Thread Tools Display Modes
01-19-08, 02:02 AM   #1
WaldoJeffers
A Molten Giant
 
WaldoJeffers's Avatar
Join Date: Jan 2007
Posts: 564
Thumbs down I clicked a keylog link

I was fooled by a keylogger link on the official wow forums and clicked it
I want to log on in 1 hour to raid. But first I want to know it is safe. I have run Ad-Aware, AVG, HijackThis, RootkitRevealer and googled every single running processes. Through these I have seen wowincgamer listed in a Ad-Aware scan several times.

Here is latest scan result for Ad-Aware
Scan detailed statistics
===========================
Type Critical Total
Process Scan....: 0 0
Registry Scan...: 0 0
Registry PE Scan: 0 0
Hosts File Scan.: 0 0
File Scan.......: 0 0
Folder Scan.....: 0 0
LSP Scan........: 0 0
ADS Scan........: 0 0
Cookie Scan.....: 24 24
File Hash Scan..: 0 0

Infections Found
===========================
Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
Item Id: 600000598 Value: Browser: Firefox Cookie: C:\Documents and [B]Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt wow.incgamers.com bblastvisit /
Item Id: 600000598 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt wow.incgamers.com bblastactivity /
Item Id: 600000598 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt wow.incgamers.com __utmz /
Item Id: 600000598 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt incgamers.com __qca /
Item Id: 600000598 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt wow.incgamers.com __utmb /
Item Id: 600000598 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt wow.incgamers.com __utma /[/b]

Item Id: 600000661 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt kontera.com cluid /
Item Id: 600000661 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt kontera.com imprs /
Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt adserver.incgamers.com OAID /
Item Id: 600000457 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt adopt.euroclick.com DMEXP /
Item Id: 600000457 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt adopt.euroclick.com CTCI /
Item Id: 600000457 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt adopt.euroclick.com HS /
Item Id: 600000457 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt adopt.euroclick.com NSC_mc-bepqu.fvspdmjdl.dpn-iuuq /
Item Id: 600000457 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt adopt.euroclick.com UI /
Item Id: 600000050 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt tribalfusion.com ANON_ID /
Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt fastclick.net m3 /
Item Id: 600000447 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt apmebf.com S /
Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt fastclick.net m1 /
Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt fastclick.net pjw /
Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt fastclick.net pluto /
Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt advertising.com ACID /
Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt advertising.com BASE /
Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt advertising.com F1 /
Item Id: 600000295 Value: Browser: Firefox Cookie: C:\Documents and Settings\Joel\Application Data\Mozilla\Firefox\Profiles/5jsbyoag.default\cookies.txt adtech.de JEB2 /
Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
Item Id: 1 Value: MRU Path: C:\Documents and Settings\Joel\Recent Count: 2
Item Id: 2 Value: MRU Registry Key: S-1-5-21-1060284298-1085031214-725345543-1004\Software\Microsoft\Search Assistant\ACMru\5603 Count: 2

The wowincgamer traces keep appearing each Ad-Aware scan I do, after removing all.

I don't use wowincgamer.com! And that's all I have seen through scans anyhow, who knows what else is lurking around especially after that keylog link I clicked on. Is this anything to worry about?
Thanks
__________________
I said lady, step inside my Hyundai

Last edited by WaldoJeffers : 01-19-08 at 02:10 AM.
  Reply With Quote
01-19-08, 02:23 AM   #2
Antiarc
An Aku'mai Servant
 
Antiarc's Avatar
AddOn Author - Click to view addons
Join Date: Nov 2006
Posts: 34
Those cookies shouldn't be anything serious to worry about. They're perfectly legit cookies; however, if you picked up a keylogger of the variant we've seen running around lately, then it won't show up in your process list.

I'd recommend trying the steps in Cairenn's post here if you think you have picked something up: http://www.wowinterface.com/forums/s...threadid=14502

I know AVG didn't pick up the last round of keylogger trojans - you might try AntiVir, which is free for personal use and can be obtained at http://freeav.com
  Reply With Quote
01-19-08, 02:25 AM   #3
WaldoJeffers
A Molten Giant
 
WaldoJeffers's Avatar
Join Date: Jan 2007
Posts: 564
Thankyou very much!
__________________
I said lady, step inside my Hyundai
  Reply With Quote

WoWInterface » General Discussion » Chit-Chat » I clicked a keylog link


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off