Poker Forum

Over 1,246,000 Posts!

Subscribe to FTR web feed
Already Registered?      Username:    Password:   Remember      Forgot Password
  >    > 

***Poker Tracker IDE POSSIBLE KEYLOGGER ALERT***

  
 
LinkBack Thread Tools Display Modes
Warpe
Old 04-16-2008, 08:55 PM     Post subject: ***Poker Tracker IDE POSSIBLE KEYLOGGER ALERT*** #1 (permalink)  
Warpe's Avatar
Moderator

Join Date: Sep 2005
Location: Canuckistan
Posts: 3,905
Warpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the rough
We have reason to suspect that a piece of software known as Poker Tracker IDE may contain a keylogger or other malicious software that is being used to steal passwords to poker accounts. We don't know this for sure but players are advised to NOT download and install this software under any circumstances.

Also, many players have reported being contacted individually on MSN by someone trying to get them to install the software. DO NOT GIVE THIS PERSON ANY INFORMATION WHATSOEVER ABOUT YOUR POKER ACCOUNTS!

Related links here:

http://www.flopturnriver.com/phpBB2/...21.html#650687

http://www.flopturnriver.com/phpBB2/...60.html#675287
Be careful out there, people.
 
Reply With Quote
Join the FTR Poker Forum to disable these banners and start posting!
Warpe
Old 04-16-2008, 09:21 PM #2 (permalink)  
Warpe's Avatar
Moderator

Join Date: Sep 2005
Location: Canuckistan
Posts: 3,905
Warpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the rough
Also posted on 2+2

http://forumserver.twoplustwo.com/sh...d.php?t=181440

and pocketfives

http://www.pocketfives.com/poker-for...02A00_-2795816
 
Reply With Quote
mrhappy333
Old 04-16-2008, 10:48 PM #3 (permalink)  
mrhappy333's Avatar
Full House

Join Date: Jan 2006
Location: Hartford, CT
Posts: 1,078
mrhappy333 is on a distinguished road
Send a message via AIM to mrhappy333
didnt read yet, But is this only with new PTs or even existing ones?
3 3 3 I'm only half evil.
 
Reply With Quote
JL
Old 04-16-2008, 11:20 PM #4 (permalink)  
Full House

Join Date: Jan 2006
Posts: 1,095
JL will become famous soon enough
Quote:
Originally Posted by mrhappy333
didnt read yet, But is this only with new PTs or even existing ones?
This has nothing to do with PT at all. It's a scam software called pokertracker IDE.
Reply With Quote
poker_pup
Old 04-16-2008, 11:30 PM #5 (permalink)  
Straight

Join Date: Apr 2007
Posts: 130
poker_pup
Thanks for the warning.
Reply With Quote
meeloche
Old 04-17-2008, 02:04 AM #6 (permalink)  
meeloche's Avatar

Join Date: Feb 2007
Posts: 2,131
meeloche is on a distinguished road
http://www.flopturnriver.com/phpBB2/...hh-t69760.html

In case nobody thinks it can actually happen...
 
Reply With Quote
Jack Sawyer
Old 04-17-2008, 02:31 AM #7 (permalink)  
Jack Sawyer's Avatar
4-of-a-Kind

Join Date: Jan 2007
Location: Old School
Posts: 2,535
Jack Sawyer will become famous soon enoughJack Sawyer will become famous soon enough
Do not even visit their website for now, as we are not sure how they infect the pc

It may use something about the buffer to infect the browser, and thus the pc. Do not visit the website (or at least not on your main pc. do it in a separate virtual machine or something if you wish)
My dream... is to fly... over the rainbow... so high...



Quote:
VHS is like a book and a book is like a stack of kindles.
Hey, I'm in a movie!
http://youtu.be/lGdnIrRKDTI
 
Reply With Quote
badgers
Old 04-17-2008, 02:35 AM #8 (permalink)  
badgers's Avatar
4-of-a-Kind

Join Date: Feb 2007
Location: Spewing
Posts: 3,372
badgers
Send a message via MSN to badgers
Quote:
Originally Posted by Jack Sawyer
Do not even visit their website for now, as we are not sure how they infect the pc

It may use something about the buffer to infect the browser, and thus the pc. Do not visit the website (or at least not on your main pc. do it in a separate virtual machine or something if you wish)
Yeah exactly can someone block out all the links?
3k post - Return of the blog!
 
Reply With Quote
Halv
Old 04-17-2008, 07:10 AM #9 (permalink)  
Halv's Avatar
pro crastinator
4-of-a-Kind

Join Date: Aug 2005
Location: No hindsight for the blind.
Posts: 1,842
Halv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond repute
Quote:
Originally Posted by badgers
Quote:
Originally Posted by Jack Sawyer
Do not even visit their website for now, as we are not sure how they infect the pc

It may use something about the buffer to infect the browser, and thus the pc. Do not visit the website (or at least not on your main pc. do it in a separate virtual machine or something if you wish)
Yeah exactly can someone block out all the links?
The links in this thread are auto-generated and lead to the real PT website (note how every time someone writes Poker Tracker a link is generated). I went ahead and edited out the links in the referred threads.

I visited the site back in february when the original thread surfaced (but didn't download/install anything), how worried should I be? Using Opera, AVG, ZoneAlarm, Snoopfree.

First music vid: http://www.youtube.com/watch?v=MFerARdGW04
Free stream of different song here: http://www.nrk.no/urort/artist/wellfear ('Lytt'/play button on right side)
 
Reply With Quote
Warpe
Old 04-17-2008, 07:54 AM #10 (permalink)  
Warpe's Avatar
Moderator

Join Date: Sep 2005
Location: Canuckistan
Posts: 3,905
Warpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the rough
From the sound of things you have to download the installer, so just visiting the site is not so bad. We don't know this for sure but it all adds up.
 
Reply With Quote
badgers
Old 04-17-2008, 11:22 AM #11 (permalink)  
badgers's Avatar
4-of-a-Kind

Join Date: Feb 2007
Location: Spewing
Posts: 3,372
badgers
Send a message via MSN to badgers
Halv there's wtill a link in page 1 of wtf ahhhhhhhhhhhhhh. I don't know how worried you should be I'm sure you're far more computer savvy than me so idk.
3k post - Return of the blog!
 
Reply With Quote
Halv
Old 04-17-2008, 12:46 PM #12 (permalink)  
Halv's Avatar
pro crastinator
4-of-a-Kind

Join Date: Aug 2005
Location: No hindsight for the blind.
Posts: 1,842
Halv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond repute
Woops, seems like I only cleaned up one of the threads, sorry. I've gone through the wtfaah thread now.

I'm running nightly scans with avg, spybot, adaware and crap cleaner, nothing has come up. I'd be a little surprised if you could get infected just by visiting the site, but I'm still gonna go the paranoid route and change all my passwords from a clean computer today. I change them all once a month anyway, now seems like a good time as any. If I was gonna go totally paranoid I would reformat, but I don't think that's called for with the information at hand.

First music vid: http://www.youtube.com/watch?v=MFerARdGW04
Free stream of different song here: http://www.nrk.no/urort/artist/wellfear ('Lytt'/play button on right side)
 
Reply With Quote
will641
Old 04-17-2008, 04:00 PM #13 (permalink)  
will641's Avatar
4-of-a-Kind

Join Date: Aug 2007
Location: getting my swell on
Posts: 1,610
will641 is on a distinguished road
i just dont get it. im running system suite for spyware and virus', and it says nothing is detected.
Cash Rules Everything Around Me.
 
Reply With Quote
jyms
Old 04-17-2008, 04:15 PM #14 (permalink)  
jyms's Avatar
Tilting Mod

Join Date: Feb 2006
Posts: 4,836
jyms has a spectacular aura aboutjyms has a spectacular aura aboutjyms has a spectacular aura about
try posting your task manager processes, maybe someone can spot something running that shouldn't be
 
Reply With Quote
Warpe
Old 04-17-2008, 04:28 PM #15 (permalink)  
Warpe's Avatar
Moderator

Join Date: Sep 2005
Location: Canuckistan
Posts: 3,905
Warpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the rough
Quote:
Originally Posted by will641
i just dont get it. im running system suite for spyware and virus', and it says nothing is detected.
Keyloggers work at the root so won't necessarily be detected. For all we know, they could've accessed the data while they delayed you online with that "Problem with promotional code" message.

The fact that your e-mail isn't working now is defintely a concern. Just wipe the fucker, though someone more tech savvy should tell you how.
 
Reply With Quote
will641
Old 04-17-2008, 04:54 PM #16 (permalink)  
will641's Avatar
4-of-a-Kind

Join Date: Aug 2007
Location: getting my swell on
Posts: 1,610
will641 is on a distinguished road
Quote:
Originally Posted by Trainer_jyms
try posting your task manager processes, maybe someone can spot something running that shouldn't be
here is everything that is by me. i.e. not system programs

Cash Rules Everything Around Me.
 
Reply With Quote
Warpe
Old 04-17-2008, 05:00 PM #17 (permalink)  
Warpe's Avatar
Moderator

Join Date: Sep 2005
Location: Canuckistan
Posts: 3,905
Warpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the rough
Download and run this:

http://free.grisoft.com/doc/download-free-anti-rootkit/

but srsly, I'd wipe it
 
Reply With Quote
Halv
Old 04-17-2008, 05:13 PM #18 (permalink)  
Halv's Avatar
pro crastinator
4-of-a-Kind

Join Date: Aug 2005
Location: No hindsight for the blind.
Posts: 1,842
Halv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond repute
Get snoopfree as well. It'll tell you anything that tries to hook the keyboard and/or scrape the screen. http://www.download.com/SnoopFree-Pr...html?tag=lst-1

I would also look into HijackThis.

I'm with warpe tho - reformat the HD and reinstall windows.

First music vid: http://www.youtube.com/watch?v=MFerARdGW04
Free stream of different song here: http://www.nrk.no/urort/artist/wellfear ('Lytt'/play button on right side)
 
Reply With Quote
jyms
Old 04-17-2008, 05:28 PM #19 (permalink)  
jyms's Avatar
Tilting Mod

Join Date: Feb 2006
Posts: 4,836
jyms has a spectacular aura aboutjyms has a spectacular aura aboutjyms has a spectacular aura about
I just ran that and found a keyhook in UltraMon. Does anyone know why this program needs it?
 
Reply With Quote
Halv
Old 04-17-2008, 05:35 PM #20 (permalink)  
Halv's Avatar
pro crastinator
4-of-a-Kind

Join Date: Aug 2005
Location: No hindsight for the blind.
Posts: 1,842
Halv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond repute
Typically a keyboard hook is related to a hotkey in the program. Ie "press ctrl+space to do this and that", that'll require a keyboard hook. Some applications require it for general text input, for example PartyPoker hooks the keyboard to use with the chat box (however typing bets works fine when blocked).

You'll also see programs taking screenshots when you access drop-down menus alot, I have no idea why they do it though. I typically just deny everything, then if there's a problem with using the program I'll manually allow it (if I've decided to trust the program).

First music vid: http://www.youtube.com/watch?v=MFerARdGW04
Free stream of different song here: http://www.nrk.no/urort/artist/wellfear ('Lytt'/play button on right side)
 
Reply With Quote
Halv
Old 04-17-2008, 05:37 PM #21 (permalink)  
Halv's Avatar
pro crastinator
4-of-a-Kind

Join Date: Aug 2005
Location: No hindsight for the blind.
Posts: 1,842
Halv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond reputeHalv has a reputation beyond repute
will, check out usnsvc.exe
http://www.file.net/process/usnsvc.exe.html

First music vid: http://www.youtube.com/watch?v=MFerARdGW04
Free stream of different song here: http://www.nrk.no/urort/artist/wellfear ('Lytt'/play button on right side)
 
Reply With Quote
jyms
Old 04-17-2008, 05:41 PM #22 (permalink)  
jyms's Avatar
Tilting Mod

Join Date: Feb 2006
Posts: 4,836
jyms has a spectacular aura aboutjyms has a spectacular aura aboutjyms has a spectacular aura about
and stop using MSN and AIM. Get Trillian. One program and not a microsoft product
 
Reply With Quote
Warpe
Old 04-17-2008, 05:49 PM #23 (permalink)  
Warpe's Avatar
Moderator

Join Date: Sep 2005
Location: Canuckistan
Posts: 3,905
Warpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the roughWarpe is a jewel in the rough
woot! triple post!

new Computer Security Primer post in Tools. I love the internetz...

http://www.flopturnriver.com/phpBB2/...er-t69797.html
 
Reply With Quote
Reply
Latest Poker News
KoRnholio Old 05-26-2012, 03:08 PM    Australia Legalized Online Poker coming up in next 6 to 12 Months
According to an email sent out by Mark Bryan, a gaming analyst at Merrill Lynch, the Australian government plans to legalize online poker sometime in the next six to 12 months. This move will coincide ...

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 07:29 AM.


FTR Testimonials

All content
© FlopTurnRiver.com
Advertising  |   Partners  |   Testimonials  |   T&C  |   Contact Us  |   FTR News & Press  |   Site Map  |   Search FTR

Full Tilt  |   Titan Poker  |   UltimateBet  |   Poker Stars  |   Ladbrokes Bonus  |   Sportsbook  |   Cake Poker  

Play Texas Holdem Online, Online Texas Holdem Strategy, & Poker Forum
This is not a gambling website.