Announcement

Collapse
No announcement yet.

Another #$%@% virus warning.

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Another #$%@% virus warning.

    Hey, heads up if you've used FFXIcyclopedia recently, You may want to take a look at this.

    Flash ad vulnerability exploit, which means they probably just got everyone with flash enabled. Check your machines for spyware and malware.

    Be the Ultimate Ninja! Play Billy Vs. SNAKEMAN today!

  • #2
    Re: Another #$%@% virus warning.

    oh great, has that website become another Allakahzam?

    Comment


    • #4
      Re: Another #$%@% virus warning.

      Second computer, virtual box, dual boot, etc. We've been over this, people.

      Comment


      • #5
        Re: Another #$%@% virus warning.

        Yeah, I had to help with a computer that was compromised most likely by this (posted about it in another thread). Fortunately, on at least some systems, the keylogger has the side-effect of breaking FFXI, providing a warning sign in this case that led us to detecting the compromise.

        The files you'll want to check for are in C:\WINDOWS\system32 and are named smart.dll and lovefly.dll. You'll need to go through some effort to unregister and delete them.

        Some relevant threads:

        My experiences with the system: http://www.ffxionline.com/forums/gam...hing-ffxi.html

        BlueGartr thread regarding the error: Order of the Blue Gartr • View topic - POL: "No such interface supported" = virus/keylogger BEWARE

        BlueGartr thread regarding the keylogger itself (includes removal instructions): Order of the Blue Gartr • View topic - "Interface not supported"? You have been hacked! Read this!

        W6r forum thread containing a guide to securing Firefox against these kinds of things (I'm hoping the mods won't mind as this is very useful and valuable technical information that doesn't relate to or promote said third-party app): GUIDE: Protecting your web browser. - Windower (edit: I see Taskmage beat me to editing the post, it's good to see this info mirrored here.)

        Worth noting that having either NoScript or FlashBlock configured as suggested would have prevented this if ffxiclopedia is not whitelisted; however, certain site features on ffxiclopedia don't work if it's not whitelisted in NoScript... If you're just browsing for info though it's fine to leave it untrusted.
        Last edited by Lunaryn; 06-18-2008, 09:37 AM. Reason: removed link to windower forums; modified post content regarding
        Kumei, pickpocket of Midgardsormr(Bastok Rank 10)
        DRK99,DNC91,THF90
        Alchemy 72, Smithing 51, Goldsmithing 48, Leathercraft 23, Fishing 20
        Koren, San d'Orian Adv.(Rank 10)
        WHM95,BLM90,SMN85,RDM82,SCH49
        Woodworking 29,Cooking 20
        All celestials(Trial-Size), Fenrir, Diabolos, Alexander, Odin
        Myrna, Windurstian Merchant
        Clothcraft 24
        Nyamohrreh, Windurstian Adv.(Rank 6)
        BST90,WHM56,DNC45

        Comment


        • #6
          Re: Another #$%@% virus warning.

          Originally posted by Feba View Post
          Second computer, virtual box, dual boot, etc. We've been over this, people.
          Feba forgot to mention his ultimate technique for preventing his FFXI account from getting hacked: stop playing FFXI.
          Lyonheart
          lvl 75 WAR, 75 BST, 75 BLM, 75 NIN, 47 SCH
          Cooking 100.0+3+3, Culinarian's Signboard, Raw Fish Handling, Noodle Kneading, Patissier
          Fishing 60

          Lakiskline
          Bonecrafting 100.0+3+3,
          Leather 60+2, Woodworking 60, Alchemy 60
          Smithing 60, Clothcraft 55, Goldsmithing 54.1, Cooking 11
          Boneworker's Signboard, Bone Purification, Bone Ensorcellment, Filing, Lumberjack, Chainwork

          Comment


          • #7
            Re: Another #$%@% virus warning.

            That's not really an effective strategy, unless you never touch POL. Actually, I'm not sure how secure the files are that store password information, but I doubt it would be too hard for someone to make malware that would find that easily too.

            Comment


            • #8
              Re: Another #$%@% virus warning.

              Hmm, apparently I'm unaffected. File checks turned up nothing, SpyBot and AVG didn't find anything, POL Linkshell Communities still has my character listed as having all the HQ stuff he logged off with.

              I'd like to put up the latest NoScript and FlashBlock versions though, anyone know how to get around Download Error -228 in Firefox? The solutions in the FAQ and mozilla boards aren't working for me. {edit} nvm, found it. Right-click, save to desktop, then drag the new .xmi file over into an open window of Firefox to install. I think this is Qwest's security filters again.
              Last edited by Kitalrez; 05-29-2008, 09:15 PM.

              Be the Ultimate Ninja! Play Billy Vs. SNAKEMAN today!

              Comment


              • #9
                Re: Another #$%@% virus warning.

                I've not had any problems but I did log on this morning to find an extra 8k on my character with no missing items or gear
                Rahal Gerrant - Balmung - 188 DRK
                Reiko Takahashi
                - Balmung - 182 AST, 191 BLM, 182 SCH, 188 SMN
                Haters Gonna Hate



                Comment


                • #10
                  Re: Another #$%@% virus warning.

                  Son of a !!! Thanks for this thread, I ran my anti virus and sure enough I was infected, I don't think it managed to do a whole lot, I upgraded to the latest adobe flash player... -.-

                  Comment


                  • #11
                    Re: Another #$%@% virus warning.

                    I did the whole debug process and ran a virus scan and found I wasn't infected. I still don't know where that extra 8k came from though
                    Rahal Gerrant - Balmung - 188 DRK
                    Reiko Takahashi
                    - Balmung - 182 AST, 191 BLM, 182 SCH, 188 SMN
                    Haters Gonna Hate



                    Comment


                    • #12
                      Re: Another #$%@% virus warning.

                      Originally posted by LyonheartLakshmi View Post
                      Feba forgot to mention his ultimate technique for preventing his FFXI account from getting hacked: stop playing FFXI.
                      Actually that's not really a solution. The only sure way to not get hacked is to use the console clients(PS2, Xbox360) exculuivley and never log into the FFXI LS community site and never use your real FFXI ID and password on any other site(basiclly never get your FFXI ID anywhere near a PC). The lame hackers have not found a way to hack the console editions at all so you're about 99% safe if you just play on those....
                      Shadowneko's FFXI Newbie Guide 2009
                      (have fun MMO players ^^)
                      Jon Davies AKA: Shadowneko of Midradsomr...soon to be transferred to Quetzalcoatl

                      Comment


                      • #13
                        Re: Another #$%@% virus warning.

                        Originally posted by Shadowneko View Post
                        The only sure way to not get hacked is to use the console clients
                        Wrong.

                        As has been pointed out, it isn't rocket science to make your web browsing extremely safe.

                        Comment


                        • #14
                          Re: Another #$%@% virus warning.

                          Originally posted by Shadowneko View Post
                          Actually that's not really a solution. The only sure way to not get hacked is to use the console clients(PS2, Xbox360) exculuivley and never log into the FFXI LS community site and never use your real FFXI ID and password on any other site(basiclly never get your FFXI ID anywhere near a PC). The lame hackers have not found a way to hack the console editions at all so you're about 99% safe if you just play on those....
                          What? Not having a FFXI account doesn't prevent getting your FFXI account from getting compromised?

                          I guess I need to be more clearly facetious in the future.
                          Lyonheart
                          lvl 75 WAR, 75 BST, 75 BLM, 75 NIN, 47 SCH
                          Cooking 100.0+3+3, Culinarian's Signboard, Raw Fish Handling, Noodle Kneading, Patissier
                          Fishing 60

                          Lakiskline
                          Bonecrafting 100.0+3+3,
                          Leather 60+2, Woodworking 60, Alchemy 60
                          Smithing 60, Clothcraft 55, Goldsmithing 54.1, Cooking 11
                          Boneworker's Signboard, Bone Purification, Bone Ensorcellment, Filing, Lumberjack, Chainwork

                          Comment


                          • #15
                            Re: Another #$%@% virus warning.

                            It's not a really solution to cancel the game...if you really want to play it ^^
                            Shadowneko's FFXI Newbie Guide 2009
                            (have fun MMO players ^^)
                            Jon Davies AKA: Shadowneko of Midradsomr...soon to be transferred to Quetzalcoatl

                            Comment

                            Working...
                            X