Is it possible to get hacked thru the client?

Discussion in 'General Discussion' started by Veylen The AenigmA, Sep 6, 2014.

Thread Status:
Not open for further replies.
  1. Veylen The AenigmA

    Veylen The AenigmA Avatar

    Messages:
    986
    Likes Received:
    699
    Trophy Points:
    105
    Gender:
    Male
    Location:
    rogers
    I noticed after past release my OS was doing things it had never done before and was acting as if it was beig controlled remotely. Had really wierd operations running in system processes etc etc. my mouse would move on its own and randomly launch programs when i wasnt even touching my computer. What gives? Sota and archeage are about the only games i play. I do have steam installed and all i use it for is heroes of might and magic. I ran virus and spyware scand and it found nothing. I noticed after launching and closing sota during thexlasy day of test my whole computer ran at least 50% slower than normal and still does. All of my windows security updates are installed and my os is up to date(win 8.1)
     
  2. Beaumaris

    Beaumaris Avatar

    Messages:
    4,301
    Likes Received:
    7,423
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Caladruin
    Do you run with a firewall?
     
  3. Veylen The AenigmA

    Veylen The AenigmA Avatar

    Messages:
    986
    Likes Received:
    699
    Trophy Points:
    105
    Gender:
    Male
    Location:
    rogers
    Ya i use avira and it has a firewall i set to on always as well as constant fil scanning. I use avira. For what it matters i have 128 bit wifi encryption etc etc on my router
     
  4. Turk Key

    Turk Key Avatar

    Messages:
    2,561
    Likes Received:
    4,012
    Trophy Points:
    153
    Gender:
    Male
    Have you tried turning the computer off and letting it re-boot? A bad habit I get into sometimes is putting it into sleep mode instead which could stretch to weeks between computer shutdowns. Many times my computer gets erratic after long periods without a shutdown.
     
  5. StaticGrazer

    StaticGrazer Avatar

    Messages:
    62
    Likes Received:
    119
    Trophy Points:
    8
    Gender:
    Male
    Location:
    Earth
    Start with running your anti-virus with a full scan.

    I cannot speak specifically for the security measures in place, but it's just as likely you got hacked through the Sota client as you got hacked through archage. Which is not much.

    More likely is that you visited a website which you unknowingly downloaded a trojan via cookie.

    Run the anti virus, preferably in safe mode, and tell us what happens.
     
  6. licemeat

    licemeat Avatar

    Messages:
    897
    Likes Received:
    2,825
    Trophy Points:
    105
    Gender:
    Male
    Location:
    Cincinnati Oh
    I'm not a computer engineer or anything but it sounds like your computer may be haunted. If the antivirus solutions turn out not to be a solution i would consider hiring someone to perform an exorcism.
     
  7. smack

    smack Avatar

    Messages:
    7,077
    Likes Received:
    15,288
    Trophy Points:
    153

    And then kill it with fire?

    If programs are launching on their own and you see the mouse moving on its own too....uhm, yeah. Scan that system in safe mode asap, get another security vendor and rescan, etc. Or better to be safe than sorry and format and start over.
     
  8. Beli

    Beli Avatar

    Messages:
    982
    Likes Received:
    2,487
    Trophy Points:
    105
    Gender:
    Male
    Location:
    Alabama
    Or contact Time Lord and have him take you back into a better time:)
     
    Aradove, Bodhbh Dearg, Leos and 4 others like this.
  9. Lord Lonn

    Lord Lonn Avatar

    Messages:
    1,037
    Likes Received:
    1,984
    Trophy Points:
    125
    Gender:
    Male
    Location:
    Milw,Wi USA
    I like Avast!! it's Free, and works quite good ;)
     
    Arianna likes this.
  10. Veylen The AenigmA

    Veylen The AenigmA Avatar

    Messages:
    986
    Likes Received:
    699
    Trophy Points:
    105
    Gender:
    Male
    Location:
    rogers
    I did have avast on my old pc. I got infected on it with win32 dropper and avast tech support nor the scan could do anything to fix it. I hate it. Its got problems with chrome and certain browsers. Anyhow i ran fullscans, boot scans, startup scans and it said no infections so idk. I dont surf the web other than whatever it does via the games i play. I never leave it running i always turn it off when not playing. I noticed in the startup there is a bluetooth icon which was never there i disabled it.
     
  11. StaticGrazer

    StaticGrazer Avatar

    Messages:
    62
    Likes Received:
    119
    Trophy Points:
    8
    Gender:
    Male
    Location:
    Earth
    Are you able to get an anti-virus program?
    I use Trend Micro, they offer support for 5 devices ( including tablets and cell phones).

    I would recommend against Norton.
     
  12. Veylen The AenigmA

    Veylen The AenigmA Avatar

    Messages:
    986
    Likes Received:
    699
    Trophy Points:
    105
    Gender:
    Male
    Location:
    rogers
    Yeah. Avira is anti virus
     
  13. Turk Key

    Turk Key Avatar

    Messages:
    2,561
    Likes Received:
    4,012
    Trophy Points:
    153
    Gender:
    Male
    Did you get a "free" comcast modem recently?
     
    Lord-Galiwyn likes this.
  14. Drocis the Devious

    Drocis the Devious Avatar

    Messages:
    18,188
    Likes Received:
    35,440
    Trophy Points:
    153
    Gender:
    Male
    No one can or will answer your question with any authority. Is it possible? It's always "possible" to do just about anything when you're talking about IT Security.

    It's my understanding that the client communicates with a central server owned by Portalarium. But the download and updates for the client are still part of a peer to peer architecture.

    It's my understanding that ANY peer to peer architecture will allow people to see your IP Address. However, if you go through a proxy server (for example like what your ISP undoubtedly would use) then your IP Address would be masked as well as monitored for malicious activity (such as a DoS Attack).

    Still, this doesn't stop Malware Bytes from freaking out about and blocking SOME of the other IP Address being used by other players in the peer to peer network (that I assume have a history of being up to no good). In addition, I'm not sure that having a "firewall" or "antivirus" software is going to be a great defense against an attack from a client that you're almost certainly giving full access to so you can play the game.

    The good news I suppose is that most people that would have the capability and the want to attack you via the SOTA client (if "possible" - see above) probably have better things to do (like attempt to hack the game servers and eCommerce website).

    At least, that's the way I see it. Security is not my specialty, but now that I've put some things out here for people to tear apart, you may see a better discussion develop.

    At least, that's the way I see it.
     
    Ahuaeynjgkxs likes this.
  15. Veylen The AenigmA

    Veylen The AenigmA Avatar

    Messages:
    986
    Likes Received:
    699
    Trophy Points:
    105
    Gender:
    Male
    Location:
    rogers
    I didnt ever use comcast i used at&t that licensed me a router/modem in one.

    When i ran avira the info said i was running windows vista and 8.1. Ive never used vista so it seems like it thinks i have two oses in dual boot or something. Idk its really wierd. When i log in the screen flickers which it never used to do
     
  16. Ristra

    Ristra Avatar

    Messages:
    3,942
    Likes Received:
    5,442
    Trophy Points:
    153
    Location:
    Athens
    I wouldn't jump right to security issues. There are several hardware/software failures that can cause things like this.

    1: do a full shut down and reboot. - fix anything loaded into memory that is corrupt
    2: remove all unused USB peripherals. - a defective USB printer/mouse/keyboard/etc can drive other USB devices nuts - a defective mouse (laser) can cause this
    3: reinstall drivers/software for the mouse IF you are using drivers other than the generic windows drivers.
     
    Lord-Galiwyn likes this.
  17. Bodhbh Dearg

    Bodhbh Dearg Avatar

    Messages:
    1,830
    Likes Received:
    3,548
    Trophy Points:
    125
    Gender:
    Male
    Location:
    Netherlands
    I agree, while it is possible in theory, it is very unlikely, unless the computer on which the patch files were made is infected and copied the virus/trojan in the patch. However, if that were the case, there'd be many people complaining about AV warnings while patching, so I would not think that likely either...

    Depending on your browser, there are many possibilities to get infected, esp. in the short time between virus/trojan release and update of the AV signatures...

    Like suggested, safe mode, full/intensive AV scan (if possible with at least 2 different vendor's scanners), followed by a scan with Spybot Search and Destroy or HijackThis (anti malware)... The latter is more involved (and may require assistance from volunteers at websites like bleepingcomputer or spywareinfoforum) but very comprehensive...
     
  18. Veylen The AenigmA

    Veylen The AenigmA Avatar

    Messages:
    986
    Likes Received:
    699
    Trophy Points:
    105
    Gender:
    Male
    Location:
    rogers
    Yeah like i said i had ran every scan and it found nothing. Havent used a web browser but when playing sota during test and only site i isited was shroud homepage. Its not doing it now i did system restore but it still freaks out randomly and runs every game at half the framerate it used to

    Any unrecognized programs i removed. But now it had three unknown devices in system device mgr and idk what they are and auto search and install drivers doesnt work. Im thinking just take it to repair shop cuz i could scree it up worse

    I appreciate all the help though it still is good to know all this even if it doesnt fix everything it still helps some
     
Thread Status:
Not open for further replies.