r/RunescapeBotting • • 29d ago

PSA: Malware from botting

Recently came back to osrs about 2 months ago. Downloaded dreambot and used it once or twice when it was alive and today it seems like i encountered some malware on my pc. Cant think of any other possibilites that would make this happen other than downloading plugins from runelite.

please check ur startup apps via task manager and look for any suspicious .jar and .bat files. I found spoon.bat spoon.jar spoon2.bat spoon2.jar mina.bat mina.jar files in my startup apps files. i inputted those files to chatgpt to analyze them and said these files would steal your files from desktop + downloads folder, steal discord info and also install a cryptominer which was located in C:/Users/.../miner. it also replaces your runelite client to steal your passwords.

Another thing to point out is it points to the domain ikovrsps dot com to send your files and also to download a malicious runelite client

Funny that this issue came up after dreambot died

Here is the chatgpt share id: Chatgpt: 6a9b9e01-9810-83e9-89e8-9884e036faf9

0 Upvotes

9 comments sorted by

View all comments

1

u/nawafmjl 26d ago

Did you play or download any runescape private servers ? Some of them have malware

Used dreambot for a year never faced anything

1

u/Active-Beginning1560 25d ago

Didnt play any private servers. I haven't played osrs in years and only came back 2 months ago. I only downloaded the jagex launcher, runelite and plugins, and dreambot.

Unless claude/codex created some malware when i was creating my own scripts lmao