Page 1 of 6 123 ... LastLast
Results 1 to 15 of 80
  1. #1
    Royce's Avatar
    Join Date
    Oct 2011
    Gender
    male
    Posts
    17,967
    Reputation
    4088
    Thanks
    6,418

    WARNING: If you downloaded "ROTMG Easy Hotkeys" By C4pt4in 4lph4

    Yesterday @C4pt4in 4lph4 posted a ROTMG Easy Hotkeys tool and it contained a phisher, If you used this program you are a victim!!! Change all important information when you have a chance before your personal things are stolen


    Quote Originally Posted by KrazySkank View Post
    I could have reported back faster but im banned for a bit for disrespect.
    Anyways, I looked over it:
    - It's not a keylogger, it's a .SOL stealer
    - The fag who made it will have access to steam accounts because GUIDs were stolen.
    - No malicious sofware was installed, it ran an operation every time someone started the app.

    Royce Distraught

    I used this while I had a mule logged in and lost 16 life, much less than the others. Please update the topic with this info.
    Thanks to Krazy for breaking it down a little. Going to have Master decompile the file when he's awake and get a more detailed analysis.

    Make sure to:
    -Change any passwords related to MPGH, ROTMG, Steam, or your emails. (obviously any other accounts you may be concerned of)
    -Run an anti-malware program to make sure your clean. Program doesn't seem to install anything.
    Last edited by Distraught; 10-24-2013 at 02:37 PM.

  2. The Following 2 Users Say Thank You to Royce For This Useful Post:

    Daenerys (10-24-2013),jollyboots (10-24-2013)

  3. #2
    Daenerys's Avatar
    Join Date
    Aug 2013
    Gender
    female
    Location
    Westeros
    Posts
    961
    Reputation
    114
    Thanks
    5,435
    My Mood
    Devilish
    Got hacked. Used all my coins + took all my WC tops. RIP.

  4. #3
    Distraught's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    California
    Posts
    1,897
    Reputation
    659
    Thanks
    1,355
    Sorry about this. Getting it sorted. That's why it's important for us to decompile every file. I suggest doing this yourself if you don't already. Here is the malicious code:


  5. #4
    Daenerys's Avatar
    Join Date
    Aug 2013
    Gender
    female
    Location
    Westeros
    Posts
    961
    Reputation
    114
    Thanks
    5,435
    My Mood
    Devilish
    Dang. Thought it was safe, so went lazy mode.

  6. #5
    Distraught's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    California
    Posts
    1,897
    Reputation
    659
    Thanks
    1,355
    Quote Originally Posted by Timii View Post
    Dang. Thought it was safe, so went lazy mode.
    and so did the minion who approved it. Thank god it wasn't @Royce

  7. The Following User Says Thank You to Distraught For This Useful Post:

    Royce (10-24-2013)

  8. #6
    Royce's Avatar
    Join Date
    Oct 2011
    Gender
    male
    Posts
    17,967
    Reputation
    4088
    Thanks
    6,418
    Quote Originally Posted by Timii View Post
    Dang. Thought it was safe, so went lazy mode.
    We are getting this sorted out at the moment, it should not of been approved.

  9. #7
    Distraught's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    California
    Posts
    1,897
    Reputation
    659
    Thanks
    1,355
    If you need help removing a keylogger and such post here. Any flame will lead to this thread being closed.

  10. #8
    Daenerys's Avatar
    Join Date
    Aug 2013
    Gender
    female
    Location
    Westeros
    Posts
    961
    Reputation
    114
    Thanks
    5,435
    My Mood
    Devilish
    Well, I deleted almost all of the remains of it. Is there a way that there is still the residue of this keylogger existing on my computer?

  11. #9
    MDii's Avatar
    Join Date
    Sep 2012
    Gender
    male
    Posts
    7
    Reputation
    10
    Thanks
    0
    My Mood
    Tired
    thanks certainly, but I already lost also the numerous gold and many things)))

  12. #10
    Distraught's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    California
    Posts
    1,897
    Reputation
    659
    Thanks
    1,355
    Quote Originally Posted by Timii View Post
    Well, I deleted almost all of the remains of it. Is there a way that there is still the residue of this keylogger existing on my computer?
    There's not much to do besides change your info and run Malware Anti-bytes or something similar. @master131 if you want to elaborate.
    Last edited by Distraught; 10-24-2013 at 02:21 PM.

  13. #11
    unsocial's Avatar
    Join Date
    Jul 2009
    Gender
    male
    Posts
    852
    Reputation
    212
    Thanks
    128
    My Mood
    Bored
    thanks for the heads up.

  14. #12
    Beex's Avatar
    Join Date
    May 2008
    Gender
    male
    Location
    Posh Gang HQ
    Posts
    644
    Reputation
    55
    Thanks
    407
    My Mood
    Angelic
    Quote Originally Posted by Distraught View Post


    and so did the minion who approved it. Thank god it wasn't @Royce
    Would @Royce have been able to decompile and locate this malicious code if he was the minion on at the time? This is why we need atleast one well-versed ROTMG minion.

  15. #13
    Jennings169's Avatar
    Join Date
    Aug 2013
    Gender
    male
    Posts
    37
    Reputation
    10
    Thanks
    2
    How do I make sure I have removed it?

  16. #14
    carbonnade's Avatar
    Join Date
    Oct 2012
    Gender
    male
    Posts
    534
    Reputation
    19
    Thanks
    63
    My Mood
    Twisted
    this is sad can't believe people do this I just hope next time we can find if someone put bad juju in :/

  17. #15
    Distraught's Avatar
    Join Date
    Jan 2013
    Gender
    male
    Location
    California
    Posts
    1,897
    Reputation
    659
    Thanks
    1,355
    Quote Originally Posted by Ryan_Duke View Post


    Would @Royce have been able to decompile and locate this malicious code if he was the minion on at the time? This is why we need atleast one well-versed ROTMG minion.
    It's not like it wasn't easy to catch. Trust me, you could see the suspicious string right off the back then decompile it further to understand it. Anyone would of caught this one if they actually took the steps they were supposed to. but yes this is the exact reason I agreed we needed someone familiar with the section or malicious code.

    Quote Originally Posted by Jennings169 View Post
    How do I make sure I have removed it?
    My anti-viruses wouldn't pick it up so your manually going to have to check your processes/services under Task Manager. You can also go further by checking your registry. Any program similar to Malware Anti-bytes will clean it though.
    Last edited by Distraught; 10-24-2013 at 02:13 PM.

Page 1 of 6 123 ... LastLast

Similar Threads

  1. Warning-Read Before you download ANYTHING!
    By Cal in forum Minecraft Creations
    Replies: 7
    Last Post: 04-26-2011, 04:04 AM
  2. Replies: 8
    Last Post: 11-17-2009, 04:35 AM
  3. (Important) Getting rid of your keylogger if you downloaded maximo's hack!
    By mastowns in forum Combat Arms Hacks & Cheats
    Replies: 63
    Last Post: 05-06-2009, 05:56 PM
  4. Replies: 0
    Last Post: 05-04-2009, 07:51 PM
  5. After you download a Warrock hack you get a virus (here for help)
    By alld0n33 in forum WarRock - International Hacks
    Replies: 3
    Last Post: 02-27-2009, 10:08 PM