Forum Settings
       
This Forum is Read Only

My Account is goneFollow

#1 Jun 02 2008 at 7:14 AM Rating: Excellent
Hey guys, just a heads up, my account has been stolen and the password has been changed. I am trying to sort things out with SE today but in the meantime please not that it is not me playing my character.
____________________________
[ffxisig]64258[/ffxisig]
Sky [O] ZM 16 "The Celestial Nexus"
Sea [X] COP Mission 5-2 "Desires of Emptiness"
#2 Jun 02 2008 at 9:22 AM Rating: Excellent
*
93 posts
Don't worry you're not alone, mine was hacked into and the password changed on Saturday....still waiting for a representative to talk to me....after 1.5 hours :(
____________________________



FFXIV Signature
#3 Jun 02 2008 at 10:45 AM Rating: Excellent
*
221 posts
I'm from Garuda and my account was hacked on May 30th. My boyfriend was hacked on the same day. 2 of my linkshell mates were hacked the next day. The reason I'm posting on Seraph is because my boyfriend's account was moved to your server. His in game name is Tuffguy. He is a 75 nin and a 75 rng. He has 98+2 fishing (all done the hard way over 3 years) and 100+3 woodworking. Based on your AH history, his character is being used to buy things in order to be a fishing bot in SSG. If anyone sees Tuffguy online, please be aware that it is a hacked account being used by RMT. If you can have him jailed for it, please do so. POL's phone number has been busy for 2 hours. Their live chat has not responded for the same amount of time. We did contact POL as soon as we discovered this thievery. He was told his account would be locked. It wasn't. He contacted a GM through a friend on May 31st and was once again told his account would be locked. It wasn't. I just called a GM again from my friend's account and he told me there was nothing he could do. We are at a loss. I'm sorry his account is being used for RMT gain on your server. The ISP number that hacked my computer is 125.46.104.172. It is located in Beijing, China. The trojans that we know of that are being used to do this are:
FakeAV.100
smart.dll
rsbo.exe
kb1ss1p.dll
kb1ssp.sys
in3.dll (note if you find a program with a long name on this program it is a plugin3.dll and safe)

To anyone who uses a computer and has not been hacked yet, please check your computer for these programs.

I use Firefox, MaxRegistry Cleaner, TrojanHunter, and Norton. None of these programs were able to detect these intrusions.

To find and remove any of these files go to Start Menu > Run > type in "regedit" and click OK > Highlight My Computer > click on edit > click on find > type in FakeAV.100. Repeat these steps for all of the above programs and delete all that you find immediately and rest your POL password right away.

Note: it was my computer that was compromised and not my boyfriend's. He logged onto my computer for all of 2 minutes to switch his macros over to his and they still got him.

Be safe and good luck to everyone.

edit: I forgot another important piece of information. You should also search your entire registry for these programs. To do this follow these instructions:

Start Menu > Search > All Files and Folders > Advanced Options > search system folders, hidden folders, subfolders > type in the search field: FakeAV.100. Delete it right away if it is there. Once again, repeat all of these steps for all above malicious files.

It has been discovered that Adobe Flash Player was compromised. The older version will put the file smart.dll on your computer. I recommend updating Flash Player asap and use the above steps once again. You can update Flash Player here :

http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash&ogn=EN_US-gntray_dl_getflashplayer

I know this seems like a lot of work, and I'm sorry I didn't add the rest of this information sooner. From the horrible experiences that so many people are going through by losing their accounts, it's worth a little trouble to not become one of the many unfortunate victims.


Edited, Jun 4th 2008 1:18pm by Bouncybouncy
____________________________
Windy Mule
75 BLM, WHM, SMN

SorenIsKing wrote:
I have returned!

And don't know what to do :P
#4 Jun 02 2008 at 10:49 AM Rating: Decent
*
154 posts
Good luck with SE. Their customer service is a complete joke, if you can even get through.

"Hi, thank you for calling today. Please pick a number between 1 and 10 trillion. If you guess correctly I will help you out. If not I will lie to you just to make you feel better. Have a nice day and thank you for paying us for years."



Edited, Jun 2nd 2008 2:50pm by Ilostmyclothes
____________________________
Tuffguy 75 nin, 75 rng, other useless jobs ^^
100+3(+3) woodworking, 98 fishing, 60 alchemy, 60 bonecraft, 60 smithing, other assorted junk




#5 Jun 02 2008 at 11:14 AM Rating: Decent
*
154 posts
BTW I wish you the best of luck with your account. I didn't mean anything negative towards you. I'm just so sick and tired of being lied to by POL and the useless GM's that are supposed to be there to help us.
____________________________
Tuffguy 75 nin, 75 rng, other useless jobs ^^
100+3(+3) woodworking, 98 fishing, 60 alchemy, 60 bonecraft, 60 smithing, other assorted junk




#6 Jun 02 2008 at 3:27 PM Rating: Good
*
190 posts
bf's account was also hacked and has been getting busy signals or been on hold off and on all day.. if he's still on hold when they close..someone will have hell to pay tomorrow lol

____________________________
75- Whm Mnk Blm Rdm Nin Smn Sch Drg Sam Rng
73pld 68brd 44war 42bst 41drk 40thf 33blu 21cor
765+ merits~ oi
#7 Jun 02 2008 at 8:33 PM Rating: Good
*
93 posts
just got access to my account, everything is gone, just as expected so unless GMs get me most of the gear back this is gonna be goodbye ffxi
____________________________



FFXIV Signature
#8 Jun 03 2008 at 10:29 AM Rating: Good
Avatar
*****
16,240 posts
SE is doing rollbacks.

As long as you didn't get Homam or something in the week before you were hacked, you should get most of what you lost back.
____________________________
All jobs at level 99 Bard 4 Life
Hanging out in the Ionosphere these days ::Finale II HNM
Daurdabla 85 completed 3-18-2013 *** Gjallarhorn 95
Turin wrote:
(Zelduh)'s won the argument by going so far off the deep end that no one is willing to follow.
#9 Jun 03 2008 at 11:55 AM Rating: Excellent
Thank you for the support guys, I was sure I am not the only one who went or is going through this. My cousins account is gone as well, the same day as mine. He for fortunate to have his frozen before his info was changed. I was not as lucky. Since all my information on the account has been replaced, I am currently going through the "Compromised Account" scenario. Being that I am out of the country at the moment you can only imagine what a pain that is. Apparently I have to provide a notarized letter from a US notary that I am who I say I am. Well in any case time will tell. I will keep you guys posted when and if I am back. In the meantime I believe I was able to get my account frozen from the hands of RMT. Thank you again for the support everyone.
____________________________
[ffxisig]64258[/ffxisig]
Sky [O] ZM 16 "The Celestial Nexus"
Sea [X] COP Mission 5-2 "Desires of Emptiness"
#10 Jun 03 2008 at 2:44 PM Rating: Excellent
*
154 posts
I have been waiting since the 30th for the email from SE. They appear to take their sweet time. There is a huge thread on hacked accounts that includes the form you can print out. I printed one and just got it notarized and will send it out tomorrow. If you want to see the thread it is here.

http://www.bluegartrls.com/forum/viewtopic.php?f=2&t=28240&st=0&sk=t&sd=a&sid=1002c8e39e1a99ee1b53fa256ff77f98
____________________________
Tuffguy 75 nin, 75 rng, other useless jobs ^^
100+3(+3) woodworking, 98 fishing, 60 alchemy, 60 bonecraft, 60 smithing, other assorted junk




#11 Jun 04 2008 at 9:33 AM Rating: Decent
*
221 posts
Just to add to Tuff's post about the notarized form: We are sending it certified, overnight mail. This will give us a confirmation and tracking number and will require a signature upon delivery. This way SE cannot claim they never received the form.

We've also read on some forums that even people who sent in the notarized form, have all their original registration forms, and can verify the first and last four numbers of the credit card they were using are being told SE cannot verify the account was theirs. If this is the case, then SE has committed credit card fraud by charging your credit card for however many years you've played. In Tuff's case of four and a half years of playing, that amounts to over $900 charged to him with all the mules he had. Since SE has a headquarters in California, they are bound by American law and this is a Federal offense. Sue the bastards! That's what we will do.

edited due to fast typing and poor spelling :P

Edited, Jun 4th 2008 1:36pm by Bouncybouncy
____________________________
Windy Mule
75 BLM, WHM, SMN

SorenIsKing wrote:
I have returned!

And don't know what to do :P
#12 Jun 06 2008 at 10:31 AM Rating: Good
*
154 posts
If you get bored while trying to get your accounts sorted out feel free to visit the Garuda forums.

We have a thread full of nonsense called 100 pages that's just for fun.

It's where I spend my time to try to keep what's left of my sanity. ^^
____________________________
Tuffguy 75 nin, 75 rng, other useless jobs ^^
100+3(+3) woodworking, 98 fishing, 60 alchemy, 60 bonecraft, 60 smithing, other assorted junk




#13 Jun 08 2008 at 3:32 PM Rating: Good
*
195 posts
funny, cause allison was on that server and switched to seraph as well.
She got a nice lu shang rod to, which never belonged to her.
However, Its not escaflownes, or crookedsparkles. I do not know where she stole the rod from. no, no, Maybe I know now.........
#14 Jun 10 2008 at 5:40 AM Rating: Excellent
Nope wasn't mine...I wish I had a Lu Shangs lol.
____________________________
[ffxisig]64258[/ffxisig]
Sky [O] ZM 16 "The Celestial Nexus"
Sea [X] COP Mission 5-2 "Desires of Emptiness"
#16 Jun 14 2008 at 11:42 PM Rating: Default
7 posts
I'm new to these forums, but not at all new to the recent hacking b.s.

On 6/2 about 7:30am CST I was on Lakshmi, leveling my 58 drg a little before work. I get the screen about my account being accessed from another terminal, but I have to get to work so I'll deal with it in the afternoon. Yeah... well as you all know, couldn't get through to the 800 #. Logged in with my separate account and couldn't find my character online. Finally spent 2 hours waiting in LiveChat and got an SE rep who reset my passwords. I log in and find out I lost almost all my drg gear except my AF and all the gear I had for my 75 thf except for AF again and other rare/ex items. I was moved to Fenrir and my character name was changed. All said my gil/item loss was almost a mil~at least by Fenrir AH prices.

Spent all day 6/3 trying to get through to the 800# again to get the transfer fee suspended since I didn't authorize it. After being on hold for 2 hours I was told that they couldn't do anything (even though they take care of the billing portion~go figure)I'd have to contact a GM in game.

On 6/4 I waited 2 hours and got a GM that just referred me to the page about the data recovery service. Told me to come back and let a GM know if I really wanted to pursue that path.

6/5&6 Waited for a GM for 2 hours and 4 hours respectively with no luck.

6/7 Waited 3 hours for a GM to take my call, decided I wanted to take a shower. They responded when I was AFK. Made another call and waited 4 more hours and I got a GM. "You'll have to call the 800# for the charges on the unauthorized transfer..." and all the hurdles and hoops you have to pass to get them to agree to investigate your account. So, now it's been 7 days and maybe I'll get an answer to whether I get anything restored or not.

My biggest concern of all is farming for gil again with my thf. Last Nov when my original character was hacked and I got it back I took time to farm a coffer key in Crawlers when I was reported by other players that came along after I'd been there 2 hours and I was charged as stealing mobs (only 4 of them over and over) and my account was banned. Even when I explained what was going on all I got was "Sorry, you did nothing wrong but we can't open your account again. Oh, and by the way you have to go buy another startup disc, and your credit card is banned for now too." At that time I was a 75 bst, 60 war, 54 whm, 50 sam/pld/drk/smn/blm/nin, 30 blu, 25 brd/rng/mnk/thf/rdm/cor/drg/pup.

My first intention was just to warn you all, or anyone else that looks at this thread that if you're hacked you will probably get a whole new name and a new server for your character.

I want my account back...SE better be e-mailing me very soon.
This forum is read only
This Forum is Read Only!
Recent Visitors: 28 All times are in CDT
Anonymous Guests (28)