Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Is this site keylogged?
#1
http://www.thatguyisawesome.com/maple/potion_etc/

OK, to make the story short. I know a DK that used this site for speed test. Got hacked and lost everything.

I know a BM that used this site and got hacked.

I used this site and got hacked yesterday and a bishop a friend let me use to train with got hacked and a dk I used in zak as zhelm mule got hacked.

I don't go to any strange sites, and then I started thinking about it, and the above site is a common denominator in all of the hacking stories I just told. Can anyone verify if that place is a keylogger or not?
#2
Websites can't "be" keyloggers. And it seems safe.
#3
Is roxstarz a keylogger? I talked to him once in game then the next day all my stuff was gone.


lol.
#4
That site's not keylogged. I've used the site as a cheat sheet for the speed quiz before its bandwidth exceeded weeks ago & stopped using it from then on. I can assure you it's safe. Lots of people on Sleepy & Basil used it also.

At above - Lol'd.
#5
I was able to find and hopefully remove the trojan on my computer. Here is the log of what it did for anyone that cares. Again, the only common denominator I have found so far with the trojan is the above mentioned site. Doesn't mean it is the culprit, but how do we check it further?

Malwarebytes' Anti-Malware 1.40
Database version: 2595
Windows 5.1.2600 Service Pack 2

8/10/2009 11:46:48 PM
mbam-log-2009-08-10 (23-46-48).txt

Scan type: Full Scan (C:\|E:\|L:\|)
Objects scanned: 307335
Time elapsed: 2 hour(s), 31 minute(s), 54 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 4
Registry Data Items Infected: 1
Folders Infected: 5
Files Infected: 18

Memory Processes Infected:
C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe (Rogue.MalwareRemovalBot) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{9d3cf193-58e5-40d5-ba60-233f4c216e37} (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\50e90ec4ec063d44bb935a0d02415732 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{9d3cf193-58e5-40d5-ba60-233f4c216e37} (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\50e90ec4ec063d44bb935a0d02415732 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1f26a7a704abd8f4f8801f37167d691f (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\aa02c0f5889834c42886c1a98ea53266 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\b575e3c1288dd9e4a83e9e064562cdc1 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\d37f1f5d110c2ea4c85ec64e702394b9 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\program files\malwareremovalbot\(default) (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\documents and settings\all users\start menu\programs\malwareremovalbot\(default) (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Settings (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Michael\My Documents\Downloads\setupxv.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128652.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128662.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128663.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128654.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
L:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128656.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\rs.dat (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Log\2009 Aug 10 - 08_52_20 PM_218.log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Settings\ScanResults.pie (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\DataBase.ref (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.url (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\vistaCPtasks.xml (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemovalBot\MalwareRemovalBot on the Web.lnk (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemovalBot\MalwareRemovalBot.lnk (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Desktop\MalwareRemovalBot.lnk (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\autorun.inf (SuspectAutorun.Rootdrive.H) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\MalwareRemovalBot Scheduled Scan.job (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
#6
Maybe you guys are visiting too many porn sites?
#7
Your avatar doesn't help there, Katie. Rolleyes Perhaps it was something all of you happened to look at on said site, a link, or something?
#8
You could've picked up a keylogger anywhere. On some sites, despite the content of them, advertisements may intentionally or unintentionally hold viruses. I host my own forum and we got a bad run of ads once. (From Google too) Friend had to reinstall windows and I had a very annoying trojan. It's hard to pin-point it, but try to stay away from sites that aren't extremely well-known to be safe. I'd say Southperry's good to go.
#9
RoxStarzzz Wrote:. Can anyone verify if that place is a keylogger or not?

TONS of people have used it.

we would be hearing about ALL of those people being hacked, so no it's not a keylogger.

edit: I use it everyday...
#10
I've used that before, and all of my 1 or 2 valuable items are still there. Along with all my mesars.
#11
The page source is comprised of basic HTML / CSS
HTML and CSS have no known dangerous exploits.

There's no JS or PHP even. No dynamic languages used.

It opens with some declarations of font size.
Next is a link to a PDF; printable version.

Then it declares a table and lists out all the items.

Absolutely no exploits whatsoever.

In fact, the page is so elementary, they even teach you how to make something like this in high school.

If you so feel inclined, you can view the page source by clicking:
In Firefox: View > Page Source
In Internet Explorer: Page > View Source


TLDR version:
This web site is proven safe.
#12
I have used that for a long time. I got 50/50 points with it and 1000 total points with it. If it was a keylogger and hacked me, all my totally awesome stuff (6 attack WG! Glitter) would be gone, along with my 100 mill. But it isn't.

Sorry you and other people got hacked though.
#13
I used that website many times since the Agents came out. Theres no virus.
TheBenign Wrote:In fact, the page is so elementary, they even teach you how to make something like this in high school.

Wut? They teach you HTML/CSS in High School? o_o I'm only a 6th grader yet I've learned a lot of PHP and C++.
#14
Love to know where you're going to school. I didn't learn C++ and PHP till my first year of college.
#15
Quote:Wut? They teach you HTML/CSS in High School? o_o I'm only a 6th grader yet I've learned a lot of PHP and C++.

Cool story bro.
#16
surprised this hasnt been locked yet,,,,,,,


Forum Jump:


Users browsing this thread: 1 Guest(s)