[RELEASE]ECSRO Zoomhack,multiclient,no-dc,bot-ready

05/14/2009 08:05 orico16#121
ty...work good
05/17/2009 11:21 shajan#122
ey
geht das über haupt
05/18/2009 00:23 ProlificSky#123
Everything works great...cept...now I'm getting DC'd often while using Sibibot. Any reason why this is happening? Thanks.
05/18/2009 21:43 alxtz#124
doesnt work for me on fembria only got the zoom hack help.
05/23/2009 10:25 IcyQueeN#125
hey guys does this zoom hack works on SjSro too?
05/23/2009 10:28 DarkPassion#126
Well since its same version as ecsro yes it works :p
05/23/2009 22:34 ProGuardian#127
Does this work with the recent update?
05/23/2009 23:19 Davincibg#128
Quote:
Originally Posted by ProGuardian View Post
Does this work with the recent update?
Yes
05/24/2009 01:15 ProGuardian#129
sibi bot doesnt work anymore . atleast not for me...
05/24/2009 06:35 khmerst1111#130
Quote:
Originally Posted by silkbotter View Post
hey folks.
me and Apokalypse finally made it!!

here are the ultimate modded silkroad executables.
The modded sro_client.exe and silkroad.exe contain:

- Zoomhack
- No-DC
- Multiclient
- sibi bot-ready (looks like it only works when you login at the first try)


feel free to scan the file.
the only things that were changed were some JNZ's into JMP's in assembler code.

like always, i've got to remind you, that i do NOT intend to ruin my reputation on Elitepvpers. the (false positive) "viruses" contained in the archive are the same as the ones from the original client.
:rtfm:


here's the download:
[Only registered and activated users can see links. Click Here To Register...]

here's the scan:
[Only registered and activated users can see links. Click Here To Register...]




all credits go to Apokalypse and me for finally "cracking" the zoom!

(for those who are interested in doing by themselves:
the pointer is sro_client.exe+600B04, the initial value of the closest zoom is the Float value (4bytes long) 10, and every out-zoom-scroll adds 6 to the previous value, and the max value is usually 150)

don't forget the thx button if you enjoy this release :P
THE RAPIDSHARE LINK IS BROKEN FOR SOME PPL CAN U UPLOAD IT TO ANOTHER WEBSITE?!?!?!? RATHER THAN RAPIDSHARE?
05/25/2009 22:55 elgato1000#131
The mirror is not broken, just use another navigator like firefox.
06/04/2009 15:48 DreaminLife#132
Thank you very much :)
06/05/2009 22:23 Allegra#133
my kaspersky said its pmd.keylogger wtf!

Quote:
Antivirus Version letzte aktualisierung Ergebnis
a-squared 4.0.0.101 2009.05.22 Virus.Win32.Agent.aj!IK
AhnLab-V3 5.0.0.2 2009.05.22 Win-Trojan/Xema.variant
AntiVir 7.9.0.168 2009.05.22 -
Antiy-AVL 2.0.3.1 2009.05.22 -
Authentium 5.1.2.4 2009.05.22 -
Avast 4.8.1335.0 2009.05.22 -
AVG 8.5.0.339 2009.05.22 Pakes.AZA
BitDefender 7.2 2009.05.22 Trojan.Generic.1445605
CAT-QuickHeal 10.00 2009.05.22 -
ClamAV 0.94.1 2009.05.22 Trojan.Downloader.Banload-4698
Comodo 1157 2009.05.08 Unclassified Malware
DrWeb 5.0.0.12182 2009.05.22 -
eSafe 7.0.17.0 2009.05.21 -
eTrust-Vet 31.6.6518 2009.05.22 -
F-Prot 4.4.4.56 2009.05.22 -
F-Secure 8.0.14470.0 2009.05.22 -
Fortinet 3.117.0.0 2009.05.22 PossibleThreat
GData 19 2009.05.22 Trojan.Generic.1445605
Ikarus T3.1.1.49.0 2009.05.22 Virus.Win32.Agent.aj
K7AntiVirus 7.10.741 2009.05.21 Trojan.Win32.Malware.1
Kaspersky 7.0.0.125 2009.05.22 -
McAfee 5623 2009.05.22 -
McAfee+Artemis 5623 2009.05.22 -
McAfee-GW-Edition 6.7.6 2009.05.22 Worm.Win32.Malware.gen!90 (suspicious)
Microsoft 1.4701 2009.05.22 -
NOD32 4098 2009.05.22 probably a variant of Win32/Genetik
Norman 6.01.05 2009.05.22 -
nProtect 2009.1.8.0 2009.05.22 Trojan/W32.Agent.9128960
Panda 10.0.0.14 2009.05.22 Generic Trojan
PCTools 4.4.2.0 2009.05.21 -
Prevx 3.0 2009.05.22 -
Rising 21.30.42.00 2009.05.22 -
Sophos 4.42.0 2009.05.22 -
Sunbelt 3.2.1858.2 2009.05.22 -
Symantec 1.4.4.12 2009.05.22 -
TheHacker 6.3.4.3.331 2009.05.22 -
TrendMicro 8.950.0.1092 2009.05.22 -
VBA32 3.12.10.5 2009.05.22 -
ViRobot 2009.5.22.1747 2009.05.22 -
VirusBuster 4.6.5.0 2009.05.22 -
weitere Informationen
File size: 9128960 bytes
MD5 : 578b5ae17e3702fe36bf21498020973b
SHA1 : 42ef50f75eba572be0c64f21da258de527344462
SHA256: 8ad359200ae194e9edd4a5af7a970b9ae2af57ab11a9012ac5 d6f70342197d00
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x47EAED
timedatestamp.....: 0x4545B211 (Mon Oct 30 09:04:33 2006)
machinetype.......: 0x14C (Intel I386)

( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x53A000 0x53A000 6.66 bc6f2255105e386ed7d363a6ac3a9bfb
.rdata 0x53B000 0x6C000 0x6C000 4.73 01407aa9bb0056aa0a638a933073b92e
.data 0x5A7000 0x2FD000 0x2FD000 0.89 7685bebf70fe1beb4bd5d3f48c32e32c
.rsrc 0x8A4000 0xA000 0xA000 4.05 bca594ae663525432ca76613db0ac061
.17sro 0x8AE000 0x2000 0x2000 5.79 a8e66f2e69baa30e20a282f2d541eaeb
.adata 0x8B0000 0x1000 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.idata2 0x8B1000 0x2000 0x2000 4.65 bbd267a0fd4346ce3f422a0b98ebf4e0
.idata2 0x8B3000 0x2000 0x1C00 5.05 ab3cf5c42ac2e6b648098a5705f75d05
[Only registered and activated users can see links. Click Here To Register...]
06/06/2009 01:07 silkbotter#134
hey mr kingli 1337 pr0 master.
do you have any acknowledgment of HOW a bot works?
heard anything about packet capture/injection?

even strukel gave me a thanks for this release!!
stop funking saying it's a virus!!
download it or leave it.

if you're that smart saying it is a virus, then just use the fucking offsets i posted, and assemble the exe by yourself (i hoe you know what olly debugger is).

there are always some noobs that i will never understand in my whole life....

btw. i had about 8000 download of this file.. there isn't even 1 little post on this topic saying that someone was hacked.
think about it before posting stuff like ya did.
06/06/2009 12:32 Allegra#135
puh i just fucking asked why my fucking kaspersky say its pdm.keylogger just fucking ASKEDDDDDD!?i know how`to work a bot,start exe click login start silkroad login start f6 bäm!?