Wow.. More fail added to my collection.
So, I download this 'cheat'. I expect something of interest, and what do I find.
Quote:
|
Originally Posted by Readme When i click the hack nothing happens?
Answer: This happens sometimes because of the Anti-Copy protection of the hack, and can also happen to vista users,
but it is compatible with vista, but anyway when this happens its because you are not using the correct properties
of the hack, send it to as many friends as possible and see if it works for them, if it does then tell them
which Operating System they use etc etc. |
Send it to as many friends as possible? Wait.. dont you want to keep cheats away from people, so it cant be detected? This seems weird.
Lets continue, by Reversing and Hexing the 'cheat':
Code:
c:\Documents and Settings\FoXoF\My Documents\Visual Studio 2005\Projects\keystealer\release\keystealer.pdb
Right from the start we know what this is. Made by FoXoF, in his VS 2005 complier.
ITs KeySTEALER! Code:
codkey SOFTWARE\Activision\Call of Duty WAW %3Cbr%3E COD5: SOFTWARE\Activision\Call of Duty 2 COD2: SOFTWARE\Activision\Call of Duty 4 COD4: SOFTWARE\Activision\Call of Duty COD1: key SOFTWARE\Activision\Call Of Duty United Offensive CODUO: SOFTWARE\Electronic Arts\Electronic Arts\Crysis\ergc Crysis: \SOFTWARE\Electronic Arts\EA Games\Crysis Warhead(R)\ergc Crysis WarHead: Software\Electronic Arts\EA GAMES\Battlefield Vietnam\ergc Software\Electronic Arts\EA GAMES\Command and Conquer Generals Zero Hour\ergc CaCG_ZeroHour: Productkey SOFTWARE\THQ\Company of Heroes COH: %3Chr%3E /1.0
See what this steals? It shows no other functions on our preliminary inpection.
Lets upload it to Anubis and see what else we can find :
Anubis - Analysis Report
Code:
State: Normal establishment and termination - Transferred outbound Bytes: 33 - Transferred inbound Bytes: 191
DNS Queries:
www.foebia.info
From ANUBIS:1032 to 86.141.180.35:80 - [86.141.180.35]
Well, first off. Using this sandbox shows that it connects to the internet, but we suspected that. It shows dns queries and active connections to a website, and directly to an IP.
How can we get rid of this, what are our options:
Well, we first need to delete the file. Then check our hosts file ( google how todo that if you are not sure ). Find Hijackthis, and run it. Then Run a AV program, such as Bitdefender, or Nod32.
Lastly, use another machine, thats not infected, to change your information, such as passwords.