ELSE - multi-class ControlClick bot

03/29/2008 02:09 Kristuliux19#721
really nice job, for those who dont have SV its a perfect, nice... keep it going
03/29/2008 02:23 adamant726#722
I AM A WATER TAOIST LVL 110 IT START ZAPING THE MOBS BUT ONLY STAY AROUND THAT SAME PLACE DOESN'T EVEN MOVE MEANING GETTING HIT MASSIVLY SO THIS IS NOT A FOR MULTI CHARACTERS BECAUSE I DON'T SEE IS DOING ANY LVLING FOR MY WATER ;P
03/29/2008 02:33 evanxxxm#723
adamant726@
u know u need to set "path" right?
of course it doesnt move if u dont select the path function...
03/29/2008 06:07 doithanhan1982#724
This bot have virus i have found by my Kapersky 6.0
03/29/2008 06:50 evanxxxm#725
ignore
03/29/2008 14:37 patriotul#726
infect!
03/29/2008 16:21 evanxxxm#727
finally someone use another term to describe "virus"
anyhow, i will explain why it is "infected"
nah, just kidding, whats the point for me self defending
let google do the job:
[Only registered and activated users can see links. Click Here To Register...]
03/30/2008 15:48 pjay#728
Okay... i know your gonna start flaming me..... but


File: ELSEpath_v1.2.rar
Status:
INFECTED/MALWARE
MD5: 26591fc41527253419e37052c3c43718
Packers detected:
-
Bit9 reports: File not found

Scan taken on 30 Mar 2008 13:35:05 (GMT)
A-Squared
Found Trojan.Win32.AutoHK.t
AntiVir
Found TR/AutoHK.AR
ArcaVir
Found Trojan.Downloader.Agent.Ejc
Avast
Found nothing
AVG Antivirus
Found Worm/Autoit.UT
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found Troj.W32.AutoHK.ar
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found Trojan.Win32.AutoHK.ar
Fortinet
Found W32/AutoHK.AR!tr
Ikarus
Found Win32.SuspectCrc
Kaspersky Anti-Virus
Found Trojan.Win32.AutoHK.ar
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found Mal/Generic-A
VirusBuster
Found nothing
VBA32
Found Trojan.Win32.AutoHK.ar




File 10691d1205905360-else-multi-class received on 03.29.2008 04:01:15 (CET)
Current status: finished
Result: 16/32 (50.00%)

AhnLab-V3 2008.3.29.0 2008.03.28 -
AntiVir 7.6.0.78 2008.03.28 TR/AutoHK.AR
Authentium 4.93.8 2008.03.28 -
Avast 4.7.1098.0 2008.03.28 -
AVG 7.5.0.516 2008.03.28 Worm/Autoit.UT
BitDefender 7.2 2008.03.29 -
CAT-QuickHeal 9.50 2008.03.28 Worm.AutoRun.aao
ClamAV None 2008.03.29 -
DrWeb 4.44.0.09170 2008.03.28 -
eSafe 7.0.15.0 2008.03.18 suspicious Trojan/Worm
eTrust-Vet 31.3.5653 2008.03.29 -
Ewido 4.0 2008.03.28 -
FileAdvisor 1 2008.03.29 -
Fortinet 3.14.0.0 2008.03.29 W32/AutoHK.AR!tr
F-Prot 4.4.2.54 2008.03.28 W32/Trojan2.WUI
F-Secure 6.70.13260.0 2008.03.28 Trojan.Win32.AutoHK.ar
Ikarus T3.1.1.20 2008.03.29 Win32.SuspectCrc
Kaspersky 7.0.0.125 2008.03.29 Trojan.Win32.AutoHK.ar
McAfee 5262 2008.03.28 -
Microsoft 1.3301 2008.03.28 -
NOD32v2 2982 2008.03.28 archive damaged
Norman 5.80.02 2008.03.28 -
Panda 9.0.0.4 2008.03.29 Suspicious file
Prevx1 V2 2008.03.29 WORM.SKIPI
Rising 20.37.41.00 2008.03.28 -
Sophos 4.28.0 2008.03.29 Mal/Generic-A
Sunbelt 3.0.978.0 2008.03.18 -
Symantec 10 2008.03.28 -
TheHacker 6.2.92.258 2008.03.29 Trojan/Downloader.Agent.hyx
VBA32 3.12.6.3 2008.03.25 Trojan.Win32.AutoHK.ar
VirusBuster 4.3.26:9 2008.03.28 -
Webwasher-Gateway 6.6.2 2008.03.28 Trojan.AutoHK.AR

Tell me these are false readings lol, if not i go stab myself:eek:
03/30/2008 16:39 opop2005ahmed#729
thanks man
realy nice
03/30/2008 17:30 evanxxxm#730
pjay@
anyone have autohotkey install in their computer can decompile my exe
since i always provide script inside, if there is a single line code that is different than the decompile one
then tell us about it
the download files will never change unless there is an update, so feel free to check it whenever u want

(the scans u provide mean nothing, it just mean many company scanners detect AHK as virus program, thats all.)

sorry everyone, i am so noob at programming that only AutoHotKey works for me
C++ is my second language, but guess what, i dont know any way that it can "readmemoryaddress"
03/30/2008 17:33 pjay#731
okai just wanted 2 know ^.^
03/30/2008 17:42 evanxxxm#732
pjay@
no problem at all, i am glad that people are aware of what they are downloading
thats why i always provide a script inside in my programs for people to compile themselves if they afraid of getting virus (and attract people to build up an interest in programming)
04/01/2008 08:34 evanxxxm#733
ELSEpath v1.3 is added
added jump function (wont take over the mouse movement)
04/01/2008 14:41 lemontearox#734
umm,mine says wrong memory address > <..first time user here :x
04/01/2008 18:07 evanxxxm#735
lemontearox@
then use the Debug to find the correct address or using Cheatengine
the instructions are on the first thread