CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Onlinegames keyloggers and fake Software for Worldofwarcraft
Goto page Previous  1, 2, 3, 4  Next
 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
KaKii

Cadet
Cadet


Joined: Oct 07, 2007
Posts: 2
Location: UK

PostPosted: Sun Oct 07, 2007 11:44 pm    Post subject:
Reply with quote

Hi, was just browsing through Google when i came across ur site.

Earlier this evening, my younger brother was browsing through WoW-Europe forums when he clicked a keylogger link.........

I'm using Firefox btw if it makes any difference, the keylogger post can be found here

http://forums.wow-europe.com/thread.html?topicId=1152956003&sid=1

********DON'T CLICK ANY OF THE LINKS FOUND WITHIN THE POST*******

According to my brother the site in question did not load fully but i guess loading it for 0.5secs is enough really. Anyway, ive been on another computer and changed my WoW account password etc for safety and have been running various Anti-Virus programs, Kaspersky, Spybot S&D and nothing of any great relevance has been discovered by them. I'll continue to run them overnight.

PS. Here is the HijackThis logfile, im just looking for some information telling me whether my computer seems infected with this crap, or hopefully not Wink

This is taken from on the Wow account screen, when i guess the process would be running........

Thanks greatly for any help in this matter.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5864

MIRT Premium

PostPosted: Mon Oct 08, 2007 12:28 am    Post subject:
Reply with quote

Thanks for posting the links.

Code:
lluzq.cn


Is currently offline.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Astair

Guest
IP: 99.251.*.*






PostPosted: Wed Nov 21, 2007 4:49 am    Post subject:
Reply with quote

I know, this thread is old and the last post was a while ago, but it seemed the most relevant place to post.

Browsing the WoW forums while half-asleep, I didn't notice the ".cn" in the domain and stupidly followed this link -

www.ocaiq.cn/albums/y287/ShadowedFate/WoWScrnShot_101207_194709.jpg

I visited using Firefox. Does that site use exploits/security holes in IE to inject its malware/trojan? I've done a full scan with AVG already, registry startup folders are clean and the task manager's process list doesn't list anything out of the norm, but I'm still unsure. Any help would be greatly appreciated.

Back to top
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5864

MIRT Premium

PostPosted: Wed Nov 21, 2007 5:05 am    Post subject:
Reply with quote

Code:
ocaiq.cn


is currently offline.

From what I can remember I think it takes advantage of an exploit in Windows.

Visit www.windowsupdate.com and scan your PC for updates. If you already have all the updates installed you are probably ok.

If you are still concerned you could always post a log in the Hijack This forum.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Astair

Guest
IP: 99.251.*.*






PostPosted: Wed Nov 21, 2007 12:51 pm    Post subject:
Reply with quote

tetak wrote:
Code:
ocaiq.cn


is currently offline.

From what I can remember I think it takes advantage of an exploit in Windows.

Visit www.windowsupdate.com and scan your PC for updates. If you already have all the updates installed you are probably ok.

If you are still concerned you could always post a log in the Hijack This forum.

the ocaiq.cn address just opened up a page with 2 frames - one with a blog and an "invisible" frame leading to http://world0fwarcraft.net/lese1.htm

Heading over to windows update now!

Back to top
bobby_

MIRT Hunter


Joined: Nov 04, 2006
Posts: 237
Location: Austria
MIRT

PostPosted: Wed Nov 21, 2007 8:52 pm    Post subject:
Reply with quote

hxxp://world0fwarcraft.net/lese.exe


_________________
ASAP member
Back to top
View users profile Send private message Visit posters website
Sugarlady

Guest
IP: 69.42.*.*






PostPosted: Sun Dec 16, 2007 1:01 pm    Post subject:
Reply with quote

Already lost my WoW account, but I can't find the keylogger. Everything I scan with comes up negative, including those listed previously as being able to find it.

The file kbass1p.dll (filesize 15872 bytes) exists on my machine under C:\Windows\system32, and is now causing explorer.exe to crash while using iexplore.exe. I looked it up in Process Explorer, and it's literally hooked into everything. I would remove it using the Windows Recovery Console, but I'm thousands of miles from home where the Windows CD is. The memory strings are more than a bit suspicious: "accountName" "password" "FsecretQuestionAnswer". I don't have lese*.exe on my machine however, and no individual running process is something I don't recognize.

Here's the HJT:

HJT log removed by moderator. Please do not post HJT logs anywhere on CastleCops except in our HJT forum. You must also join as a member to post in that forum.

Is this dll the likely problem? And how do I go about deleting it?

Back to top
Sugarlady

Guest
IP: 69.42.*.*






PostPosted: Sun Dec 16, 2007 1:23 pm    Post subject:
Reply with quote

Good news! I managed to delete it by terminating every process that was using it with Process Explorer (including Process Explorer itself) while keeping a command prompt up. The repeatable crashes and errors have stopped. I kept a copy of the file in case it was something necessary to re-register. Can I submit this file somewhere to people who would know what to do with it so it might not infect other people?

Back to top
Sugarlady

Guest
IP: 69.42.*.*






PostPosted: Sun Dec 16, 2007 1:26 pm    Post subject:
Reply with quote

Err... I should have mentioned: I got this by clicking a link on my realm forums for a "jpg" that had a frameset with a hidden frame which opened a url that ran a script. Was running IE.

Back to top
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5864

MIRT Premium

PostPosted: Mon Dec 17, 2007 12:58 am    Post subject:
Reply with quote

Please add the file (and any others you think may be malware) to a .zip file and upload them to this post.

If you know the URL you clicked on please post the url as well but replace http with hxxp so other users don't click on it by mistake.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
sula_nebouxi

Cadet
Cadet


Joined: Dec 06, 2007
Posts: 5
Location: USA

PostPosted: Mon Dec 24, 2007 5:44 am    Post subject:
Reply with quote

My guard was down and I clicked one of these links. I realized my mistake and haven't logged on to WoW. The page didn't load long enough to show anything so I'm hoping I'm fine. I'm running some checks with avg to be sure though and I was using Firefox.

It seems the same story is being passed around the forums with the whole druid look.

These following links are being used(Don't copy paste!)

Here's the original thread, http changed to hxxp:

hxxp://forums.worldofwarcraft.com/thread.html?topicId=3547801357&sid=1

And here's the offending links:

hxxp://www.48304.cn/albums/x1/seymourseesmore/currentbearformsize.jpg
hxxp://www.48304.cn/albums/x1/seymourseesmore/proposalbearformlevel10size.jpg
hxxp://www.48304.cn/albums/x1/seymourseesmore/proposalbearformlevel70size.jpg
hxxp://www.48304.cn/albums/x1/seymourseesmore/shoulderarmor.jpg
hxxp://www.48304.cn/albums/x1/seymourseesmore/kittymalevs.female.jpg
hxxp://www.48304.cn/albums/x1/seymourseesmore/loldruid.jpg
hxxp://www.48304.cn/albums/x1/seymourseesmore/?action=view&current=superxxtrollshuntz.jpg
hxxp://www.48304.cn/albums/x1/seymourseesmore/?action=view&current=dyani.jpg

Are these redirects or are they piggybacking on the jpg itself? I'm trying to understand how these actually plant keyloggers onto your system and where they usually reside on the comp.

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Mon Dec 24, 2007 6:17 am    Post subject:
Reply with quote

[edit] removed potentially dangerous links.
submitting to mirt.

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Mon Dec 24, 2007 6:51 am    Post subject:
Reply with quote

http://www.siteadvisor.com/sites/48304.cn
http://www.siteadvisor.com/sites/94564.cn
http://www.siteadvisor.com/sites/766598.com
http://www.siteadvisor.com/sites/cvcvdede.cn
I've already submitted a malcious file for siteadvisor evaluation for cvcvdede.cn using the following link

Quote:
hxxp://www.siteadvisor.com/sites/scarddlg.com/writeCommentsPre?flag=suggestedDownload&domain=domain.com&section=suggestedDownload&user=UNKNOWN&comments=

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5864

MIRT Premium

PostPosted: Mon Dec 24, 2007 2:37 pm    Post subject:
Reply with quote

48304.cn seems to be offline now.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
karthu

Cadet
Cadet


Joined: Dec 28, 2007
Posts: 6
Location: USA

PostPosted: Fri Dec 28, 2007 9:25 am    Post subject:
Reply with quote

I clicked on the same links as sula_nebouxi. I was wondering what course of action I should take...I've scanned using Norton, Spybot, and Ad-Aware. Ad-Aware was the only program to return anything, which I quarantined. I downloaded Windows Defender and ran that also, to no avail. I was using Firefox when the links were clicked. Just hoping for a response as to what I should do now to make sure I'm safe. Thanks in advance.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Goto page Previous  1, 2, 3, 4  Next
Page 3 of 4

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer