Become a premium member to remove ads
AwakenedRage

Security Incident (SCAN NOW!)

6 posts in this topic

Attention,

 

It has been brought our attention of a potential compromise in Chaotic United Gameserver's and Database server. The cause of this is to be determined, but from what information we have right now we advise everyone running Windows who has received files from staff members since last October  to:

 

Download: Malwarebytes

http://www.malwarebytes.org/mwb-download/confirm/

 

Do a Full System Scan or Threat Scan

 

Delete all threats that you do not recognize, After the threats are dealt with it should ask to restart the computer. and thats exactly what needs to be done.
 Restart the computer and once Windows is rebooted a text file should open. You can close as it isn't important at this time.

 

Now you are going to want to download adwcleaner

 

http://www.bleepingcomputer.com/download/adwcleaner/

 

Please de aware that Avira Webguard is using the ASK Toolbar as part of its web security. If you remove the ASK Toolbar by using Adwcleaner, Avira Webguard will no longer work properly on your system. Therefore, if you use this program please use the instructions below to access the options screen where you should enable /DisableAskDetections before using AdwCleaner.
  • Important! Before starting AdwCleaner, close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Windows Vista/ 7/8 users right-click and select Run As Administrator.
  • Click on the scan button,
  • When the scan is ready click on the Clean butten

 

  • Your desktop icons will be disappear, this is normal so don’t be worry about that.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • Close the text file that opens after the restart, double click on adwcleaner.exe to run the tool.
  • Click now on Uninstall, then confirm with yes to remove AdwCleaner from your computer.

 

After ADWCleaner is installed we want to be sure that we got the virus completely,

 

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the esetOnline.png button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetSmartInstallDesktopIcon-1.png icon on your desktop.

•Check esetAcceptTerms.png
•Click the esetStart.png button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check esetScanArchives.png
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push esetListThreats.png
•Push esetExport.png, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the esetBack.png button.
•Push esetFinish.png

 

I am not sure whether ESET will ask you to restart, but after it does we are going to want to verify that  your system files were not damaged by using SFC

 

Share this post


Link to post
Share on other sites

To Run the SFC /SCANNOW Command in Windows 7
1. Open an elevated command prompt.

2. To Scan and Repair System Files
NOTE: Scans the integrity of all protected system files and repairs the system files if needed.
A) In the elevated command prompt, type sfc /scannow and press Enter. (see screenshot below)
NOTE: This may take some time to finish.

2327d1231529432t-sfc-scannow-command-sys

B) Go to step 4.

3. To Only Verify if the System Files are Corrupted
NOTE: Scans and only verifies the integrity of all proteced system files only.
A) In the elevated command prompt, type sfc /verifyonly and press Enter.

4. When the scan is complete, hopefully you will see all is ok like the screenshot below.
NOTE: If not, then you can attempt to run a System Restore using a restore point dated before the bad file occured to fix it. You may need to repeat doing a System Restore until you find a older restore point that may work.

2328d1231529438t-sfc-scannow-command-sys

5. When done, close the elevated command prompt.

 
 
If all is good, then you are safe. At this time we advise you not to take files from players or staff members of Chaotic United until we can safely say our staff members are secure.
 
At this moment we are unable to give a ETA on the server being back online. But we will be sure to let you know when we do!
 
 
Thanks,
AwakenedRage

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now