Item Search
     
BG-Wiki Search
Page 2 of 2 FirstFirst 1 2
Results 21 to 35 of 35

Thread: Hacked ;(     submit to reddit submit to twitter

  1. #21
    CoP Dynamis
    Join Date
    Sep 2009
    Posts
    251
    BG Level
    4

    Honestly man I don't want to blame her. So if you didn't find anything on either computer you might have to go for a full format or something. Perhaps others could chime in on this post for you and suggest something. But if you've tried CCLeaner, Ad-aware and a virus checker. And it didn't find something then I'm not exactly sure how safe you're going to be able to use your computer to play FFXI. Usually when a company has a security vulnerability it's usually best to see HOW and WHY it was able to get in. In your case if those programs didn't catch anything then format seems in order. I can't suggest anything else.

    Sucks you didn't find a virus or something. Did you run all those programs? They're all easily available from download.com

  2. #22
    Fake Numbers
    Join Date
    Sep 2007
    Posts
    90
    BG Level
    2

    Tried CCleaner, Malwarebytes and SpyBot. Didn't try Ad-aware but will if you reckon there's a chance it could find something the others didn't?

  3. #23
    CoP Dynamis
    Join Date
    Sep 2009
    Posts
    251
    BG Level
    4

    No those 3 are fine. And you scanned with a virus scanner and didn't get anything either. I don't know what to say though. Either it's something that's still on your computer and you need to reboot. And no one has your account information except your girlfriend. It's hard to say what is to blame. I'm going to give your gf the benefit of the doubt. You can basically get Windows 7 free and what not so perhaps it's time to upgrade both computers to the new OS. Her computer might still be infected.

    But you have to admit the fact that your account was taken and then the mules were made on X server. It's quite suspect to me so I don't know. Maybe they didn't worry about locking you out and just wanted to send the stuff asap. Almost like they know what your play schedule is and did it when they knew you weren't around. You could try hijack this and post the log here. I and others could point something out right away.

    If that still doesn't show anything, just reformat. I know I wouldn't be able to feel safe without doing that if malware programs or antivirus didn't pick something up lol. Do Hijack this log and post it here first though. We'll go from there.

  4. #24
    Fake Numbers
    Join Date
    Sep 2007
    Posts
    90
    BG Level
    2

    Yeah virus scan was with AVG, not sure if that is good enough or not.

    I'll try and get the HijackThis one tomorrow. Cheers for the help.

  5. #25
    Fake Numbers
    Join Date
    Sep 2007
    Posts
    90
    BG Level
    2

    Here's the log for GF laptop in spoiler tags, no idea what any of it means so hopefully someone does. ^_^;


    Spoiler: show
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:21:26 AM, on 10/30/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16915)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\OEM02Mon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.ex e
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\system32\libusbd-nt.exe
    C:\WINDOWS\system32\KADxMain.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Mieke\Desktop\avg_free_stb_en_9_39_free.e xe
    C:\DOCUME~1\Mieke\LOCALS~1\Temp\7zS16A.tmp\stub.ex e
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Personalized Start Page
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Dell Search Page
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Dell Search Page
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Stuff.co.nz - Latest New Zealand News & World News, Sports News & NZ Weather Forecasts
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Canada - The all-new MSN Canada, home of world-class services such as Hotmail, Windows Live Messenger, and News, Sports, Financial and Entertainment services
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Canada - The all-new MSN Canada, home of world-class services such as Hotmail, Windows Live Messenger, and News, Sports, Financial and Entertainment services
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Dell Search Page
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = Personalized Start Page
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1194527801421
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/en/10/install/gtdownde.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{EEC26B11-C017-4994-9364-12B9F14D925F}: NameServer = 203.96.152.4,203.96.152.12
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.ex e
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - LibUsb-Win32 - C:\WINDOWS\system32\libusbd-nt.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    --
    End of file - 12705 bytes

  6. #26
    Old Merits
    Join Date
    Jan 2007
    Posts
    1,102
    BG Level
    6
    FFXI Server
    Phoenix

    Only thing that looks suspicious to me is:

    C:\DOCUME~1\Mieke\LOCALS~1\Temp\7zS16A.tmp\stub.ex e

  7. #27
    MaachaQ
    Guest

    Sounds like almost the same thing that happened to my sister's account.

    I'm not sure when it was initially hacked, as my sister did not really play anymore and could not remember changing her password, so couldn't help me when I tried to log into her account ~Sept 10th to cancel it. I had been paying for her account since she started, to try to lure her away from WoW to play with me on FFXI, but she never really got into it.

    I called and had the password reset on Sept. 16th and changed it back (stupidly) to the password it had been before, since that's what was saved on our other machines and I was lazy >< I logged in and at the time nothing seemed to be wrong. I think I did a few quests with her character and logged back off, planning to get items off her character later in the week before I cancelled it. Well, the next time I tried to log in a few days later I was told the password was wrong and I had a really bad feeling...

    I didn't get a chance to contact SE until a little after the beginning of October, and I had the password reset again and logged in to find this:

    http://i193.photobucket.com/albums/z...lieaccount.png

    The account had last been logged in on September 20th. RMTs had created a ton of new content IDs (the account only had 1 chara before), unlinked my sister's character from her original Handle so we wouldn't know she was online, and charged a world transfer to the account, even though the original character wasn't even moved to a new server... Only 5 new characters remained on the account, all lvl 1 war blond hume males, all on different servers, all logged out at the AH item sending character.

    My credit card had been charged almost $70 instead of the normal $13.

    I had the account locked later that day, and it has now been cancelled, but until my sister sends in the notary form they cannot refund me for all the charges the RMT caused.

    I warned my sister she may have a virus on her computer, which could threaten her WoW account as well, but she hasn't yet found anything. We had rarely logged her account on from our place, but still, virus scans on our computers here showed nothing. All 3 of our other accounts have security tokens, my sister's account did not.

    PS - I cannot find a phone number on the SE service site anymore, only e-mail or web chat... just FYI

  8. #28
    CoP Dynamis
    Join Date
    Sep 2009
    Posts
    251
    BG Level
    4

    Yeah that stub.exe is definitely suspect. It may be in the startup processes as well. You could kill it, and delete the directory that it is in. I think to see startup process you go to run and type: msconfig. Go to Startup tab and deselect the box. Hijack this can delete the registry entry too I believe. Interesting stuff thoughI'm going to do a search on this and see what i find.

  9. #29
    Fake Numbers
    Join Date
    Sep 2007
    Posts
    90
    BG Level
    2

    Here's another hijackthis log.

    Spoiler: show
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:37:51 p.m., on 30/10/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\GetRight\getright.exe
    C:\Program Files\GetRight\getright.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\WINDOWS\system32\libusbd-nt.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cintek.com/search.shtml
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Canada - The all-new MSN Canada, home of world-class services such as Hotmail, Windows Live Messenger, and News, Sports, Financial and Entertainment services
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Canada - The all-new MSN Canada, home of world-class services such as Hotmail, Windows Live Messenger, and News, Sports, Financial and Entertainment services
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Canada - The all-new MSN Canada, home of world-class services such as Hotmail, Windows Live Messenger, and News, Sports, Financial and Entertainment services
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Cintek.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: AVG Free Control Center.lnk = C:\Program Files\Grisoft\AVG Free\avgcc.exe
    O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
    O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.cintek.com/default.shtml
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1142582789905
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - LibUsb-Win32 - C:\WINDOWS\system32\libusbd-nt.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 8231 bytes

  10. #30
    Hydra
    Join Date
    Oct 2007
    Posts
    121
    BG Level
    3
    FFXI Server
    Asura

    Quote Originally Posted by MaachaQ View Post

    PS - I cannot find a phone number on the SE service site anymore, only e-mail or web chat... just FYI
    Square-Enix Support Center
    858 790-7529

  11. #31
    CoP Dynamis
    Join Date
    Sep 2009
    Posts
    251
    BG Level
    4

    C:\Program Files\GetRight\getright.exe
    C:\Program Files\GetRight\getright.exe
    Getright Information = THIS IS A WORM!

    C:\WINDOWS\system32\libusbd-nt.exe - Generic USB file for something

    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe - Run a MySQL server? No idea why it's here.

    C:\WINDOWS\System32\tcpsvcs.exe

    C:\WINDOWS\System32\snmp.exe smnp.exe = THIS IS A WORM

    Looks like you have a couple worms from what I see from the two I pointed out. I'm sure there's sites you could go to for removing these threats. I'm not entirely sure why AVG and other programs didn't pick these up. So my best recommendation is a full format. Removing this stuff doesn't always work as they're normally programmed to hide somewhere and scan your processor list to see if its running. If it isn't it'll re-install. Good luck. I would change both POL account passwords immediately and discontinue logging onto FFXI from this infected computer. Who knows how much information has been compromised excluding FFXI itself. Honestly man I'll be upfront. You should format both computers. If you need help on getting a clean copy of XP3 or Windows 7 just let me know I'll help you out to the best of my ability. I got 7 Ultimate running now with BIOS Mods. Just PM me don't post anything here.

    Okay. Since you have to reformat I made a guide on Warhammer Online forums. I suggest going to your computer manufacturer's website and pre-download the LAN and WAN drivers onto a USB drive or burn them onto a CD-R considering XP SP3 doesn't always pick up a LAN/WAN on a new install. Windows 7 will however. Post your two computers and their model numbers. I don't need their stats I can look it up and help you out. Here's the guide though:

    Greetings fellow players! You can call me Anderson, it's my last name. I have always preferred to go by my last name for some reason. Regardless I'm going to give you a quick run down on how to solve easy technical problems with your computer. First things first. No one should ever use dxdiag, or system information from within windows for any kind of system information. It's total garbage. It's quite sad that you have to use third parties within an operating system to find out about your system.



    I recommend using the program 'Everest Ultimate Edition'. You can just go to download.com and download the latest version available there. This program is really great. 90% of the time this program can identify everything that is installed in your computer from BIOS version to your hard drive manufacturer. When you install the program just let it launch aftewards. To get a summary of the basic of what your computer has.



    Click on 'Computer' and then 'Summary. It will list everything for you. Go to http://www.afn.org/~afn05420/Everest.htm to see an example. For some reason the link didn't work in this post.



    If you click on 'Report' button, choose 'System Summary' , then save as HTML file. You can send this to various people through e-mail that will basically see a snapshot of your computer. This will usually identify any device you have and what drivers you should download for it. You'd normally go to the manufacturer's website. If you can't find it there go to your computer's website, like dell.com, toshiba.com etc. They usually have all the drivers that came with your computer available for download that was installed into your computer.



    If you ever reformat a computer which I do often. Everest is a godsend when you need to know specifically what drivers to install once your OS is running again. I usually recommend this in order.



    1: Turn off Automatic Updates, double check in settings it's off when Windows loads

    2: Load Internet Explorer (choose express options or custom) then close it.

    3: Load Windows Media Player (choose express options or custom) then close it.

    4. Load Media Center (If Applicable) (choose express or custom) then close it.

    5. Load Internet Explorer, Go to Adobe.com (Install latest flash player)

    6. Go to Java.com (Install latest java)

    7. Go to Graphic Card's Website (ati.com/nvidia.com), Download Drivers then Install Them

    8. (Usually you'll restart your computer once/twice after this step)

    9. Go to your computer's website (dell.com/toshiba.com/etc)

    10. Normally here you download your Sound Driver, Network Driver, Dial-up Modem Driver, Wireless Driver

    11. Look At Computer Summary on Everest. Mine says: Motherboard Chipset Intel Lakeport i945p

    Go to intel.com or amd.com for your processor and search for i945p or whatever chipset drivers.

    Install them, it will prompt a reboot.



    12. Look at Computer Summary on Everest. Mine says: IDE Controller Intel(R) ICH7 Family Ultra ATA Storage Controllers - 27DF. A lot of hard drives these days use a Intel Controller. You'll want to download Intel Storage Matrix Manager. It will usually be an option when you search for your chipset.



    13. After all of these steps, Reboot one final time. Now go back and turn automatic updates on. If your computer is missing a driver usually XP and above will notice and install it if it can. Always double check 'Device Manager' to make sure you didn't miss anything. Your computer's website usually has your computer's specifications if Everest doesn't show it.



    14. Then install Antivirus, whether this be Avast, AVG, any of the free ones. I personally like Avast.

    15. And for the love of God, INSTALL FIREFOX with NOSCRIPT and AD BLOCK PLUS. If you're not used to Noscript you have to click on the Options box to allow sites you trust from the getgo to run any kind of scripting. It's pretty safe verse sites installing trojans and stealing your game information.



    16. That should be good enough to get you going from a fresh format. And give you the general idea of what to do if you don't know what devices you have and need drivers. USE EVEREST!



    There's tons of other problems that can happen with computers but for the most part I find a lot of problems point to having low memory. I'm pushing it running Warhammer with 2gbs of memory I don't suggest doing that unless you're using XP then you should be safe. For Vista and Windows 7, use 3 to 4gbs at least. With a 64 bit Windows you can use even more.



    If anyone ever has any technical problems, or questions just ask. I'll be happy to help. Remember. If you START suddenly having a problem, it's usually because you changed something or your computer automatically changed something. If you can't do a system restore, then try tracing it backwards from when it happened back through everything that went on the day before.



    - Anderson, Un-official Warhammer Player Tech Support

  12. #32
    Relic Shield
    Join Date
    Apr 2009
    Posts
    1,514
    BG Level
    6

    Quote Originally Posted by LinkNZ View Post
    Its definitely RMT as the account names are stupid like Emxdia, Emxlev, Emxgil and so on, unless my GF is RMT (lol why am I lending her gil for scrolls then!).

    And when I checked the sent box of them at the AH there is 1mil being sent somewhere but of course you can't see anything as it vanishes instantly. So the account has been used and then just left I suppose.

    Thanks for all the advice guys, have spent the whole day trying to 'clean' all the computers. Haven't found anything obvious spyware or virus etc wise, so I don't know what to think.

    We use Firefox, but she didn't have adblock, noscript etc on her laptop. So maybe somethings got in somewhere along the way. That's all loaded now so at least the future might be safer.

    My biggest fear now is that they server hopped on my dime also, there are 4 mules that aren't on Leviathan so I fear for the worst unwanted fee wise.

    Even though its not my main account and the GF doesn't play 'seriously' enough to warrant it, I think now I'll try and get a security token all the same. Would have been much better than this crazy situation. Hacked by RMT but not quite stolen account. :\

    EDIT: So I've been digging round the Content ID section of the account, some really detailed info there lol, never even looked in it before this. >_<

    They were created on the 3rd of October, 12 POL IDs and 1 World Transfer.

    So I'm out $37USD (I think), money down the RMT toilet. So yeah, despite it not really having anything worth stealing I still wish I had protected the account better now with a token. Something like this never even crossed my mind. All I thought is meh nothing worth stealing on it in game not what can they charge to my credit card with the account details.

    I know it could have been worse (and HAS been for some), but still lame.
    SE will refund your lost transfer money if you go through the compromised account process and they verify that it was compromised. Do not mention that you let your gf use it or they will likely repeat the TOS to you about how it is against policy to share accounts, possibly denying you.
    They have two separate situations one for accounts with token and without but they are in the same area and have the right info for you. There is lots of information on the Square Enix Support Center web site about how to do it as well as an easy to read FAQ.


    Good luck

  13. #33
    Fake Numbers
    Join Date
    Sep 2007
    Posts
    90
    BG Level
    2

    Ugh, yeah formatting sucks but it was prolly time to start-a-fresh anyway. Computer has been running sluggishly.

    I have no idea why AVG doesn't find this stuff, its always the question for me, does it not find anything cause its useless or because there is nothing there? lol.

    Thanks for the help Gethsemane and everyone else, I've got XP discs but I might have a look at the new Windows, heard its ok.

    Guess I know what I'm doing with my weekend now!

    Ordered another security token earlier for the GF, bit late now but at least it should help avoid this crazy situation in the future.

  14. #34
    CoP Dynamis
    Join Date
    Sep 2009
    Posts
    251
    BG Level
    4

    Well when you re-installed make sure you follow the install guide I gave for the most part. AVG works but that stuff may have gotten on your computer before AVG was installed. I know some viruses can evade any AV program with certain programming. Regardless the new Windows is pretty awesome, it's basically XP SP3 And Vista SP2's love child. Works well for FFXI too. But yeah definitely use firefox, noscript, adblock plus addons from now on.

    I'll send you a pm with some information about some stuff. Good luck. And also to anyone else that may be paranoid. Hijack This! is probably the best program to find suspicious processes that are running on your computer. But I'm sure these accounts being stolen only happen to maybe 5% of FFXI's population. Regardless everyone should secure their computer to the best of their ability and always install updates. If anyone else needs help just PM me or reply here.

  15. #35
    Fishing Guru
    Join Date
    Jan 2007
    Posts
    4,722
    BG Level
    7

    What mistress said about getting money back is what I also went through. They had to investigate/verify it was RMT before I could apply for the transfers funds to be charged back. So it took 2 months to verify it was a hacking then about 6 months for the 29.95 to be transferred back. I actually gave up on getting the money back so it was a nice surprise when it showed up.

Page 2 of 2 FirstFirst 1 2

Similar Threads

  1. JPButton hack, can you do it?
    By Marcatil in forum FFXI: Everything
    Replies: 30
    Last Post: 2005-10-30, 17:41
  2. Bikwin hacks
    By Bikwin in forum FFXI: Everything
    Replies: 15
    Last Post: 2005-10-05, 09:56
  3. Draw Distance Hack Movie
    By Maguspk in forum FFXI: Everything
    Replies: 44
    Last Post: 2005-09-21, 17:04
  4. Replies: 9
    Last Post: 2005-09-19, 06:44
  5. i got hacked by ...
    By Raiko in forum FFXI: Everything
    Replies: 25
    Last Post: 2005-09-16, 04:58
  6. Bikkwin hacks
    By Bikwin in forum FFXI: Everything
    Replies: 29
    Last Post: 2005-09-12, 00:18
  7. Screenshot Translation Please (New hacks?)
    By RustyMetal in forum FFXI: Everything
    Replies: 25
    Last Post: 2005-08-15, 18:21
  8. New Stealing hack?
    By Jaysensen in forum FFXI: Everything
    Replies: 8
    Last Post: 2005-05-16, 10:13