home   |   contact us   |   sitemap   |   advertising Free Online Games
Free MMORPG

The Free MMORPG Games- Free MMORPG - P2P Games - Open Beta - Closed Beta - Browser Based - Non-English - Other Free Games - Top 50


Go Back   Onrpg Free MMORPG Forums > Online Games > Other Games > Final Fantasy XI
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 01-01-2008, 07:55 AM   #1 (permalink)
Lord Mog
Loric's Lunatic
 
Lord Mog's Avatar
 
Join Date: Aug 2006
Location: In the Mana Tree.
Posts: 2,014
Reputation: 10
Send a message via AIM to Lord Mog Send a message via MSN to Lord Mog Send a message via Yahoo to Lord Mog Send a message via Skype™ to Lord Mog
MMOFaces Profile: No thanks.
Default Recent Account Hackings and How To Keep Your Account Safe (PLEASE READ!)

Due to the extremely recent account hackings of Final Fantasy XI members, I've decided to spread the word and help keep OnRPG (and potentially anyone else) from experiencing this tedium.

According to The Order of the BlueGartr, popular Final Fantasy XI information database sites such as Somepage, FFXIAH, Allakhazam, and many more have been infected with virus dropping packets that download secretly onto your computer and keylog your Final Fantasy XI account.

DO NOT GET CURIOUS AND LOOK AT THESE WEBSITES!

Instead, please read these step-by-step instructions posted by Airenn on the BluGartrLS forums:

First things first:

Actions that need to be taken immediately:
1) Take this post to your LS Forums. Post it.

2) No forums? LS Message, broadcast on FFXI, send them(LS), friends, people you know, to BG to read it. (Publicizing BG and preventing hacks<3)

3) Run Anti-Spyware.

4) As for your PW method? You're on your own.

Programs you should be getting: (A BG rep can check these links, there is no maliciousness hidden within.)
1) Ad-Aware Free Version
2) Spy-Bot Search&Destroy
3) AVG Free Spyware Edition AND AVG Free Virus Edition Get both, they are 2 seperate downloads. I have caught so many problems with this that Norton never picked up. <3
4) Firefox
5) ProcessGuard
6) CCleaner
7) Kapersky Anti-Virus -- Proved to show that it can prevent this Trojan from Auto-Downloading.

Step-by-Step Walkthrough:

1) Get those programs and open them. Update them first, once they are installed.
2) Run them, fix any problems, delete any bad files, etc, etc.
3) Once all that is done, do this:
Start Menu > Search > All Files and Folders > Click Advanced Options > Search System Folders, Hidden Folders, Search Subfolders > Type in the Search Field: rsbo.exe

Repeat said steps for ALL these files:

rsbo.exe
kb1ss1p.dll
kb1ss1p.sys
in3.dll

4) If you find the files, delete them asap. If you cannot delete them, post here, we'll try to figure out how to do it.

5) Search the Registry by doing this:

Start Menu > Run > type in "regedit" and click OK > Highlight My Computer in the newly opened Regedit box > Click on Edit > Click on Find > type in rsbo.exe

Repeat said steps for ALL these files:

rsbo.exe
kb1ss1p.dll
kb1ss1p.sys
in3.dll

6) If you find anything with those listed delete them immediately. Note: you may find something with a really long name when you look for "in3.dll" it's not it, it's actually a plugin3.dll

Secondary note: You will find strings related to your previous Start Menu > Search functions. It is just indicating that you recently did a search on this. Just to clear that up, I know it scared a lot of people.
Ashokan wrote:
Zosi's right.

It is okay if what you found is in HKEY_CURRENT_USER/Software/Microsoft/Search Assistant/ACMru/5603, probably looks something like:

Code:
[HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
(Default) REG_SZ Value not set
000 REG_SZ in3.dll
001 REG_SZ rsbo.exe
002 REG_SZ kb1ss1p.dll
003 REG_SZ kb1ss1p.sys

That's just the stuff you searched for in start button -> search. You can test it. Type in something completely random, refresh that regedit 5603 folder and it will be there.

7) Restart your computer, research to make sure it's all gone. You should be clean.

8) If you are all clean, now is the time to change your password in case RMT have gotten it. Do so. If you want 100% extra security, call SE, have them change it.


For more information please look at the official thread.

And remember: SPREAD THE WORD! The more people who know about this, the safer we all are.

Happy Gaming.

- Lord Mog
__________________
Quote:
Originally Posted by hksmrchan View Post
Sex change.

It's a cash item.



Last edited by Lord Mog : 01-01-2008 at 05:47 PM.
Lord Mog is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-01-2008, 11:10 AM   #2 (permalink)
Seiyuuki
Diddy Kong's Boxers
 
Seiyuuki's Avatar
 
Join Date: Jan 2007
Posts: 672
Reputation: 10
MMOFaces Profile: None Yet
Default

Cheers for that, I was on Alakazam (or wehatever its called), since reading some of the topics I've been very careful about what I click on an making sure I let my antivirus finish its scans now >.<

Looked and I'm clean so far as I know, though I did have susspicions when I tried to log on and it said I had no content ID when it was in the middle of my free month :S

Besides, theres nothing of value on my character at this lvl, so I'd imagine it would just be a waste of their time.
__________________

Playing
Silkroad
IGN: Seidhal - Server: Venus
Unreal Tournament 3
IGN: Munkerz
Seiyuuki is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-01-2008, 01:07 PM   #3 (permalink)
Liberty Spikes
Sonic’s Milkshake
 
Liberty Spikes's Avatar
 
Join Date: Dec 2007
Location: The Netherlands
Posts: 307
Reputation: 6
MMOFaces Profile: Sucks
Default

Thanks Lord Mog, can be really useful for some of us, and I think it helps for World of Warcraft players also (Allakhazam).
Liberty Spikes is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-01-2008, 05:50 PM   #4 (permalink)
Lord Mog
Loric's Lunatic
 
Lord Mog's Avatar
 
Join Date: Aug 2006
Location: In the Mana Tree.
Posts: 2,014
Reputation: 10
Send a message via AIM to Lord Mog Send a message via MSN to Lord Mog Send a message via Yahoo to Lord Mog Send a message via Skype™ to Lord Mog
MMOFaces Profile: No thanks.
Default

Quote:
Originally Posted by Seiyuuki View Post
Cheers for that, I was on Alakazam (or wehatever its called), since reading some of the topics I've been very careful about what I click on an making sure I let my antivirus finish its scans now >.<

Looked and I'm clean so far as I know, though I did have susspicions when I tried to log on and it said I had no content ID when it was in the middle of my free month :S

Besides, theres nothing of value on my character at this lvl, so I'd imagine it would just be a waste of their time.
Oh, indeed. I was searching on Somepage and FFXIAH for two hours before I knew they were both infected, and I freaked out because of it.

Quote:
Originally Posted by Liberty Spikes View Post
Thanks Lord Mog, can be really useful for some of us, and I think it helps for World of Warcraft players also (Allakhazam).
Indeed. If you look closely at the BlueGartr post, you'll find also that some WoW players have been hacked like this as well.
__________________
Quote:
Originally Posted by hksmrchan View Post
Sex change.

It's a cash item.


Lord Mog is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-01-2008, 06:44 PM   #5 (permalink)
lothia
Staff Admin
 
lothia's Avatar
 
Join Date: May 2006
Location: Kent Washington
Posts: 3,679
Send a message via AIM to lothia Send a message via MSN to lothia Send a message via Skype™ to lothia
MMOFaces Profile: None Yet
Default

NOOO I USE THOSE WEBSITES EVERYDAY. I will do a virus scan right now, im scared, I really am. (not joking)
__________________


Moderator since before Aug 2004.
I'm a dude
email me at lothia@gmail.com
FFXI Tsukisa: 60pld/30War
lothia is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-02-2008, 12:12 AM   #6 (permalink)
Cingal
OnRPG Elite Member!
 
Cingal's Avatar
 
Join Date: Jun 2006
Posts: 5,063
Reputation: 26
Send a message via AIM to Cingal
MMOFaces Profile: Cingal
Default

So, it's a key logger?

My sign in is automatic, I don't type anything been that way for a year, so, is it worth checking or "Better to be safe than sorry"?
__________________
Come on down to the other side,
Come with us through the gates of hell.

Where we'll drag you from where you are to where you belong.
Cingal is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-02-2008, 12:26 AM   #7 (permalink)
Lord Mog
Loric's Lunatic
 
Lord Mog's Avatar
 
Join Date: Aug 2006
Location: In the Mana Tree.
Posts: 2,014
Reputation: 10
Send a message via AIM to Lord Mog Send a message via MSN to Lord Mog Send a message via Yahoo to Lord Mog Send a message via Skype™ to Lord Mog
MMOFaces Profile: No thanks.
Default

Quote:
Originally Posted by Cingal View Post
So, it's a key logger?

My sign in is automatic, I don't type anything been that way for a year, so, is it worth checking or "Better to be safe than sorry"?
I also have an automatic sign in, but it's defiantly better safe than sorry. Two years of playing FFXI + losing an account = absolute fail.

I've also read that this "keylogger" also decrypts your saved account info, as well.
__________________
Quote:
Originally Posted by hksmrchan View Post
Sex change.

It's a cash item.


Lord Mog is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 01-02-2008, 10:37 AM   #8 (permalink)
Darksin
OnRPG Elite Member!
 
Darksin's Avatar
 
Join Date: Jul 2006
Location: netherlands
Posts: 4,912
Reputation: 10
MMOFaces Profile: PointlessBeing
Default

I never go to these sites xD So i'm probably safe
__________________



Quote:
Originally Posted by Untouchable View Post
Listen Darksin,i`m not your average 10 year old.My IQ is 600!And one more
thing,I`m the fucking most smartest kid in my class!

>: (
Epic don't you think? xD
Darksin is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 10:49 PM.

Forums Section List
Main Category Free Games Online Games Upcoming Games Online Games Upcoming Games
General Free MMORPG Fiesta Online    Maple Story Guides Trickster DOMO - Dream of Mirror Online
RolePlaying Free MMO & MMOFPS Conquer Online    Maple Story Buy/Sell/Trade WarRock Online Seal Online
Newbie Zone Korean/Foreign Games DragonGem Lunia World of Warcraft Age of Armor
  Browser/MUDs FlyFF Ragnarok Online Other Games Exteel
  Single Player RPGs Ghost Online Rakion    Rappelz Infinity
  Free MMORPG Requests Guildwars Runescape    Final Fantasy XI Cabal Online
    Gunz Online Scions of Fate (YulGang)    Goonzu Online Granado Espada
    Maple Story Silkroad    Gunbound Nostale



Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC8
Onrpg, Copyright ©2003-2007, BlueCastle Media

Copyright © 2004-2007 BlueCastle Media