Co partner has a keylogger?

04/20/2006 15:04 wAndAA#16
Quote:
Originally posted by tsu@Apr 20 2006, 15:00
it's strange too, not a single antivirus at jotti scan finds any kind of malware, but your does.
exactly, and I bet we all have antispyware and firewalls etc on our comps that detect this kinds of stuff??? or am I the only one?
04/20/2006 15:57 some1else#17
Quote:
Originally posted by tsu@Apr 20 2006, 15:00
it's strange too, not a single antivirus at jotti scan finds any kind of malware, but your does.
actualy he didn't say that the spyware doctor detects copartner as containing a trojan/keylogger. that pic shows(at least that's what i understand) that during the execution the process was blocked by the antivirus. i would like to know what did the partner do that the antivirus didn't agree with. i just hope that the spayware doctor is a paranoid antivirus with weird heuristics and that there is nothing wrong with the partner(otherwise 90% of my server's population can get hack any moment)
04/20/2006 16:36 ArtisanDude#18
I think that if CoPartner did have a keylogger, why not start stealing accounts a long time ago? Unless they were waiting for it to become so popular that everyone had used it and done a mass attack againest the users. But, it would be a murderous task. They would have to find out what server the character was on and theres like 50 of them =/. Not to mention, I'm sure they would have thousands of files to go through to get all of the accounts.
04/20/2006 16:55 some1else#19
until someone with good programing knowlege examines the partner realy good and the packets that it sends all talk about it is useless, and since all of us use it there is nothing to do(except maybe change passwords and find weird login sequences)
04/20/2006 17:03 LMAONADE#20
Well... On the moment you click "start" the doctor block it.. and says its sendin strings to keylog.

That is the lastest version posted on epvp..
I would like to hear some from who posted that.

Any one can do that test just use the spyware doctor turn the OnGuard on click keylogger guard then results then open co partner then click start. It'll instantly pop up the error message.
04/20/2006 17:25 tester#21
COPartner does send strings it sends the user and pass or wat ever it is to the server (or COPanther) depends which verion you have, then recieves [Only registered and activated users can see links. Click Here To Register...] back as i understand it
04/20/2006 17:29 LMAONADE#22
actually i started to take care of it because like 2 versions ago when you click start you had instantly answer... cause of the emulator.. now it seems You're sendin to some server and getting it back.

The Emulator is a fake.

I'm pretty disgusted with the creator...
04/20/2006 17:32 arbitrary_illusion#23
If I am not mistaken, COPartner was made by TQ for use on the Chinese servers. Botting is legal there because the game is pay to play, and I guess they're figuring that if you're paying for the game, you should be allowed to play however you want to. I haven't had any problems with CO Partner, and I have been using it for a very long time. I think those of you that claimed to have been hacked need to consider the other cheats and peripheral programs that you are undoubtedly using as well as anyone that you may be sharing your acct with.
04/20/2006 17:50 LMAONADE#24
Quote:
Originally posted by arbitrary_illusion@Apr 20 2006, 17:32
If I am not mistaken, COPartner was made by TQ for use on the Chinese servers. Botting is legal there because the game is pay to play, and I guess they're figuring that if you're paying for the game, you should be allowed to play however you want to. I haven't had any problems with CO Partner, and I have been using it for a very long time. I think those of you that claimed to have been hacked need to consider the other cheats and peripheral programs that you are undoubtedly using as well as anyone that you may be sharing your acct with.
I dont belive that theory... the older versions was clean.. but the past two ones are keylogged. that dont even requires the emulator. the one in there is fake cause it connects into a server and send the string.
04/20/2006 17:52 some1else#25
can you extract the logger from it? or make it think it sends to the server but in fact make it all local with another program?
04/20/2006 17:54 LMAONADE#26
Quote:
Originally posted by some1else@Apr 20 2006, 17:52
can you extract the logger from it? or make it think it sends to the server but in fact make it all local with another program?
I'll leave c3 editing for a while and look every bit code of it.
04/20/2006 23:10 Pindle#27
this is true, i posted a pic of swdoctor saying tqprogram.exe was trying to monitor my keystrokes here [Only registered and activated users can see links. Click Here To Register...]

and the pic to show i get this too (if it means anything, COPartner wasn't even running at the time.) And it continured to try to monitor keystrokes many times after that, until i deleted it.
04/20/2006 23:41 LMAONADE#28
found that co partner connect into this ip
04/21/2006 00:58 basil14344#29
there are two type of COPartner I found it, they are in different IP host connections:
the 202.109.124.19 as LMAONADE scaned and the other is 127.0.0.1
try to HEx and see there find these Hex Value= 4E6F7468696E672068657265203D50 or text string = Nothing here =P
maybe we can do something about it....

And also I tried the TQProgram from [Only registered and activated users can see links. Click Here To Register...] to see the different it is still detectable by SpyWareDoctor and still the same as the crack one..


Only one way to avoid from keylogg is to cleanup ur entire OS scann all some detected or make a new fresh copy of the OS and make a final DeepFreeze, First run your CO2 login ur char's and make position were u will level and after that run the COPartner... the keylog will never vary b4 the COpartner coz u already login ur char b4 the COPartner. After that continue on leveling.... if u try to login again jst restart ur computer to refresh the system and try it again vice-versa...
04/21/2006 01:52 shadowkiller#30
Quote:
Originally posted by basil14344@Apr 20 2006, 17:58
there are two type of COPartner I found it, they are in different IP host connections:
the 202.109.124.19 as LMAONADE scaned and the other is 127.0.0.1
try to HEx and see there find these Hex Value= 4E6F7468696E672068657265203D50 or text string = Nothing here =P
maybe we can do something about it....

And also I tried the TQProgram from [Only registered and activated users can see links. Click Here To Register...] to see the different it is still detectable by SpyWareDoctor and still the same as the crack one..


Only one way to avoid from keylogg is to cleanup ur entire OS scann all some detected or make a new fresh copy of the OS and make a final DeepFreeze, First run your CO2 login ur char's and make position were u will level and after that run the COPartner... the keylog will never vary b4 the COpartner coz u already login ur char b4 the COPartner. After that continue on leveling.... if u try to login again jst restart ur computer to refresh the system and try it again vice-versa...
Basically, you shouldn't have to use tqprogram anymore if your using co partner. There are 2 programs you run, and those 2 (neither are tqprogram) can make co partner run. I did search my tqprogram, which once again I don't use, and found that value. So if I did find that value, it pretty much is the keylogger version? If anybody wants to know how to get coparnter working without having to use tqprogram, just those other 2 I mentioned pm me.

basil14344: Send me a pm so we can talk about this in further detail.