyware doctor? Reason I ask is that I was hack Friday morning for registering at FFXI linkshell community on Thursday night. (Huge mistake of my life)
All I pretty much lost was 2.5 mill + a peacock charm and I was told I was extremely lucky my account was not clean out.
probably a newbie question but if your pw is saved on pol and all you do is click login can they steal your pw?
Yes, if you get a keylogger. What's scary here is that a lot of the people having problems supposedly protected themselves properly, which implies it's either:
A) on a commonly used site and embedded in that site's code, as opposed to an outside ad
B) in some other way able to get on people's pcs, not sure how this would happen if malicious code is located outside of trusted site
C) coming from SE's end, which is very scary
So either SE seriously fucked up and reset everyone's passwords so that they can't get on, or the people who got the e-mail legitimately got their accounts ganked by some form of 3rd party and SE *might* have been on the ball and tried to warn us?
Either way: https://secure.square-enix.com/cisweb/app is the way to get into our accounts, so if RMT/hacker, etc. got access to your POL ID and password, they could go in and change it through this website and have your character. Those of us with security tokens were potentially saved losing our characters because of this possibility. When I logged in the day before it said my POL ID and/or password was incorrect. It got through checking my sq-enix acct and security token.
I am denied until Monday though, I went the route of having my fiancee lock my account. I'll be joining the throngs of angry people at 12:00PM EST that day. x_x The joy.
"We're working SO HARD to protect your accounts, we're gonna make it so that YOU can't even access them!"
Same for me, couldn't get on this afternoon. I can get into SE account no prob, can't get by POL password. Sucks can't do anything about it until Monday. Funny thing is my alt account that a friend gave me with no token that I also use on all the same computers i use my main on is fine... Guess next time I get an email from SE that says I should change my password I should listen...![]()
I am a serious computer newb if anyone could pm or respond with the best ways to stay protected from this i would really apprieciate it.
Registration server maintenance starting from Aug. 31, 2009 23:50 to Sep. 1, 2009 5:00 (PDT)
So monday there wont be any password changing.
@Fyrebrand there is lots of information in this thread as well as sticky's posted on how to secure your account in this forum. I think I linked them in this thread also, early in the first few pages.
I'm going with:
C) coming from SE's end, which is very scary
From my experience. I just hope they didn't move my character or jack my stuff yet, but I guess I won't know until Monday. If this is a virus, etc, ESET NOD32 and Malwarebytes both failed to find it, and I pretty much refuse to believe that.
I also run Firefox, noscript, etc, and really doubt I got something that's undetectable. The logical conclusion is that it's a problem on SE's end, maybe brute-forcing the POL page, or another, even more direct attack. Who fucking knows, I'm just pissed off they can't get their shit together after this long and I'm dragged into it even after buying their 'security' token.
POL should have been done away with ages ago.
If its worth protecting with a password, its worth it to try and steal it, no matter how you log in, some douchebags out there are just gonna try and steal your shit no matter how secure you think it is. If its not POL its some other square log in deal that is going to get hacked.
what I am curious to find out is how they are hiding it so well, that nothing is picking it up.
Yea I ran scans with Kaspersky, Trojan Remover, Avast, Spyware Doctor on my gaming computer and my laptop, still going to have to scan my work computer but not until Monday. If it is a virus, its really fucking sneaky...
I still find it odd though that the account I take extra measures to 'secure' gets hacked and yet the mule account that should be 'easy' to hack is fine and on right now. SE never fails to impress me...
They don't have to hide it well from us if they're harvesting information from them. Why even bother with a clients machine when you could attack a SE server or webform if you have an exploit?
I'm saying I don't think it was something on my machine (maybe any of ours in this newest round), I think it was something on their end. I'd love to be proven wrong so I know what the fuck to 'remove,' but as far as I can tell, and I'm 99.9% sure, my machine doesn't have shit on it.
I work in ITS every day of my life. It doesn't make me immune from being hacked or targeted, but it certainly wouldn't be easy. I have reasons to believe this has nothing to do with my machine, and if it does, I'd love to know what it is. Not like SE will ever tell me though, nor will they release something if it's on their end. I just hope I don't have more of a headache come Monday![]()
I also am suspecting that it's something on SE's end. It seems like the easy route to blame someone else, not ourselves, but at the same time It doesn't make sense for all these to happen so similarly (and sinisterly), to people with proper protection against these sorts of threats no less (and to people without, but they were the easy pickings).
I've also had yet to run across ANY suspicious files or programs lurking on my computer. I find it highly unlikely that anything could slip through all these programs.
So yeah, I just got hit. No idea how, my pc was 'clean'.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:21:05, on 30/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Marvell\61xx\svc\mvraidsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Marvell\61xx\Apache2\bin\Apache.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Marvell\61xx\Apache2\bin\Apache.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spotify\spotify.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ~☆Zidiane☆~
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Search Microsoft.com
LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Search Microsoft.com
LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05
\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common
Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common
Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet
Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common
Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet
Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh
Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh
Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\WINDOWS\system32\rundll32.exe" "C:\Program
Files\NOS\bin\getPlus_Helper.dll",Uninstall /Get1noarp
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05
\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows
Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} -
C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11
\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolba...lerControl.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w3/pr01...s/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-
UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/micr...?1229436191390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/micr...?1229436177531
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary...r.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary...n.cab31267.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems
Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common
Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program
Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec
Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common
Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet
Security\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision
Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Marvell RAID Event Agent (Marvell RAID) - Unknown owner - C:\Program
Files\Marvell\61xx\svc\mvraidsvc.exe
O23 - Service: MRU Web Service (MRUWebService) - Apache Software Foundation - C:\Program
Files\Marvell\61xx\Apache2\bin\Apache.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet
Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common
Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec
Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-
LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program
Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 10126 bytes
My log, help![]()
so, haven't read anything past page 3 or 4, but someone help explain this to me...
i play almost exclusively on PS3, only using wifes laptop when i need to talk on vent. lil while ago, while xping in mire, the screen clears, and i get the message that my account has been logged on from another terminal. i freak out, and and able to find my SE token quickly, and log back in myself. the party i was in said i disappeared 2 times (again, on PS3, so no pic taken). I haven't logged onto the game through the PC in over 2 weeks. I use firefox with the appropriate blocks up. All PWs are unique, and have now been changed.
I am just at a loss how a PS3 acct can be hacked