Log in

View Full Version : Compromised by Super Private Keylogger


Cauhauna
July 1st, 2010, 20:41
Hello,

I recently acquired 3 private "hacks" for a video game.

one (or more) of them contains a keylogger which successfully compromised by system, recorded keystrokes, and reported to an outside party. I am typing this from my freshly D-BANned desktop 7 pass with mbr rewrite --- had to be sure. I will post the three files for analysis. I tried to look at them with Olly but i couldn't find anything. One (or more) of them are encrypted.

Keylogger defeated the following:
Virustotal.com initial scan
ProcessGuard
Comodo
Avira
Malware Bytes Anti Malware
Doesn't appear to show up in HJT or any other process viewer

I don't need to know how to "cure" the infection -- I'm wiping all machines regardless. What I DO need to know is which file package contains the virus, as I need to use whichever file package(s) is clean. I'll be uploading them shortly from the infected machine.

These files are super private hacks for a video game, held in tight groups of "friends" to prevent them from going public, as the hack detection system is tight (updated with public hacks regularly).

The Three Files are:

Package 1) An injector file (.exe) which injects a DLL into a running process (in this case, game.exe). The DLL is where the "hack" is written, and, when injected, produces the desired effects in game. The injector file got a 3/41 on virustotal, but the threats listed didn't sound "scary" -- they sounded like falses.

Package 2) Very similar, but with an Injector hosted @ the Novell website (i'm assuming it's safe). DLL that hooks into process

Pacakge 3) an .MPQ file that is used by the game. This file goes into the game directory and has been pre modified to produce some desirable effects.

I'll also allow a trusted member access to the system via teamviewer if they so desire. just post or pm me.

Cauhauna
July 1st, 2010, 20:50
here they are


and the third:

http://usershare.net/5dxq2ty2w498

_genuine
July 2nd, 2010, 10:55
There doesnt seem to be anything malicous about these files. Theyre basically DLL injectors.

xenakis
July 2nd, 2010, 13:14
And now they are not super private

Cauhauna
July 2nd, 2010, 14:21
No, one of them must be malicious.

These are the only 3 files that could have been the source. period.

somehow, someway, one of them is dirty.

there is 100% a virus/keylogger/rat/something in one of those files

what methods did you use to check?

esther
July 3rd, 2010, 01:36
eeks,looks like a lazy b*****,non researching,no homework done crack request

Silkut
July 3rd, 2010, 04:55
Plus your post doesn't comply with the malware forum rules:

_changing files extension to a non executable/clickable one (.exe to .sex for instance)
_password protecting the archive you attach to the thread.
_notifying in big red letters that the content is potentially malicious

Read the rules ("http://www.woodmann.com/forum/showthread.php?9907-Malware-Forum-RULES")

Woodmann
July 3rd, 2010, 19:55
There is nothing wrong with the files by themselves.

I suspect something in third .rar
I am not going to look at all of the files in the third .rar because I dont care one bit about this.

You do the research into .mpq files.
Get an extractor and then look at each of them yourself.

Shit, if there is a keylogger in there then your Comodo has been severely compromised.

Woodmann

yogi_saw
July 4th, 2010, 07:05
chk with virus total online antivirus service if u suspect any malware into it!!!