| View previous topic :: View next topic |
| Author |
Message |
KaKii
Cadet

 Joined: Oct 07, 2007 Posts: 2 Location: UK
|
Posted: Sun Oct 07, 2007 11:44 pm Post subject: |
|
|
Hi, was just browsing through Google when i came across ur site.
Earlier this evening, my younger brother was browsing through WoW-Europe forums when he clicked a keylogger link.........
I'm using Firefox btw if it makes any difference, the keylogger post can be found here
http://forums.wow-europe.com/thread.html?topicId=1152956003&sid=1
********DON'T CLICK ANY OF THE LINKS FOUND WITHIN THE POST*******
According to my brother the site in question did not load fully but i guess loading it for 0.5secs is enough really. Anyway, ive been on another computer and changed my WoW account password etc for safety and have been running various Anti-Virus programs, Kaspersky, Spybot S&D and nothing of any great relevance has been discovered by them. I'll continue to run them overnight.
PS. Here is the HijackThis logfile, im just looking for some information telling me whether my computer seems infected with this crap, or hopefully not
This is taken from on the Wow account screen, when i guess the process would be running........
Thanks greatly for any help in this matter.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
|
| Back to top |
|
 |
Astair
Guest IP: 99.251.*.*
|
Posted: Wed Nov 21, 2007 4:49 am Post subject: |
|
|
I know, this thread is old and the last post was a while ago, but it seemed the most relevant place to post.
Browsing the WoW forums while half-asleep, I didn't notice the ".cn" in the domain and stupidly followed this link -
www.ocaiq.cn/albums/y287/ShadowedFate/WoWScrnShot_101207_194709.jpg
I visited using Firefox. Does that site use exploits/security holes in IE to inject its malware/trojan? I've done a full scan with AVG already, registry startup folders are clean and the task manager's process list doesn't list anything out of the norm, but I'm still unsure. Any help would be greatly appreciated.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
Posted: Wed Nov 21, 2007 5:05 am Post subject: |
|
|
is currently offline.
From what I can remember I think it takes advantage of an exploit in Windows.
Visit www.windowsupdate.com and scan your PC for updates. If you already have all the updates installed you are probably ok.
If you are still concerned you could always post a log in the Hijack This forum. _________________ Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
|
|
| Back to top |
|
 |
Astair
Guest IP: 99.251.*.*
|
Posted: Wed Nov 21, 2007 12:51 pm Post subject: |
|
|
| tetak wrote: |
is currently offline.
From what I can remember I think it takes advantage of an exploit in Windows.
Visit www.windowsupdate.com and scan your PC for updates. If you already have all the updates installed you are probably ok.
If you are still concerned you could always post a log in the Hijack This forum. |
the ocaiq.cn address just opened up a page with 2 frames - one with a blog and an "invisible" frame leading to http://world0fwarcraft.net/lese1.htm
Heading over to windows update now!
|
|
| Back to top |
|
 |
bobby_
MIRT Hunter
 Joined: Nov 04, 2006 Posts: 237 Location: Austria
|
|
| Back to top |
|
 |
Sugarlady
Guest IP: 69.42.*.*
|
Posted: Sun Dec 16, 2007 1:01 pm Post subject: |
|
|
Already lost my WoW account, but I can't find the keylogger. Everything I scan with comes up negative, including those listed previously as being able to find it.
The file kbass1p.dll (filesize 15872 bytes) exists on my machine under C:\Windows\system32, and is now causing explorer.exe to crash while using iexplore.exe. I looked it up in Process Explorer, and it's literally hooked into everything. I would remove it using the Windows Recovery Console, but I'm thousands of miles from home where the Windows CD is. The memory strings are more than a bit suspicious: "accountName" "password" "FsecretQuestionAnswer". I don't have lese*.exe on my machine however, and no individual running process is something I don't recognize.
Here's the HJT:
HJT log removed by moderator. Please do not post HJT logs anywhere on CastleCops except in our HJT forum. You must also join as a member to post in that forum.
Is this dll the likely problem? And how do I go about deleting it?
|
|
| Back to top |
|
 |
Sugarlady
Guest IP: 69.42.*.*
|
Posted: Sun Dec 16, 2007 1:23 pm Post subject: |
|
|
Good news! I managed to delete it by terminating every process that was using it with Process Explorer (including Process Explorer itself) while keeping a command prompt up. The repeatable crashes and errors have stopped. I kept a copy of the file in case it was something necessary to re-register. Can I submit this file somewhere to people who would know what to do with it so it might not infect other people?
|
|
| Back to top |
|
 |
Sugarlady
Guest IP: 69.42.*.*
|
Posted: Sun Dec 16, 2007 1:26 pm Post subject: |
|
|
Err... I should have mentioned: I got this by clicking a link on my realm forums for a "jpg" that had a frameset with a hidden frame which opened a url that ran a script. Was running IE.
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
Posted: Mon Dec 17, 2007 12:58 am Post subject: |
|
|
Please add the file (and any others you think may be malware) to a .zip file and upload them to this post.
If you know the URL you clicked on please post the url as well but replace http with hxxp so other users don't click on it by mistake. _________________ Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
|
|
| Back to top |
|
 |
sula_nebouxi
Cadet

 Joined: Dec 06, 2007 Posts: 5 Location: USA
|
|
| Back to top |
|
 |
brewt
SIRT Handler Premium Member
 Joined: May 29, 2007 Posts: 792 Location: USA
|
Posted: Mon Dec 24, 2007 6:17 am Post subject: |
|
|
[edit] removed potentially dangerous links.
submitting to mirt.
|
|
| Back to top |
|
 |
brewt
SIRT Handler Premium Member
 Joined: May 29, 2007 Posts: 792 Location: USA
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5864
|
|
| Back to top |
|
 |
karthu
Cadet

 Joined: Dec 28, 2007 Posts: 6 Location: USA
|
Posted: Fri Dec 28, 2007 9:25 am Post subject: |
|
|
I clicked on the same links as sula_nebouxi. I was wondering what course of action I should take...I've scanned using Norton, Spybot, and Ad-Aware. Ad-Aware was the only program to return anything, which I quarantined. I downloaded Windows Defender and ran that also, to no avail. I was using Firefox when the links were clicked. Just hoping for a response as to what I should do now to make sure I'm safe. Thanks in advance.
|
|
| Back to top |
|
 |
|
|