CABAL RIDER 1.0.6 PH WEBSITE JAVASCRIPT INITIATED VIRUS

07/17/2008 03:28 minime2k7#1
last night my antivirus started to detect this javascript/vbscript automatically downloaded from cabalrider ph launcher. (instead of the proper cabalrider guide that pops up on the window of cabalrider....a blank page is displayed.)


This script instantly creates a KPY folder and attaches to your windows processes (worm/rootkit) once it has downloaded its main .exe file. So far updating my antivirus and rescanning it does not contain it. Im trying to remove my other Harddrive now and rescan it on other pc.

I dont know whether cabalrider's site has been compromised or they themselves created it (in preparation for their pay-to-use service) but it definitely is a password stealer.

U can still continue to bot safely but the trick is *AFTER LOGGING INTO THE GAME....HEAD TO E-GAMES SITE AND REPLACE UR PASSWORD INSTANTLY* do this everytime you try to login to the game using cabalrider.


NOTE: I aint forcing anyone to believe me...i seldomly post on this site though im an oldie on epvp. This just pisses me that cabalrider aint doing anything for this worm after 24hrs. Be wary guys.

minime signing off...
07/17/2008 04:11 minime2k7#2
scan result after slaving my infected harddrive.

note: nevermind the wpa and mms detections....they are my creatures. :)

[Only registered and activated users can see links. Click Here To Register...]
07/17/2008 05:49 shemgwapo#3
hmmm i guess i'll start scanning mg HD
07/17/2008 06:35 japz17#4
also happened to me..
im using it for about 1 week
then an error came
07/17/2008 08:18 minime2k7#5
ok once the worm gets in the only way u can remove it is by connecting the harddisk to another pc and replacing explorer.exe since it infects this one.had my infected harddrive fixed by:

1. scanning windows drive of the infected harddrive using an updated antivirus.

2. copy explorer.exe (same version) of the clean machine and replace the c:\windows\explorer.exe of the infected drive.

infected machine now back and botting! CIAO! :)
07/17/2008 09:34 tokaides#6
Nod32 blocks and deletes it everytime you launch CR. just my 2 cents.
07/17/2008 11:24 drone1987#7
i suggest u use nod32 = XP or eset smart center = vista...
try it and u'l c...