MALWATE WARNING: (2Moons hack Trainer v3)

08/22/2009 16:49 HellSpider#16
Yeah don't mess with it unless you know what to do :).

Btw, anyone got the first release of the trainer (some months ago)? Is that trainer clean? If it is, it could be that someone else appended the malware into it. It doesn't have to be VxWxV. Just thought of that...
08/22/2009 16:53 Vaidas B#17
the first V3 trainer? or THE FIRST trainer he made?
08/22/2009 16:55 HellSpider#18
Quote:
Originally Posted by waidas123 View Post
the first V3 trainer? or THE FIRST trainer he made?
The v3 I suppose. Anyway the one with the same visual looks :).
08/22/2009 16:59 6Drako9#19
no I think hes talking about V1 and V2

also I found the gadu-gadu keygen trying to extract the scripts lol
I was looking for resemblances to the known scripts and in the presses I think I borke the keyen and it was giving an error every time it took a screen shot lol.

I would like to extract the Trainer only but Im not sure what is the trainer and what is not.
I would like to learn tho
08/22/2009 17:09 HellSpider#20
Quote:
Originally Posted by 6Drako9 View Post
no I think hes talking about V1 and V2

I would like to extract the Trainer only but Im not sure what is the trainer and what is not.
I would like to learn tho
If you say so, idk what it's called but I mean the one with the same visual looks and functions. It was released before. I wonder if it was a clean one or one like this too.

The good thing about the runtime SFXes are that they store all the files in a temporary folder. The clean trainer can be found there too. And the Gadu-Gadu.exe . It would be much harder if the trainer would've been compiled to work malicious. But no, all malicious things are just appended in a runtime SFX :).
08/22/2009 17:33 vitorjun#21
can someone tell me if the [Only registered and activated users can see links. Click Here To Register...]
its clear, and the fist , kind of cheat were clear ?, 'cause i'm usin him percect usa hack , share folder( from the fist tut, that he deleted)
08/22/2009 17:44 HellSpider#22
Quote:
Originally Posted by vitorjun View Post
can someone tell me if the [Only registered and activated users can see links. Click Here To Register...]
its clear, and the fist , kind of cheat were clear ?, 'cause i'm usin him percect usa hack , share folder( from the fist tut, that he deleted)
It should be ok. All CSV files are always clean. Idk about the additional tools.
08/22/2009 18:27 SillyLittleWhore#23
Quote:
Originally Posted by InstantDeath View Post
Looks like the Malware has been appended to the trainer by Microsoft CAB SFX. I managed to extract the trainer from the SFX. So what I'm saying is that the trainer isn't a malware but there has been a malware appended to the trainer in the form as an runtime SFX archive.
So...I'm seeing two files inside the trainer exe - 2MOONS~2.EXE & server.exe.

Just viewing the server.exe in winrar's internal viewer, I can see the address it sends data to.

What did you use to view the internals on these?

Is there anything compelling in the trainer?

I 'spose I could sandbox it, and use a throwaway account with it to test.
08/22/2009 18:56 Sodomizied#24
Quote:
Originally Posted by L.e.v.i.a.t.h.a.n View Post
My ORYGINAL Trainer is Clear and Dont Have any Virus. And all LINKS what post NOOBS are not MY so I dont now what They do Wich Him.
Its Hard to believe you .. , Well Number One Reason is , You barely posted on this thread , How long it take you to come up with that lie? No Offense does he Speak English?
08/22/2009 19:10 SillyLittleWhore#25
So....I extracted and am using the trainer itself after dumping the server.exe.

But shouldn't the original thread be nuked for 1-click?
08/22/2009 19:20 Sodomizied#26
Quote:
Originally Posted by L.e.v.i.a.t.h.a.n View Post
Hmm U now what I tell u? GTFO and dont begin me for hack u Noob wana Hack so do Them.
I'm lost are you a fucking stupid ass retard or what?

Quoting Stupid Kid

"U now I what tell u?

GTFO and dont begin me for hack?"

I'm not asking for your stupid hack cunt. So stfu you stupid fucking idiot , you qqing about me saying you put the shit in it only makes you look worst. Really don't care if I get an Infraction for that.
08/22/2009 19:52 Keith1#27
Quote:
Originally Posted by L.e.v.i.a.t.h.a.n View Post
Hmm U now what I tell u? GTFO and dont begin me for hack u Noob wana Hack so do Them.
Sure Sounds like VXV lol.
08/22/2009 21:03 HellSpider#28
Quote:
Originally Posted by SillyLittleWhore View Post
So....I extracted and am using the trainer itself after dumping the server.exe.

But shouldn't the original thread be nuked for 1-click?
It should, but the mods are somewhere else than on E*pvp.

Quote:
Originally Posted by Keith1 View Post
Sure Sounds like VXV lol.
Wonder why? :p...
08/22/2009 21:23 ~Twister~#29
Quote:
Originally Posted by L.e.v.i.a.t.h.a.n View Post
My ORYGINAL Trainer is Clear and Dont Have any Virus. And all LINKS what post NOOBS are not MY so I dont now what They do Wich Him.
lol at you man no offense but everybody knows, all mods and all people who were there when u posted trainer v 3 know that it had keylogger in it made by you, wanna ask any MOD lol? you still got that childish sence of humor and a big ego :) Well hope sometime you'll grow up, best of luck to you man ;)
08/22/2009 23:24 ♠Blunt♠#30
Amen