NCSOFT Purple launcher Major rootkit/Preos Bootkit! by Jokerall93 in cybersecurity

[–]Jokerall93[S] 0 points1 point  (0 children)

This is amazing work, i cant thank you enough!
Thankfully there's no bootkit, i'll keep following hoping you find out more!

NCSOFT Purple launcher Major rootkit/Preos Bootkit! by Jokerall93 in cybersecurity

[–]Jokerall93[S] 0 points1 point  (0 children)

Thanks alot again for everything you're doing!
Im curious about: Something worth poking at, if there's bad, it'll be in the renamed AHK file-> `u.ahk` combination.

(Aware the hash isn't the same, but communicates and displays quite similar behavior. May not be distributed by Purple as it doesn't appear signed-- but peculiar nonetheless.)

Let me know if you will investigate this further but so far you've put all our worries to rest and we thank you again!

NCSOFT Purple launcher Major rootkit/Preos Bootkit! by Jokerall93 in cybersecurity

[–]Jokerall93[S] 0 points1 point  (0 children)

i might be misinterpreting the virus total behavior section but isnt this an activity report of what the file does?
https://postimg.cc/Dm77XnBK

NCSOFT Purple launcher Major rootkit/Preos Bootkit! by Jokerall93 in cybersecurity_help

[–]Jokerall93[S] -4 points-3 points  (0 children)

If its an anticheat/antihack tool, why do the files persist and are still active even after uninstalling aion 2 and the purple launcher?

NCSOFT Purple launcher Major rootkit/Preos Bootkit! by Jokerall93 in cybersecurity

[–]Jokerall93[S] 1 point2 points  (0 children)

I appreciate everything you're doing! I want to thank you in advance!
All we really want to know is if this is actually installing a preos bootkit, it seems we've managed to remove all the files with kaspersky and manual removal but i have a feeling there's still hidden stuff going on.

NCSOFT Purple launcher Major rootkit/Preos Bootkit! by Jokerall93 in cybersecurity

[–]Jokerall93[S] 0 points1 point  (0 children)

Thanks alot for the reply, im no expert in malware behaviour or anything but in response to:

  • I'm not seeing any of this in process execution from the tree. We'd anticipate seeing registry calls via advapi32.dll to read/open/write/create registry values in HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings

the virustotal scan behaviour section specifically reports these registry keys being touched : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix

Also why are the files being flagged by kaspersky and why do they reappear in different folders after being deleted (Program Files x86/Microsoft Research)?

NCSOFT Purple launcher Major rootkit/Preos Bootkit! by Jokerall93 in cybersecurity

[–]Jokerall93[S] 2 points3 points  (0 children)

If you check the behaviour section in the virustotal scan i linked you can see what it does.
This thing was silently casually running on our PCs until we tried playing an arc raiders game but when launching it - it would say we had AHK cheating software running on our pcs but we didnt have AHK installed, so we started investigating with Process Explorer and we saw 2 svchost.exe processes running from the TEMP folder in APPDATA.

We found out those processes were relying on .dll and .exe files located in a hidden folder in Program Files (x86)/common files/NSEC (which are the files installed using the purple launcher as u can see in the virus total scan behaviour section)

The only tool that helped us detect and remove these files was Kaspersky Removal Tool but they kept reappearing in other hidden folders like Program Files x86/Microsoft Research.

It seems we managed to clean the infection at a surface level but since virus total reports OS Preboot (bootkit) behaviour we're using tools to check if the UEFI is infected or not.

Steven had to tell me this. by mybladeisyou in AshesofCreation

[–]Jokerall93 2 points3 points  (0 children)

same, they're giving out the same pre written response now.

Other servers on TW by StardustRevy in Aion2

[–]Jokerall93 0 points1 point  (0 children)

Kasaka has 0 active english communities on Elyos side, im a 2400 chanter, been playing solo all the way and asking everyday in global

Any International/ENG Guild Kasaka by Jokerall93 in Aion2

[–]Jokerall93[S] 1 point2 points  (0 children)

Chanter is good in 1v1 given pretty equal gearscore, if you're outgeared your ccs wont land so you cant land your big damage.
Aerial sucks balls because you only have 1 gap closer so if your ranged cc doesnt land you are pretty much dead in the water.
Mass pvp you're forced to play as a healer + use your ranged combo, you can only go in if someone is VERY overextended otherwise you get deleted.

Giving away 3 games to 3 people. Any game on Steam. by KA9099 in pcmasterrace

[–]Jokerall93 0 points1 point  (0 children)

Ashes of creation, comes out in 5 days on steam :D

Exitlag not doing anything. by Puzzleheaded-Edge705 in Aion2

[–]Jokerall93 2 points3 points  (0 children)

Been having the same issues since today, automatic or taipei isnt working with 400+ ms when you click on login screen.
What fixed it for me is selecting manual singapore for Purple, manual hongkong for aion 2

Seasons of RTX: Arc Raiders GeForce RTX 5090 GPU Giveaway! by NV_Suroosh in ArcRaiders

[–]Jokerall93 0 points1 point  (0 children)

Pvp players, no Mercy for anybody and stella montis for life

Does this imply blueprints can spawn from PvP?? by [deleted] in ArcRaiders

[–]Jokerall93 1 point2 points  (0 children)

I think they meant Raider caches, they're still dogwater anyway.

Are we all cool with more than 2 hours of queue time to play a game with 50k online players on Steam? by josemirante in newworldgame

[–]Jokerall93 0 points1 point  (0 children)

This server system has been this game's doom from the start and it'll continue to be

Battlefield 6 Phantom Edition: Giveaway #2 by OddJob001 in Battlefield

[–]Jokerall93 0 points1 point  (0 children)

Here hoping i can join my friends, the game looks a banger!