Jump to content

Recommended Posts

Posted (edited)

The last few weeks there's a kid lurking on the forum spreading keyloggers. He has access to more than 15 MXC accounts approximately and he's trying to get more. His main target is to steal your hard-worked & earned money from your PayPal, Skrill and other payment processors. This kid is sharing files as executable (.exe) so BE CAREFUL. DO NOT RUN ANY EXECUTABLE FILE BEFORE SCANNING IT WITH VIRUSTOTAL.COM. STILL THOUGH, VIRUSTOTAL MIGHT NOT CATCH IT BECAUSE OF THE ENCRYPTION. IN ANY WAY, DO NOT TRUST ANYONE FOR A WHILE. ESPECIALLY IF IT'S ABOUT AN EXECUTABLE.

 

Now, if you ran his files, change your passwords and format your computer right away. I tried myself to remove his shit from my computer and it took me so damn long, so it's not worth it. Go straight for a format.

 

You will see him sharing L2 stuff (lameguard, maps, tools, etc) but he might change his trends later.

 

If you want to see if you got infected, search your computer for the folder "Imminent".

 

It should be located here: C:/Users/<Name>/AppData/Roaming/Imminent/Logs/ 

 

If it exists do the following:

 

check up your processes by hitting alt+ctrl+del simultaneously -> task manager -> processes 

 

And then look for "winlogor.exe", if it exists, right click on it -> open file location -> delete

 

Download MBAM & BitDefender. Run a full scan with both of them and check what are the results. If you don't have the right knowledge to do so, just format your computer before seeing your money transferred to another PayPal account.

 

Note: I recommend you to have an update AV/Anti-malware always. Just to be 100% sure before jumping on fake conclusions, run a full scan using an antivirus (BitDefender, NOD32, etc) & an anti-malware (Malware Bytes - Antimalware) & Ccleaner, it will help you clean junk.

 

A few information that I have gathered about the mr h4x0r:

 

PayPal email: dimitriou16@outlook.com

Email(s): hack0t@hotmail.com | andrianosg@outlook.com

Edited by N1nj4Styl3
Posted

Give some foruum account name at least, thanks.

He doesn't have a certain account. He uses the accounts of the people who downloaded his files.

Posted (edited)

I tried myself to remove his shit from my computer and it took me so damn long, so it's not worth it. Go straight for a format.

I had this shit on my pc... But when i searched on my processes (Ctrl - Alt - Delete), i found a "Winlogor.exe"...

The real name of this processes is "Winlogon.exe" and no Winlogo"r".exe

When I looked at the date, been in windows/system32 from 23/02/2015. I kick off this shit...

and now the real "Winlogon.exe" is there from 17/7/2014.

 

Not need always format..

Edited by 'Baggos'
Posted

I had this shit on my pc... But when i searched on my processes (Ctrl - Alt - Delete), i found a "Winlogor.exe"...

The real name of this processes is "Winlogon.exe" and no Winlogo"r".exe

When I looked at the date, been in windows/system32 from 23/02/2015. I kick off this shit...

and now the real "Winlogon.exe" is there from 17/7/2014.

 

Not need always format..

I know, I found it as well.

It stores all the logs in AppData/Imminent/Logs

You run supposedly lameguard and it appears up as Google Chrome.exe (that's random). The thing is you need to kick out winlogor.exe.

I wanted to format my computer anyway, so that's why I did it. But yeah, in case someone is not capable of finding these stuff a format would be ideal to be 100% secure.

Posted (edited)

and which file is this? 

I think I have not missed anything in my first post.

 

/EDIT

 

If you want to see if you got infected, search your computer for the folder "Imminent".

 

It should be located here: C:/Users/<Name>/AppData/Roaming/Imminent/Logs/ 

 

If it exists do the following:

 

check up your processes by hitting alt+ctrl+del simultaneously -> task manager -> processes 

 

And then look for "winlogor", if it exists, right click on it -> open file location -> delete

 

Download MBAM & BitDefender. Run a full scan with both of them and check what are the results. If you don't have the right knowledge to do so, just format your computer before seeing your money transferred to another PayPal account.

Edited by N1nj4Styl3
Posted

i don't have winlogor on task manager but i have winlogon is this the same or no?

should i remove it?

09D4YHK.png

No, this means you're fine. If you right click on it and press "open file location" you will see that's located in System32. Verify this.

Posted

No, this means you're fine. If you right click on it and press "open file location" you will see that's located in System32. Verify this.

well one friend tested and it's fine but when i try to open the file location don't open the location but i found it inside the folder System32 as you said

Posted

well one friend tested and it's fine but when i try to open the file location don't open the location but i found it inside the folder System32 as you said

Run task manager as administrator, this might help.

 

Updated first post with a few info about the mr h4x0r.

Guest
This topic is now closed to further replies.



  • Posts

    • Do you want stability? Lagless and bugless game? Instant support? Daily PVP? Long-Term playing? You are in the right place, time to start! Lineage2 X70 Interlude NEW Season 2025 February 8th 13:00 UTC+2 Greece/Lithuania: 13:00 UTC+2 Poland/Norway: 12:00 UTC+1 United Kingdom: 11:00 UTC+0 Brazil/Argentina: 8:00 UTC-3 Opening Bonus First 100 players after third class changing will automaticly get Premium Coin award in their inventory. All new players spawn in town of Gludio! All players start from 25 LvL with starter pack (adenas and equipment)! RATES XP: x70 | SP: x70 Party XP/ SP: x1.2 Adenas drop rate: x30 Drop Items: x25 | Spoil: x25 Drop SealStones rate: x1.2 Drop Manor rate: x1 Drop Quest rate: x5 | Reward rates: x2 (NOT FOR ALL) Raid Boss Drop: x10 Raid Boss Adenas Drop: x3 Grand Boss Drop: x1 Grand Boss Adenas Drop: x2 Information NPC Buffer 32 Buffs | 4 Debuffs PET Buffer for all classes [Except Necromancer] Scheme buffer: 3 Profiles. Buffs time: 2 Hours | Summons buffs - 60min. Global Gatekeeper. GM SHOP till weapon / armor / jewel B grade. Caradine letter 3rd part in GM Shop. Offline shop: SELL , PRIVATE CREATION , PACKAGE SALE from 35 LvL ! Mana potions: 500MP/2s. Spawn Protection: 20 Seconds. EVENTS Manager [TVT/DM]. Max Clients for one PC: 5 Rift | 4S Players: 3 Maximum inventory slots: 240 Maximum inventory slots for Dwarf: 250 Custom drop list: - Raid Boss Horus, Ember, Brakki, Nakondas: 1 VIP COIN (25%) | Korim (50%). - Raid Boss Apepi, Shacram, Atraiban, Korim: 1 BEWS (25%). - Raid Boss Glaki, Olkuth: 1-2 BEAS (40%). - Raid Boss Golkonda, Galaxia: 1-3 BEAS (60%). - Raid Boss Shyeed: 1-3 BEWS (30%) | 1-7 BEAS (40%) | 1-5 TOP LS 76 (50%). - Raid Boss Shuriel: 1-7 TOP LS 76 (50%) | 1-4 BEAS (60%). - Raid Boss Ashakiel: 1-2 BEWS (30%) | 1-7 TOP LS 76 (50%) | 1-4 BEAS (75%). - Raid Boss Antharas Priest Cloe: 1-3 BEWS (30%) | 1-7 TOP LS 76 (70%). ------------------------------------------------ - Hestia: Demon Splinters / Forgotten Blande (10%). - Ember: Arcana Mace / Draconic Bow (10%). - Galaxia: Angel Slayer / Heaven's Divider (10%). 1. Baium Lair and TOI 13/14 are PVP zones. 2. Valakas PVP zone near NPC "Klein" and inside Valakas room. 3. Antharas Lair and near "Heart Of Warding" are PVP zones. 4. Frintezza PVP zone is in first Imperial Tomb room. 5. Queen Ant PVP zone after the bridge and near Boss. 6. Zaken ship deck and rooms - PVP area. How to connect STEP BY STEP: 1. Install clear Lineage2 Interlude client 2. Download our patch, delete old system folder and add our 3. Delete, turn off anti virus or add our system folder to anti virus exceptions 4. Run l2.exe from Lineage2/system 5. Enter data on login window and enjoy the game! * You have to remove, turn off or use exceptions of antivirus because of our security protection. It is not a virus. * If you have connection issues with Windows 8 or 10, press right mouse button on l2.exe icon, press Properties, choose compatibility and unmark compatibility mode. Take your friends, clan, alliance, enemys, sharp your swords, clean your armors and meet your destiny at 2025 February 8th 13:00 UTC+2! WWW.L2BLAZE.NET INTERLUDE Empire X70 New Season: 2025 February 8th 13:00 UTC+2! WEBSITE: http://WWW.L2BLAZE.NET
    • Hello all,  i use L2jAcis 409 and i have problem with oly cycle, everyday is a different oly cycle and oly won't finish at the end of the month...almost 50 cycles and no end. I see oly matches in db but no points and after a day pass with /olympiadstat no points... Any help welcome, thank you.
    • Bump NEW USER IN TELEGRAM AND DISCORD IS "mileanum"  NEW USER IN TELEGRAM AND DISCORD IS "mileanum"  NEW USER IN TELEGRAM AND DISCORD IS "mileanum" NEW USER IN TELEGRAM AND DISCORD IS "mileanum" 
  • Topics

×
×
  • Create New...