Installed Ksro but it installed a keylogger wtf

Discussion portal for kSRO, jSRO, vSRO, cSRO, and all other SRO versions.
Post Reply
User avatar
Axeoo7
Frequent Member
Posts: 1078
Joined: Wed Oct 18, 2006 3:23 am
Quick Reply: Yes
Location: Somewhere Fun

Installed Ksro but it installed a keylogger wtf

Post by Axeoo7 »

Ok i downloaded ksro from the official website installed it. It did a 5 second update but when i clicked start my zone alarm blocked a keylogger program called kdfmgr.exe.

I was like wtf so i uninstalled it and reinstalled it into a new directory and found that it installed these files into that directory too.

Now im pissed thinking ksro had a keylogger into the installation file, just to double check i downloaded on another computer which never had sro or ksro or any game installed on it before and the same thing happened.

WTF is going on did KSRO get hacked and someone modified the installation file.

i downloaded SilkroadOnline_v2.03.exe yesterday the latest verstion from the official site, http://kr.silkroad.yahoo.com/dataroom/download.asp

My isro copy is still runing fine can someone test it out for me and see if your geting the same shit.
Playing GW1 Rarely
Image

owning_since_1981
Hi, I'm New Here
Posts: 19
Joined: Thu Apr 19, 2007 10:42 am

Post by owning_since_1981 »

perhaps u got it when u download somekind of hack/bot on normal sro :)

User avatar
Axeoo7
Frequent Member
Posts: 1078
Joined: Wed Oct 18, 2006 3:23 am
Quick Reply: Yes
Location: Somewhere Fun

Post by Axeoo7 »

owning_since_1981 wrote:perhaps u got it when u download somekind of hack/bot on normal sro :)


eh no never downloaded or visted anything like that
Playing GW1 Rarely
Image

User avatar
Kaigar
Regular Member
Posts: 252
Joined: Tue Jun 13, 2006 3:55 am
Quick Reply: Yes
Location: Australia

Post by Kaigar »

Is zone alarm just being strange? Is there a way to check that that file actually is a keylogger?
IGN: Kaigar - Retired

Until the day that the silkroad is all covered with lag...

User avatar
jackietang33
Casual Member
Posts: 71
Joined: Tue Apr 03, 2007 9:49 am
Quick Reply: Yes
Location: Greece

Post by jackietang33 »

Ahhh, ur one happened in ksro, my one was in isro ingame, my kaspersky anti vrius reported a keylogger, I clicked terminate and it closed my sro, i think its a bug

User avatar
StealMySoda
Ex-Staff
Posts: 5245
Joined: Sun Sep 03, 2006 2:37 pm
Quick Reply: Yes
Location: Off Topic
Contact:

Post by StealMySoda »

http://virusscan.jotti.org/

Upload it there, see what it says.
Ooh, I got a sexy ex-staff title!

User avatar
numatan
Common Member
Posts: 117
Joined: Mon Apr 02, 2007 3:57 pm
Quick Reply: Yes
Location: Sparta

Post by numatan »

My suggestion:

Find the kdfmgr.exe, zip it up, and send it to http://www.virustotal.com/en/indexf.html.

This link shows it to be a Lineage 2 password stealer/keylogger, but it's best to be sure.

User avatar
NuclearSilo
Forum God
Posts: 8834
Joined: Mon Aug 21, 2006 12:00 pm
Quick Reply: Yes
Location: Age of Wushu

Post by NuclearSilo »

Playing Age of Wushu, dota IMBA

User avatar
NuclearSilo
Forum God
Posts: 8834
Joined: Mon Aug 21, 2006 12:00 pm
Quick Reply: Yes
Location: Age of Wushu

Post by NuclearSilo »

Playing Age of Wushu, dota IMBA

User avatar
Axeoo7
Frequent Member
Posts: 1078
Joined: Wed Oct 18, 2006 3:23 am
Quick Reply: Yes
Location: Somewhere Fun

Post by Axeoo7 »

If someone can download the new installer from ksro and check it out for me please.

My ISRO is working fine no problems with it its only ksro installation with the new installer the old installer worked fine.

----

EDIT

HELP SOME DOWNLOAD THE NEW INSTALLER PLSSSS LET ME KNOW IF ITS CURRUPTED :banghead: :banghead: :banghead: :banghead: :banghead:
Playing GW1 Rarely
Image

User avatar
John_Doe
Advanced Member
Posts: 2094
Joined: Sun Mar 25, 2007 7:36 pm
Quick Reply: Yes
Location: Off topic

Post by John_Doe »

jackietang33
Posted: Fri Apr 27, 2007 11:04 am Post subject:
Ahhh, ur one happened in ksro, my one was in isro ingame, my kaspersky anti vrius reported a keylogger, I clicked terminate and it closed my sro, i think its a bug


same thing happened to me...I was like wtf Isilkroad keylogger...the isro download i have was from like 2006...I really hope its just a bug...cause when i do a normal scan (also uses kaspersky anti virus) it doesn't say any thing but if i start isro it warms me of keylogger I'll post screenshot later if I have time. To feel safe I'll scan it again.

Vandango
Senior Member
Posts: 4143
Joined: Sat Jun 03, 2006 3:23 pm
Quick Reply: Yes
Location: Babel

Post by Vandango »

Some Virus scanners go off for no reason
when i was with project raptor (CNC General zero hour mod) Nortan anti virus would detect a worm within its programming of corse there was nothing like that in there but nortan was the only virus scanner that detcted it

Zone Alarm most be doing the excat same thing except with KSRO

i would try the file Axeoo but i CBA atm
anyways hope ur having fun on Xian

Grtz Van
<<banned from SRF for bot admission. -SG>>

User avatar
BrowNTyGeR
Common Member
Posts: 186
Joined: Mon Mar 20, 2006 12:53 pm
Quick Reply: Yes
Location: Xian Retiree / Aion[NA] : Zikel Retiree

Post by BrowNTyGeR »

Dropper/KorGameHack.20336

Summary

Dropper/KorGameHack.20336 is a dropper creating trojan horse that steals the user account information of a specific online game. When the dropper is executed, it creates kdfmgr.exe (14,848 bytes) , vdete.exe (20,336 bytes) in the Windows system folder. which is the trojan stealing the user's key strokes and sending to a specific email address.


weirdddddddd ehhhh?
Image

User avatar
Sharp324
Senior Member
Posts: 4383
Joined: Tue Jan 30, 2007 4:24 am
Quick Reply: Yes
Location: Off Topic

Post by Sharp324 »

Most of the time it will say characteristics of a keylogger. Doesnt mean it is actually one but never can be too sure. To the person who said something about getting it from bots/hacks lol SRO isnt the only way to get keyloggers
------------------------------

User avatar
shousuke
Valued Member
Posts: 414
Joined: Wed Mar 29, 2006 3:12 pm
Quick Reply: Yes
Location: Xian

Post by shousuke »

its not a keylogger o.o
its something called kdefense
check ur ksro folder
Image
Image
http://img116.imageshack.us/img116/407/sawasig02nc2.jpg
waiting for euro

User avatar
sama98b
Frequent Member
Posts: 1428
Joined: Thu Feb 22, 2007 2:32 am
Quick Reply: Yes
Location: Aege

Post by sama98b »

Yes get ready for it in isro too soon.
It's a keylogger well actually something that monitors keyboard directly.
It is an extension or replacement for gameguard.

U can see the small icon in the taskbar if u alt-tab out.

ps.: By the way gameguard is a rootkit too, it is always active deep in the os
at every boot, the .sys is loaded and it's in the windows dir.

User avatar
shousuke
Valued Member
Posts: 414
Joined: Wed Mar 29, 2006 3:12 pm
Quick Reply: Yes
Location: Xian

Post by shousuke »

Image
Image
http://img116.imageshack.us/img116/407/sawasig02nc2.jpg
waiting for euro

User avatar
BlackFox
Forum Legend
Posts: 6588
Joined: Thu Jan 18, 2007 2:43 pm
Quick Reply: Yes
Location: Oo Some where i dont know!!

Post by BlackFox »

Note: Some of reported threats might be legitimate but in most cases they are dangerous.

Threat name Win32.X
Filename [System32Root]\kdfmgr.exe
Filesize Unknown
Status Known to RemoveIT Pro as dangerous.


oh shit :wink:
mwahahahahaha !!

User avatar
GodsAngel
Valued Member
Posts: 467
Joined: Sun Oct 01, 2006 5:56 pm
Quick Reply: Yes
Location: Venus

Post by GodsAngel »

kdfmgr.exe is part of a Korean program called Kdefense. If you google it you get sites that tell you it's a keylogger well it's not. It's a false positive disregard it and just play your ksro.
Last edited by GodsAngel on Fri Apr 27, 2007 8:42 pm, edited 1 time in total.
Euro- Mob baller * 1hand
ign: IAmZeeDevil
Guild:-=Avalon=-
gonna miss you all but I've officially quit silkroad :)
Current Projects
Comprehensive European Party Guide - -15% done
(currently setback)
Warrior Guide - -45% done
(working hard)

User avatar
Rainigul
Senior Member
Posts: 4490
Joined: Thu Mar 29, 2007 5:43 pm
Quick Reply: Yes
Location: Pacific

Post by Rainigul »

That's not the official one.

Official is v. 1.468 I think...

They changed it for whatever reason, because I remember I originally downloaded v 2.something.

Anyways. Yup.

User avatar
sama98b
Frequent Member
Posts: 1428
Joined: Thu Feb 22, 2007 2:32 am
Quick Reply: Yes
Location: Aege

Post by sama98b »

Search only on korean sites, it's not used in any english game yet.
K-Defense : http://www.ewithus.co.kr/3_5_1.htm

User avatar
BlackFox
Forum Legend
Posts: 6588
Joined: Thu Jan 18, 2007 2:43 pm
Quick Reply: Yes
Location: Oo Some where i dont know!!

Post by BlackFox »

GodsAngel wrote:kdfmgr.exe is part of a Korean program called Kdefense. If you google it you get sites that tell you it's a keylogger well it's not. It's a false positive disregard it and just play your ksro.


@ Axeoo7 Yea If you download on theirs real homepage I dont think Is a kelogger, But sometimes can spyware/antivirus think is a kelogger or whatever.But when you download this on other site so never now what can be on it..
mwahahahahaha !!

User avatar
Axeoo7
Frequent Member
Posts: 1078
Joined: Wed Oct 18, 2006 3:23 am
Quick Reply: Yes
Location: Somewhere Fun

Post by Axeoo7 »

Im so confused because their were files called kdefence or something and the icon had kd anyway not sure now what it is but im not gonna mess with ksro anymore till i find out.

That site that was given the upload never worked and ive deleted the installation file and folder so im not going back to ksro ever again.
Playing GW1 Rarely
Image

yshi
Hi, I'm New Here
Posts: 18
Joined: Thu Dec 28, 2006 9:09 pm

Post by yshi »

Axeoo7 wrote:Im so confused because their were files called kdefence or something and the icon had kd anyway not sure now what it is but im not gonna mess with ksro anymore till i find out.

That site that was given the upload never worked and ive deleted the installation file and folder so im not going back to ksro ever again.


Lol man,Its just part of the new security system they have,kdfmgr.exe its just a program that dont let foreign ppl write pass and login,if you try write them,you will just get some wierd letters like s~~ç~.so dont worry its just part of the new security update they got,when the game start just ctrl alt del go to Processes,look for kdfmgr.exe and End task,simples as that,just play your ksro and be happy,ITS NOT A KEYLOGGER,its part of ksro now.

Cya

PureOwnage
Frequent Member
Posts: 1104
Joined: Thu Jun 01, 2006 6:54 pm

Post by PureOwnage »

Axe it aint a keylogger, I am a programmer and I can tell you for a fact it isnt a keylogger, it is infact part of an intergrated system to stop people who are non-korean from playing KSRO, once you edit the game files to set to english you should be good to go. (btw its me Memphist :D)
<<banned from SRF for rules violations. -SG>>

User avatar
sama98b
Frequent Member
Posts: 1428
Joined: Thu Feb 22, 2007 2:32 am
Quick Reply: Yes
Location: Aege

Post by sama98b »

^^ got any way to switch language settings on the keyboard like
it could be done before k-def.

Used to switch alt+shift+(number) from english>korean>japanese>...
Used applocale to display ingame text korean in english setup xp.

k-def screwed it up.

Now game is set to english in pk2, and found no way to type korean anymore.

Post Reply

Return to “Other SRO versions”