Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Graal Main Forum (English) (https://forums.graalonline.com/forums/forumdisplay.php?f=4)
-   -   Small Account Risk (https://forums.graalonline.com/forums/showthread.php?t=134257445)

Tigairius 12-24-2009 11:21 PM

Small Account Risk
 
Hello,

Today a link has been spread around, the link, said to be a place "you can talk about bad staff members, etc", is actually a malicious website created by the hacker that he uses to get access to your computer/accounts.

The link ended in "booter.info/index.html" and required you to accept a Java applet. If you accepted it, then the hackers may have access to your PC. Please note that the hackers may change the URL in the future to infect further people, please do not fall for their trick.

If you're unsure whether or not you're infected, check your C:\Windows\ directory for a file called "sch.exe" or "\\sch.exe" and delete it. The reboot your computer and change your passwords.

Please note that it is not guaranteed that this will fix the problem, and we strongly urge you not to accept any java applets on a website sent to you by a strange/unknown person on Graal.

Thanks,
Graal Administration

k_killar 12-24-2009 11:43 PM

SCH.exe is known to
  • Added as a Registry auto start to load Program on Boot up
  • Created as a new Background Service on the machine
  • Executed as a Process
  • Created as a process on disk

Hiro 12-24-2009 11:44 PM

is this the same type of trick i've heard of people using where they inject hidden HTML into PMs to make people accept things like this?

very clever

Sky 12-24-2009 11:46 PM

Lol, wow. I gota weird link earlier today and I hardly ever click links on graal so good thing I didn't. Thanks for the heads up though!

LordSquirt 12-24-2009 11:48 PM

I was sent the link through AIM :(

DuBsTeRmAn 12-24-2009 11:59 PM

That is just sad, Come on people.. Are you really so in the game that you are hacking people for items?

Unkownsoldier 12-25-2009 12:12 AM

I got one of these today, I ignored it because it was a link to a chat room and a guy told met to accept something. Thanks for the heads up.

Crimson2005 12-25-2009 12:18 AM

I didn't click the link because it was massed by a person called Scouser. Don't trust people from Liverpool ever, I think this is the real moral of the story.

Door 12-25-2009 12:21 AM

what happens if we don't delete it? Nothing bad has happened yet, and I hate messing around with my computer

Hiro 12-25-2009 12:23 AM

Quote:

Originally Posted by Door (Post 1546912)
what happens if we don't delete it? Nothing bad has happened yet, and I hate messing around with my computer

uh oh

DuBsTeRmAn 12-25-2009 12:23 AM

Quote:

Originally Posted by Door (Post 1546912)
what happens if we don't delete it? Nothing bad has happened yet, and I hate messing around with my computer

The virus is actually a key-logger, They will get all your password.. Nothing bad happend yet for you, But it will happen if you don't delete it.

Door 12-25-2009 12:33 AM

whatever man idc

Catbert 12-25-2009 12:35 AM

idc lol

RevolutionJS 12-25-2009 12:40 AM

Quote:

Originally Posted by Catbert (Post 1546923)
idc lol

They can get more then only your graal password if it is actually a keyllogger, like bank account and more.

Door 12-25-2009 12:42 AM

No one would be mean to me online cuz they all like me too much

Tenchry_P2P 12-25-2009 12:51 AM

schtasks and schtasks.exe.mui all good? cause you just said sch.exe?

deathbarrier99 12-25-2009 01:17 AM

Quote:

Originally Posted by RevolutionJS (Post 1546925)
They can get more then only your graal password if it is actually a keyllogger, like bank account and more.

Everyone here is like 14 no one has an actual bank account.

cyan3 12-25-2009 01:25 AM

Quote:

Originally Posted by deathbarrier99 (Post 1546947)
Everyone here is like 14 no one has an actual bank account.

17 - 20 years old is average age according to the poll in this thread and I wouldn't take a threat like this lightly because the stakes for ignoring it could be very high.

http://forums.graalonline.com/forums...hp?t=134256162

cbk1994 12-25-2009 01:28 AM

I can definitely vouch for the validity of this, I was testing it in a sandbox and one of the "hackers" IMed me the name of one of the files in the folder I was viewing (which happened to be what I was using to "decode" the java applet).

It's also the same people responsible for the "Era Hotkeys" keylogger that caused some trouble a while back.

Fulg0reSama 12-25-2009 03:01 AM

Thanks for the warning Tig. And good detective work chris.

Dnegel 12-25-2009 05:52 PM

Thanks for telling us this too. :)

CharlieM 12-25-2009 07:46 PM

I talked to the people who its trying to be blamed on and they said it isn't them, and that was actually the first they heard about it

cbk1994 12-25-2009 08:10 PM

Fortunately the site's down now, including the PHP file where the data was being sent. Not sure if they took it down or if it was a result of the abuse complaints that were sent in, but the domain and URL were hard coded into the virus, so I guess things are safe for now.

DuBsTeRmAn 12-25-2009 08:27 PM

Quote:

Originally Posted by cbk1994 (Post 1547125)
Fortunately the site's down now, including the PHP file where the data was being sent. Not sure if they took it down or if it was a result of the abuse complaints that were sent in, but the domain and URL were hard coded into the virus, so I guess things are safe for now.

I have been told that someone (cjclark) works for UPS or something and shut the server down ;]

CharlieM 12-25-2009 08:30 PM

Quote:

Originally Posted by DuBsTeRmAn (Post 1547130)
I have been told that someone (cjclark) works for UPS or something and shut the server down ;]

United Parcel Service?

WhiteDragon 12-25-2009 08:38 PM

Quote:

Originally Posted by CharlieM (Post 1547131)
United Parcel Service?

He must have mailed explosives to the server room.

DarknessShadow 12-25-2009 10:14 PM

The virus was never meant for graalonline,it was spread onto due to a friend who IM'd me that he did it.
The virus did not steal anything,or install any extra.
Sorry for inconvenience i have closed the hosting,the domain is still existing.

Quote:

Originally Posted by DuBsTeRmAn (Post 1547130)
I have been told that someone (cjclark) works for UPS or something and shut the server down ;]

He lied.

Quote:

Originally Posted by Tenchry_P2P (Post 1546933)
schtasks and schtasks.exe.mui all good? cause you just said sch.exe?

schtasks and schtasks.exe.mui are fine the virus droped to \WINDOWS\system32\sch.exe or \WINDOWS\sch.exe depending on your OS
The virus installs itself to
\WINDOWS\system32\sdra64.exe
\WINDOWS\system32\lowsec\local.ds
\WINDOWS\system32\lowsec\user.ds

-Darow

cbk1994 12-25-2009 10:16 PM

Quote:

Originally Posted by WhiteDragon (Post 1547134)
He must have mailed explosives to the server room.

lol'd
Quote:

Originally Posted by DarknessShadow (Post 1547160)
The virus was never meant for graalonline,it was spread onto due to a friend who IM'd me that he did it.
The virus did not steal anything,or install any extra.
Sorry for inconvenience i have closed the domain.

Good to hear :).

Imperialistic 12-25-2009 11:13 PM

Quote:

Originally Posted by DarknessShadow (Post 1547160)
The virus was never meant for graalonline,it was spread onto due to a friend who IM'd me that he did it.
The virus did not steal anything,or install any extra.
Sorry for inconvenience i have closed the hosting,the domain is still existing.


He lied.



schtasks and schtasks.exe.mui are fine the virus droped to \WINDOWS\system32\sch.exe or \WINDOWS\sch.exe depending on your OS
The virus installs itself to
\WINDOWS\system32\sdra64.exe
\WINDOWS\system32\lowsec\local.ds
\WINDOWS\system32\lowsec\user.ds

-Darow

Not sure how well I could trust a registered/active/scripter for the Graal Hack team.

Sorry, but everyone should still take it seriously just in case.

Matt 12-25-2009 11:26 PM

Quote:

Originally Posted by LordSquirt (Post 1546903)
I was sent the link through AIM :(

same here.

DarknessShadow 12-26-2009 04:27 PM

Quote:

Originally Posted by Imperialistic (Post 1547172)
Not sure how well I could trust a registered/active/scripter for the Graal Hack team.

Sorry, but everyone should still take it seriously just in case.

I have not been apart of their team since the backdoor incident,I am in no way against graalonline i was there for coding experience.

Imperialistic 12-27-2009 12:43 AM

Yea, I was in al-Qaeda just for the experience!

Still means I'm trustworthy, right?!1

Geno 12-27-2009 01:11 AM

!!! Ban the hax0r!!!

DarknessShadow 12-27-2009 03:55 AM

Quote:

Originally Posted by Imperialistic (Post 1547333)
Yea, I was in al-Qaeda just for the experience!

Still means I'm trustworthy, right?!1

You said "Not sure how well I could trust a registered/active/scripter for the Graal Hack team."

I'm not registered,active or a scripter for GH
Your point is invalid, raise your IQ level and come back.The reasons for the virus's were explained no need for skids who don't understand them to get involved.
Thread needs to be locked the risk is gone and is just causing randoms to rage.

DarkReaper0 12-27-2009 05:49 AM

Quote:

Originally Posted by DarknessShadow (Post 1547367)
You said "Not sure how well I could trust a registered/active/scripter for the Graal Hack team."

I'm not registered,active or a scripter for GH
Your point is invalid, raise your IQ level and come back.The reasons for the virus's were explained no need for skids who don't understand them to get involved.
Thread needs to be locked the risk is gone and is just causing randoms to rage.

The fact that you knew who started the virus spreadings, and what it was originally intended for is unnerving enough that I don't think Shadow is out of line with his responses.

CharlieM 12-27-2009 08:01 AM

Quote:

Originally Posted by DarkReaper0 (Post 1547377)
The fact that you knew who started the virus spreadings, and what it was originally intended for is unnerving enough that I don't think Shadow is out of line with his responses.

He said the virus wasn't mean't for graal online. How is that unnerving?

Darow is a brilliant coder, and if he gets experience now he can go into the coding field and who knows maybe he will be the next bill gates.

I know he's already made his own systems (Nothing bad about them)
In the field that he runs in, he probably runs into a lot of coders who make bad things, thats probably why he knew about the virus

Loriel 12-27-2009 02:59 PM

Quote:

Originally Posted by Imperialistic (Post 1547333)
Yea, I was in al-Qaeda just for the experience!

Still means I'm trustworthy, right?!1

Equating a geek hobby with terrorism? Seriously, now?

Unkownsoldier 12-27-2009 06:48 PM

I took a plane and crashed it into a building killing thousands of people just for the experience. V.S. I coded a small program that could potentially hurt your computer. hm...


All times are GMT +2. The time now is 08:36 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.