Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > 12Sky2
You last visited: Today at 07:31

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Zenith files investigation [possible RAT?]

Discussion on Zenith files investigation [possible RAT?] within the 12Sky2 forum part of the MMORPGs category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Feb 2010
Posts: 271
Received Thanks: 108
Zenith files investigation [possible RAT?]

Hello guys,

I would be careful with running ZenithSky client files, and so on.

I were investigating their files and I have found this:



See the Company? Katherina something? Ye. I googled that and I've did not found anything related to viruses or whatsoever in the first results, until I have found a result in the end of the first page leading to another hacking community forum.



I have also found some information about a program that allows to create RAT's or whatsoever here related to katherina walenski:

When scanning Zenith12sky.exe only few antivirus will report a false-positive (packed file, package, gen). Because it has been packed with a fishy packer I presume. Therefore antiviruses will not recognize malicious code if there is any.

I am just alerting people to be careful running their client nothing else, they always seem'd fishy to me. Doesn't matter if they are competitors of AE Sky or not.

Regards
MyDooMJr is offline  
Thanks
5 Users
Old 09/27/2015, 21:44   #2
 
elite*gold: 0
Join Date: Sep 2015
Posts: 19
Received Thanks: 11
I'd check the traffic from the launcher if I were you. Last time I checked, it sent a bunch of stuff that's not related to the game at all, whilst the game was running.
HairyWizard is offline  
Old 09/28/2015, 16:10   #3
 
elite*gold: 0
Join Date: Sep 2015
Posts: 1
Received Thanks: 0
I created an account especially for you.
Sorry but you fail hardcore.

I can clearly see you got something against Zenith, and you probably are a fanboy of AE.
Now to come with facts on the table.

I did a bigger research on your post. The first link you gave, is redirecting you towards the original thread. In the original thread someone investigated that report and it all came back negative, so not malicious. He didn't do a full research because that will take pretty long. Your second link is not pointing to any RAT as well.

Stop hating competition and spread around half or incorrect information. Better come with real facts on the table, or stfu.

I checked my services, processes etc while I opened up AE, and I opened up Zenith.
Both have no trojans or RAT's running in the background. So nice try, but fail.
unknown1981 is offline  
Old 09/28/2015, 16:40   #4
 
elite*gold: 0
Join Date: Sep 2015
Posts: 19
Received Thanks: 11
Quote:
Originally Posted by unknown1981 View Post
I created an account especially for you.
Sorry but you fail hardcore.

I can clearly see you got something against Zenith, and you probably are a fanboy of AE.
Now to come with facts on the table.

I did a bigger research on your post. The first link you gave, is redirecting you towards the original thread. In the original thread someone investigated that report and it all came back negative, so not malicious. He didn't do a full research because that will take pretty long. Your second link is not pointing to any RAT as well.

Stop hating competition and spread around half or incorrect information. Better come with real facts on the table, or stfu.

I checked my services, processes etc while I opened up AE, and I opened up Zenith.
Both have no trojans or RAT's running in the background. So nice try, but fail.
Check the network traffic coming from the launcher, or you clearly don't know how to do that. I'll release a launcher bypass for Zenith soon, so people can actually play it without that fishy **** launcher of theirs.

Also, that all virus scanners don't detect something as malicious, doesn't mean it isn't.

Let me elaborate a bit on the launcher, it pretty much functions as a relay server that relays game packets to the game server, for whatever reason, but those are not the only packets that it sends, which troubles me.
HairyWizard is offline  
Thanks
1 User
Old 09/28/2015, 18:14   #5
 
elite*gold: 0
Join Date: Feb 2010
Posts: 271
Received Thanks: 108
About the second link google: xtreme3.6private-fixed.exe
or

Adios!
MyDooMJr is offline  
Old 09/29/2015, 18:42   #6
 
elite*gold: 0
Join Date: Sep 2015
Posts: 15
Received Thanks: 0
It is probably sending information of your credit cards to the end server but its ok right? haha
TheUnknownWarrior is offline  
Old 09/29/2015, 19:05   #7
 
elite*gold: 0
Join Date: May 2010
Posts: 22
Received Thanks: 9
i wanted to play NSG, but this is disgusting. why can not 2 servers? i do not understand a lot of negative advertising. u get level, full gear or more? this first NSG launcher
this okay ? it was not a new topic .
K.e.f.e is offline  
Old 09/29/2015, 19:24   #8
 
elite*gold: 0
Join Date: Feb 2010
Posts: 271
Received Thanks: 108
Have you read the viruses?

Generic , ProcessPatcher.

VIPRE RiskTool.Win32.ProcessPatcher.Sml!cobra (v) (not malicious)

See if the current launcher has any viruses or weird **** going on the background. I thought so.

HairyWizard is right about the Zen launcher, something shady is going on. Might be nothing but who knows, I don't trust to much these chineses .
MyDooMJr is offline  
Old 09/29/2015, 20:15   #9
 
elite*gold: 0
Join Date: Sep 2015
Posts: 15
Received Thanks: 0
This guy with Virus Total is to funny.
TheUnknownWarrior is offline  
Old 09/29/2015, 20:42   #10
 
elite*gold: 0
Join Date: Jan 2010
Posts: 26
Received Thanks: 4
Quote:
Originally Posted by TheUnknownWarrior View Post
It is probably sending information of your credit cards to the end server but its ok right? haha
Wrong.. they use Paypal as payment method so they can't steal our credit cards information.


Anyway you guys should stop this hate against Zenith... it's start to be childish and really annoying.

You had and have people on AE who abuse bugs and they don't get banned, atleast here bug/hackers get banned in few minutes. Anyway stop this hate against zenith.
dudle05 is offline  
Old 09/29/2015, 21:01   #11
 
elite*gold: 0
Join Date: Sep 2015
Posts: 19
Received Thanks: 11
Quote:
Originally Posted by dudle05 View Post
Wrong.. they use Paypal as payment method so they can't steal our credit cards information.


Anyway you guys should stop this hate against Zenith... it's start to be childish and really annoying.

You had and have people on AE who abuse bugs and they don't get banned, atleast here bug/hackers get banned in few minutes. Anyway stop this hate against zenith.
Atleast Anrinch Entertainment has the ability to fix bugs (and introduce new content). And don't be so sure about him banning in a few minutes, I have a character with duped cash from 3 days ago and it's still not banned. Not that I'm saying AE is the better alternative of the two, but I'm suspicious of Zeniths files (the network activity in particular) and his (DDoS) attacks towards AE in general. That's exactly the reason why I'm planning to release exploits for Zenith (in due time.. ).
HairyWizard is offline  
Old 09/29/2015, 21:11   #12
 
elite*gold: 0
Join Date: Jan 2010
Posts: 26
Received Thanks: 4
Quote:
Originally Posted by HairyWizard View Post
Atleast Anrinch Entertainment has the ability to fix bugs (and introduce new content). And don't be so sure about him banning in a few minutes, I have a character with duped cash from 3 days ago and it's still not banned. Not that I'm saying AE is the better alternative of the two, but I'm suspicious of Zeniths files (the network activity in particular) and his (DDoS) attacks towards AE in general. That's exactly the reason why I'm planning to release exploits for Zenith (in due time.. ).
Zenith DDoS AE? Show us the proof. Don't say someone DDoS if you have 0 proof.

Got exploit? Show it.. prove it.. stop saying u got this and that without a bit of proof.

PS: Let's not forget duped items are not only available few mins or till u log off, so ur money and items are just for show.. not permanent... if u even know how to dupe
dudle05 is offline  
Old 09/29/2015, 21:19   #13
 
elite*gold: 0
Join Date: Sep 2015
Posts: 19
Received Thanks: 11
Quote:
Originally Posted by dudle05 View Post
Zenith DDoS AE? Show us the proof. Don't say someone DDoS if you have 0 proof.
As I've been told, there are strong assumptions that can not be ignored:

- The first time AE was ddosed was when Zenith first popped up.
- 2 weeks later, a supposed blackmailer had ddosed zenith and zenith agreed upon paying $800 and also ddosed AE, for a fee of $1000.
What the 'blackmailer' did not foresee is that his information could be traced easily and was traced to Zeniths hometown. This series of ddos attacks happened shortly after the official release.
- Zenith had no downtime from the supposed ddoser, as a matter of fact that one hour downtime he had was caused by something else. I'm not going into detail about this.

EDIT: Meet me at yongu blacksmith in 2 minutes @ zenith, and I'll show you.
HairyWizard is offline  
Old 09/29/2015, 21:25   #14
 
elite*gold: 0
Join Date: Jan 2010
Posts: 26
Received Thanks: 4
Quote:
Originally Posted by HairyWizard View Post
As I've been told, there are strong assumptions that can not be ignored:

- The first time AE was ddosed was when Zenith first popped up.
- 2 weeks later, a supposed blackmailer had ddosed zenith and zenith agreed upon paying $800 and also ddosed AE, for a fee of $1000.
What the 'blackmailer' did not foresee is that his information could be traced easily and was traced to Zeniths hometown. This series of ddos attacks happened shortly after the official release.
- Zenith had no downtime from the supposed ddoser, as a matter of fact that one hour downtime he had was caused by something else. I'm not going into detail about this.

EDIT: Meet me at yongu blacksmith in 2 minutes @ zenith, and I'll show you.
Waiting for you at blacksmith
dudle05 is offline  
Old 09/29/2015, 21:39   #15
 
almar12's Avatar
 
elite*gold: 0
Join Date: May 2011
Posts: 883
Received Thanks: 157
Quote:
Originally Posted by dudle05 View Post
Zenith DDoS AE? Show us the proof. Don't say someone DDoS if you have 0 proof.

Got exploit? Show it.. prove it.. stop saying u got this and that without a bit of proof.

PS: Let's not forget duped items are not only available few mins or till u log off, so ur money and items are just for show.. not permanent... if u even know how to dupe
In which fantasy world do you live?
Where did you get that from, the part of money and items just being for show lol?
almar12 is offline  
Reply


Similar Threads Similar Threads
Need help for investigation.
09/30/2012 - Archlord - 2 Replies
Hi for this idiot Broadwin and other noobs like him can i prove somehow that im not that cropwr or idk becouse everbody now think im the scammer,becouse of his posts...So i wana help of admin to help me in this,he ruin ym every posts withs tupid coments ..Ty in advence.
S> Lv 121 Bowmaster Zenith GMS
08/15/2012 - Trading - 1 Replies
Just as the title says. Lvl 121 Bowmaster in GMS Zenith server Only asking for 40 USD
SBot for private [Investigation]
05/27/2009 - SRO Private Server - 60 Replies
Dear members, Just answer this question, don't give me mumbojumbo about it's not possible etc. SBot for private servers. Do you want it? Are you willing to pay for it? Again, please just answer the question, there is no need to flame or w/e.



All times are GMT +1. The time now is 07:31.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.