Keyloggers Are Spread on EPVP *WARNING*

01/15/2010 11:24 Boat#1
okay so today i manually checked some of my files that i got off from here i checked it with manual unpacking (ollydbg) i did some reverse on them and they seemed like infected

so i download some anti viruses and rechecked if i am really right because i couldnt belive in my eyes

my results were this

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\R oot\LEGACY_RPCHGM (Trojan.Keylogger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\RPCHGM (Trojan.Keylogger) -> Quarantined and deleted successfully.


Files Infected:
C:\Documents and Settings\Owner\Desktop\loader.exe (BackDoor.Bifrost) -> Quarantined and deleted successfully.
C:\Misc\SRO Keypresser.exe (BackDoor.Bifrost) -> Quarantined and deleted successfully.
C:\Misc\SWSRO\asd.exe (BackDoor.Bifrost) -> Quarantined and deleted successfully.
C:\Misc\SWSRO\SWSRO Potion\bot.exe (BackDoor.Bifrost) -> Quarantined and deleted successfully.

we must know that "C:\Documents and Settings\Owner\Desktop\loader.exe" is lolkops older loader which seems like it is really infected with a rat keylogger named bifrost

C:\Misc\SRO Keypresser.exe this is also lolkops work its his old "bot" so i got really angry because seems like he really infected some of his old work

C:\Misc\SWSRO\asd.exe this is an old autopotion i dont know who made it but its a packetbased one that i got from there long time ago for swsro old patch (it needed nuconnector and some other shit)

C:\Misc\SWSRO\SWSRO Potion\bot.exe this is TeamImperials bot which is also infected

really guys take care of what you download

its really sad that peoples i trusted have infected some of their files but oh well

i succesfully removed the keyloggers from my pc and changed all my passwords

i would recommend you do a huge clean up with this software named "Malwarebytes' Anti-Malware 1.44" if you used any of these programs like me
01/15/2010 11:30 Epic_Rage#2
If any of these are made in Autoit then ofc it will come up as a virus, just be aware of that, as near-none of Autoit programs are viruses which have been posted so far, but always scan/decompile anything you download (if you can decompile it) for safety
01/15/2010 11:32 Boat#3
Quote:
Originally Posted by Epic_Rage View Post
If any of these are made in Autoit then ofc it will come up as a virus, just be aware of that, as near-none of Autoit programs are viruses which have been posted so far, but always scan/decompile anything you download (if you can decompile it) for safety
i know what are false positives but i checked these myself with ollydbg

and they were infected

and also 3 anti viruses (kaspersky, avira, malware bytes anti malware) has proven that these files have been infected with a very well known keylogger named bifrost

(also some that i compiled myself from public sources made totally different results)
01/15/2010 11:32 _FoulSoul_#4
in lolkops original tools (bot,loader,autopotion) is not infected in keyloggers 200%.
only who download tools from the game chat links it's 100% virus.
01/15/2010 11:34 Boat#5
Quote:
Originally Posted by _FoulSoul_ View Post
in lolkops original tools (bot,loader,autopotion) is not infected in keyloggers 200%.
only who download tools from the game chat links it's 100% virus.
i downloaded them from here like 4months ago

also u must know those tools were working for me but they had hidden malwares

also the new ones are not infected for me either
01/15/2010 11:48 _FoulSoul_#6
any tool for silkroad has bad positives, but they are not effective( i talking about lolkop tools)
01/15/2010 12:09 HaGsTeR#7
"Hidden viruses is lurking behind the corners, Watch out!"
01/15/2010 12:55 audi0slave#8
[Only registered and activated users can see links. Click Here To Register...]

Do that and you`ll be ok.

#closed