Gurukeylogger.sip.332 scan now

therangereminem

therangereminem

Jungle Guide

Join Date: Jan 2007

R/Mo

Gurukeylogger.sip.332 this is the source of the new hacks that have been happening, no anti virus has picked it up scanned with 10 types of antivirus scanners

justa heads up need to find all files ass. with that file name and remove

Admin Edit: This is blatant misinformation. I'm assuming you are trying to tell people that we had a keylogger on Guru and this is how people got hacked. Not only is this absolutely false, but no one who has been hacked has been infected from this site. We have gone through our servers, our ad servers and more. You are wrong, if you've been infected with a virus such as this it's from your own internet surfing, giving out your passwords, etc. and not this site.

I won't even address the fact that you gave no useful information in your post for anyone.

N1ghtstalker

N1ghtstalker

Forge Runner

Join Date: Dec 2007

E/

and how did you know of this file?

White Lies

White Lies

Frost Gate Guardian

Join Date: Feb 2007

oh dear.
hw did u notice the files?

Free Runner

Free Runner

Forge Runner

Join Date: Oct 2005

GW2G

Knights Of The Sacred Light [KSL]

Rather than making a rather vague post could you actually tell us how you found it? details people details.

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

One very simple question: who named this keylogger?

Aera

Aera

Forge Runner

Join Date: Dec 2005

Galactic President Superstar Mc [awsm]

E/

Not a very clever name for a keylogger if you want to do damage. Come on, as a hacker you wouldn't want your files to be found do you?

Darkobra

Darkobra

Forge Runner

Join Date: Aug 2006

Scotland

Type like an idiot, I'll treat you like an idiot

E/Me

So you scanned with 10 types of antiviruses, not one has picked it up and you somehow found it? So how do you expect us to remove it?

skitz

skitz

Academy Page

Join Date: May 2006

Australia

Handmedown Rejects [doob]

R/

this got 2 of my guildies, he serched for keylogger in his computer and thatd what popped up, this is serious. they even took his customized wepons and runes off his armour.

Arduin

Arduin

Grotto Attendant

Join Date: May 2005

The Netherlands

Limburgse Jagers [LJ]

R/

And now what? Time for everyone to start panicking? Anyone now of some means to remove these loggers?

Edit: I've searched for keyloggers on my machine, couldn't find any, and I haven't been hacked of late. Guess I'll grab some more cake.

Free Runner

Free Runner

Forge Runner

Join Date: Oct 2005

GW2G

Knights Of The Sacred Light [KSL]

Aswell as how to remove them details, how about whereabouts they came from? i know it says Guru on it but i've been a member for ages and have yet to see any traces of this. What have you guys been doing? have you clicked any ads? downloaded any programs linked to from here?

miskav

miskav

Jungle Guide

Join Date: Jun 2005

None

Mo/

My guess is they clicked on one of those links in the topics that are randomly created with random keywords to attract hits from google (Those topics are mostly deleted within 5 min)
And thus they got infected.

zwei2stein

zwei2stein

Grotto Attendant

Join Date: Jun 2006

Europe

The German Order [GER]

N/

Quote:
Originally Posted by miskav
My guess is they clicked on one of those links in the topics that are randomly created with random keywords to attract hits from google (Those topics are mostly deleted within 5 min)
And thus they got infected.
Because it is impossible to get infected by malicious flash ad, right?

Etta

Etta

Forge Runner

Join Date: Jun 2006

Mancland, British Empire

I find the lack of respond from the OP, disturbing.

Vitues

Vitues

Wilds Pathfinder

Join Date: Sep 2006

Sydney, Australia

Mo/W

Quote:
Originally Posted by zwei2stein
Because it is impossible to get infected by malicious flash ad, right?
Is It?

i just did a scan, nothing came up. Thank god

miskav

miskav

Jungle Guide

Join Date: Jun 2005

None

Mo/

Quote:
Originally Posted by zwei2stein
Because it is impossible to get infected by malicious flash ad, right?
Nah, I just figured because there seem to be only 2 known cases of this issue, and if It was a flash ad, I assume there would be more infections reported.

deathwearer

deathwearer

Krytan Explorer

Join Date: May 2005

Canada/Quebec

Silentum Altum

E/Mo

If you can get adware installed on your computer from a random website, why not a keylogger.

Kusandaa

Kusandaa

Forge Runner

Join Date: Jul 2006

N/Mo

I'm gonna check on this computer now, if I try and tell my parents on how to scan my desktop they'll break it apart.

I'm curious on how he found it though...

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

I can see 3 possible situations here:

1) FUD (Fear, Uncertainty, Doubt), the OP invented a story, he's a troll and wants to scare people;

2) Hacker's delight, the guy or one of his friends is a n00b h4ck0r who managed to install a keylogger somewhere and wants to brag about it;

3) Hacker's nightmare, the guy or one of his friends is a white-hat hacker who discovered the keylogger and wants to brag about it.

The tone of the OP suggests that this is not serious, but if we find how the name Gurukeylogger.sip.332 (a very strange name ...) was created, we have our answer.

Fried Tech

Krytan Explorer

Join Date: Sep 2007

[Yeti]

E/

I smell a hoax

DarkNecrid

Furnace Stoker

Join Date: Jul 2006

it's most likely either a FUD or the guy. Most white hat's don't really brag about this kind of stuff at all, from what I've seen.

Inde

Site Contributor

Join Date: Dec 2004

This is blatant misinformation. I'm assuming you are trying to tell people that we had a keylogger on Guru and this is how people got hacked. Not only is this absolutely false, but no one who has been hacked has been infected from this site. We have gone through our servers, our ad servers and more. You are wrong, if you've been infected with a virus such as this it's from your own internet surfing, giving out your passwords, etc. and not this site.

I won't even address the fact that you gave no useful information in your post for anyone.

BladeWind

BladeWind

Krytan Explorer

Join Date: Nov 2007

The Ice Wastes in the Underworld.

The Renegades Of Ascalon

E/

Three cheers for inde!


NoXiFy

NoXiFy

Wilds Pathfinder

Join Date: Aug 2007

★☆٭Ńēŵ~ŶờЯК٭☆★

The Benecia Renovatio [RenO]

Mo/Me

Stop downloading you know what. We all know that Gwen 'gets around', but don't google her stuff and download it >.<

graverobber2

Frost Gate Guardian

Join Date: Apr 2008

Order of the Flameseekers [NL]

W/

Quote:
Originally Posted by Fried Tech
I smell a hoax
*sniff, sniff* I smell it too

Ignatius Tremere

Ignatius Tremere

Lion's Arch Merchant

Join Date: Dec 2006

CANADA FTW!!!!

Mo/

Stay off the gold buying sites and your fine. viruses don't magically happen, you have to think of the source of all viruses. Hoax or not, stay away from shady sites and you don't get viruses. Another item to watch out for is pictures that may be corrupted, don't click on any pictures and especially stay away from pictures that link to obscure picture hosting sites. Corupted .jpg, .gif, and .tif are nasty little things that you don't need to interact with, as soon as you can see it your infected. Although it takes a skilled coder to be able to create one without a noticable size difference they do exist. Most sites won't display them properly but small image hosting sites will display them just fine and quite happily, usually they embed their own cookie type virus, tracker into the site as well. Why people get so worked up about viruses is beyond me, i do this for a living, and what i have learnt in the last 7 years is that 99% of viruses are I D 10 T errors. The most common way of getting someone else infected is using Social Engineering. 1 other word of advice. If it sounds too good to be true, IT IS!!!

Personally i don't run any AV software, i just do a scan once a week and i haven't had a virus in YEARS. So any tard that is getting infected on a daily basis, IT YOUR FAULT... yup i said it, but its true.

If you have a virus and can't figure out how to get rid of it, and your AV program won't clean it send me a pm and i'll give you some tips.

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

Quote:
Originally Posted by Ignatius Tremere
Corupted .jpg, .gif, and .tif are nasty little things that you don't need to interact with, as soon as you can see it your infected.
No, the correct sequence is:
1) you click the picture;
2) the browser goes awry;
3) the vulnerability is used by a particular program for direct exploitation.

Step 3 can be stopped by the use of up-to-date antiviruses, use Firefox and not IE, use Firefox add-ons such as NoScript.

You only get infected when your security (see this guide) is not good enough or you're one of the few unfortunate victim of a 0-day exploit.

Quote:
Although it takes a skilled coder to be able to create one without a noticable size difference they do exist.
Most modern browser won't accept broken pictures, though what really happens in fact is that there's a buffer overflow in a picture decoding module. This is constantly fixed and now rarely happens. As zwei2stein explained above, it's more sensible with Flash.

Quote:
but small image hosting sites will display them just fine
Remember: the website hosts the image, but only your broswer will display it. The browser is at fault here, not the hosting site, however small it is.

Quote:
Why people get so worked up about viruses is beyond me, i do this for a living, and what i have learnt in the last 7 years is that 99% of viruses are I D 10 T errors. The most common way of getting someone else infected is using Social Engineering. 1 other word of advice. If it sounds too good to be true, IT IS!!!
This amazes me from a security professional. Social engineering gets your logins, passwords, hidden urls, etc. You've heard of secure software coding? Know the OWASP Top 10? Now try to tell me what users can do about that... (I mean by not turning into a geek!)

Quote:
Personally i don't run any AV software, i just do a scan once a week and i haven't had a virus in YEARS. So any tard that is getting infected on a daily basis, IT YOUR FAULT... yup i said it, but its true.
Once more, you're just trolling or you're a very unprofessional security person. The trolling comment is "people are tard".

Quote:
If you have a virus and can't figure out how to get rid of it, and your AV program won't clean it send me a pm and i'll give you some tips.
Only contact people you trust, and I wouldn't trust you. May be you're just using social engineering to make people believe you're brilliant and then infect their computer? I don't know for sure but ...

lord of all tyria

Lion's Arch Merchant

Join Date: Mar 2007

Thread delivers.

bcelmo

bcelmo

Ascalonian Squire

Join Date: Mar 2006

Invalid Spell Target [HaX]

N/E

dudes basic crap ... if it happens that you have a keylogger or your computer and you av (in case you have any, i don`t use them) does not pick it up, than the easiest way to protect you from gettin yer gw account hacked is by letting the game remember your username.. trust me on this one. Because all that keyloggers do is record your keystrokes and mouse clicks. There are some that acutally do screenshots on predetermined intervals but most ppl will not use that option because loggers send to an email which eventually will be crowded with 100`s upon 100`s of emails per day. Only opening each one will take 3-4hours of someone`s day. By not actually typing your username when u login will make the guy reading the log with only the pass and he will need to figure out the email address that is used with GW. If it happens that u use the same email as your usual one .. than you are pretty much screwed cause he will find it in logs (if he has enough patience), but if it`s different u`ll let a hacka stare at yer useless pass

mistokibbles

Lion's Arch Merchant

Join Date: Mar 2008

N/A

Even if this was real, just because it has guru in it doesn't mean it's from guildwarsguru.

Painbringer

Painbringer

Furnace Stoker

Join Date: Jun 2006

Minnesota

Black Widows of Death

W/Mo

Be safe and don’t be a fool

1. Run a firewall Always
2. Run an antivirus an update and scan as much as possible
3. Run a free or purchased Malware scanner Scan periodically
4. Phishing protection turn it on
5. Clean your system periodically Example; CCleaner
6. Do not blindly click ever… wait for pages to load.
7. When pulling up a download page (antivirus or update etc) be careful on what you click sometimes ad banners look identical to what you are downloading
8. Let windows update itself (many security flaws can be fixed this way)
9. Update your Java (there is a new one that was just released)
10. If infected write down the information. Read up on what the little buggers can do. This is a more precautionary step. If you find a virus knowing what the name of it is can help support staff. Most scanners keep logs but if the virus shuts you out are you going to remember it?

Snow Bunny

Snow Bunny

Alcoholic From Yale

Join Date: Jul 2007

Strong Foreign Policy [sFp]

Guru doesn't have a keylogger, but you do because you've been going god-knows-where on the internet.

Not to mention that you're throwing your own mistakes onto Guru.

What a terrible way to conduct yourself.

/close

Kanyatta

Forge Runner

Join Date: Jun 2006

Guildless, pm me

R/Mo

Seeing as the OP has completely abandoned this thread, I assume we have fed this troll long enough.

I motion to close.

ShadowsRequiem

ShadowsRequiem

Furnace Stoker

Join Date: Oct 2005

Inde is Smoking [Hawt] *ToA*

W/E

Quote:
Originally Posted by Inde
This is blatant misinformation. I'm assuming you are trying to tell people that we had a keylogger on Guru and this is how people got hacked. Not only is this absolutely false, but no one who has been hacked has been infected from this site. We have gone through our servers, our ad servers and more. You are wrong, if you've been infected with a virus such as this it's from your own internet surfing, giving out your passwords, etc. and not this site.

I won't even address the fact that you gave no useful information in your post for anyone.
Inde to the rescue!

<3

Avai

Frost Gate Guardian

Join Date: Jul 2006

Maybe the OP was infected as well as his computer. This virus could be more dangerous than we think. The OP could have simply been trying to warn us but now he's in a hospital bed somewhere with no access to guru.




Or maybe he was just seeing if this thread would make it to a second page.

BenjZee

BenjZee

Forge Runner

Join Date: Dec 2006

The Overacheivers [Club]

Mo/

wtf like theres a keylogger going around
anyway only an idiot would use the same guru /main gw username etc + password

FeroxC

Krytan Explorer

Join Date: Mar 2006

EOA

P/W

1) Nobody is going to name a keylogger GuruKeylogger.
2) If its on your PC it will already be running and you wont be able to delete it.
3) Files don't automatically download and execute unless your systems seriously out of date.
4) A firewall should block a keylogger detectable or not

Damian979

Krytan Explorer

Join Date: May 2008

keylogger.... maybe not but this site is going to give my pop up blocker a nervous break down one day.

Rocky Raccoon

Rocky Raccoon

Desert Nomad

Join Date: Jan 2007

Massachusetts, USA

Guardians of the Cosmos

R/Mo

As a regular poster on this forum, I have no worries that any keylogger is coming from this site. If you Google the keylogger you mention the only 2 results are from posts you have made.

therangereminem

therangereminem

Jungle Guide

Join Date: Jan 2007

R/Mo

ok this file is what i sayit is i had guildys with it on there computer after then did a serach for it after getting there guildwars account hacked.

alli was tryign to do is help other poeple out and give a heads up, my whole allince is ticked off at this we dont know where it came from all i know is we did a man search there the poeples computers that got hacked and looked for certain things and that was what came up, guru can deny what it wants i know and my allince knows what it was and what it did

Inde

Site Contributor

Join Date: Dec 2004

Quote:
Originally Posted by therangereminem
ok so in the last week 3 of my allince memebrs have gotten hacked we area small allaince we haev known each other for 3 years + now,

i was on vent tonight about 1 hour ago and my friend got hacked i just did elonia reach with him and boom he went off line.

and he tried to reconnect , but got error message saying there is alreadya instance of guildwars running, right when he said that we said change your pw and keep tryign to log in, but it still gave himthe same message. mean while in allince chat we got the guy to say a couple of things..

wow 3 guy frm this allince this week newbs you must all do the same things.

i had to log into myfriends account for him with new pw to kick the guy off the account. but it was too late all mo ney and thing where gone happened in 2 min , my friend changed pw again

sence this has happened to my allince alot we are having a talk about using guru any more or signing up through anything for guildwars.

you say it only happens to rich poeple is bull 2 of the 3 poeple didnt even have fow armor or over 15k of anything on them no good rare skins or anything.

things we think have to do with it the tourney house within hours of signing up 72 or less there accounts hacked 1 person doesnt ever use guru, we are all on each others messangers, out of everyone that got hacked none use the -pw -account name in the target line

so either a its guildwars main site or b wiki or c through hotmail we are giving it to each other,

im doing more research on this

anet can and should be tracing ip that have this happen not only the ips hacking but who they are trading with they have to get it off somehow
You stated in your post that 1 person from your alliance that was hacked "doesn't ever use guru". You then stated you "had to log onto your friends account to kick the hacker off"... right there you have told us some of your problem.
  1. It wasn't from guru
  2. You are sharing passwords and logging onto each other's Guild Wars accounts