Posting Freak
Posts: 775
Threads: 75
Joined: 2008-07
Gender: Male
Sexual Orientation: Straight
Country Flag: Ohio
IGN: GreasyEggs
Server: El Nido
Level: 160
Job: Battle Mage
Websites can't "be" keyloggers. And it seems safe.
Senior Member
Posts: 444
Threads: 27
Joined: 2009-07
Is roxstarz a keylogger? I talked to him once in game then the next day all my stuff was gone.
lol.
Posting Freak
Posts: 1,593
Threads: 2
Joined: 2008-07
That site's not keylogged. I've used the site as a cheat sheet for the speed quiz before its bandwidth exceeded weeks ago & stopped using it from then on. I can assure you it's safe. Lots of people on Sleepy & Basil used it also.
At above - Lol'd.
Member
Posts: 79
Threads: 14
Joined: 2009-07
I was able to find and hopefully remove the trojan on my computer. Here is the log of what it did for anyone that cares. Again, the only common denominator I have found so far with the trojan is the above mentioned site. Doesn't mean it is the culprit, but how do we check it further?
Malwarebytes' Anti-Malware 1.40
Database version: 2595
Windows 5.1.2600 Service Pack 2
8/10/2009 11:46:48 PM
mbam-log-2009-08-10 (23-46-48).txt
Scan type: Full Scan (C:\|E:\|L:\|)
Objects scanned: 307335
Time elapsed: 2 hour(s), 31 minute(s), 54 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 9
Registry Values Infected: 4
Registry Data Items Infected: 1
Folders Infected: 5
Files Infected: 18
Memory Processes Infected:
C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe (Rogue.MalwareRemovalBot) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{9d3cf193-58e5-40d5-ba60-233f4c216e37} (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\50e90ec4ec063d44bb935a0d02415732 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{9d3cf193-58e5-40d5-ba60-233f4c216e37} (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\50e90ec4ec063d44bb935a0d02415732 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1f26a7a704abd8f4f8801f37167d691f (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\aa02c0f5889834c42886c1a98ea53266 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\b575e3c1288dd9e4a83e9e064562cdc1 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\d37f1f5d110c2ea4c85ec64e702394b9 (Rogue.MalwareBot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\program files\malwareremovalbot\(default) (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\documents and settings\all users\start menu\programs\malwareremovalbot\(default) (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Settings (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\Michael\My Documents\Downloads\setupxv.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128652.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128662.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128663.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128654.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
L:\System Volume Information\_restore{C79F8364-4415-48C7-8404-AE219B9E133D}\RP980\A0128656.bat (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\rs.dat (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Log\2009 Aug 10 - 08_52_20 PM_218.log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Michael\Application Data\MalwareRemovalBot\Settings\ScanResults.pie (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\DataBase.ref (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.url (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Program Files\MalwareRemovalBot\vistaCPtasks.xml (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemovalBot\MalwareRemovalBot on the Web.lnk (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemovalBot\MalwareRemovalBot.lnk (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Desktop\MalwareRemovalBot.lnk (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\autorun.inf (SuspectAutorun.Rootdrive.H) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\MalwareRemovalBot Scheduled Scan.job (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
Posting Freak
Posts: 2,386
Threads: 88
Joined: 2008-07
Gender: Female
Sexual Orientation: Straight
Country Flag: Michigan
IGN: QuIt!!!
Server: Bellocan
Level: 184
Job: ♥Bishop
Guild: QUIT!
Guild Alliance: quit quit QUIT
Maybe you guys are visiting too many porn sites?
Senior Member
Posts: 610
Threads: 19
Joined: 2009-07
You could've picked up a keylogger anywhere. On some sites, despite the content of them, advertisements may intentionally or unintentionally hold viruses. I host my own forum and we got a bad run of ads once. (From Google too) Friend had to reinstall windows and I had a very annoying trojan. It's hard to pin-point it, but try to stay away from sites that aren't extremely well-known to be safe. I'd say Southperry's good to go.
Member
Posts: 160
Threads: 3
Joined: 2009-06
I've used that before, and all of my 1 or 2 valuable items are still there. Along with all my mesars.
Junior Member
Posts: 3
Threads: 0
Joined: 2009-08
The page source is comprised of basic HTML / CSS
HTML and CSS have no known dangerous exploits.
There's no JS or PHP even. No dynamic languages used.
It opens with some declarations of font size.
Next is a link to a PDF; printable version.
Then it declares a table and lists out all the items.
Absolutely no exploits whatsoever.
In fact, the page is so elementary, they even teach you how to make something like this in high school.
If you so feel inclined, you can view the page source by clicking:
In Firefox: View > Page Source
In Internet Explorer: Page > View Source
TLDR version:
This web site is proven safe.
Senior Member
Posts: 554
Threads: 6
Joined: 2008-10
Love to know where you're going to school. I didn't learn C++ and PHP till my first year of college.
Posting Freak
Posts: 1,518
Threads: 40
Joined: 2008-08
surprised this hasnt been locked yet,,,,,,,