[RFOPH]Working Tools

04/14/2008 14:31 squidol#1
These tools are currently working on RFOPH[Philippine RF Online]

Files uploaded respectively

1. RFbinCMvr_nopatch.rar (RF.exe and RF_online.bin CM version)

- you need this to bypass the tools

2. YaRFOB.rar (Yet another RF Online Bot)

- a premium bot shared

3. RFep2_multiclient.rar

- Enable to run multiple RF windows
04/14/2008 16:54 borlet#2
already posted,but anyways,nice compilation for those newbies out there.
04/14/2008 16:54 zereke#3
YaRFOB.rar - Trojane horse Dopper agent DYZ - found by AVG virus scan

not safe?
04/14/2008 17:18 edtexodus#4
Any program with the ability to hook other threads/processes to access their protected address space is suspicious to most virus scanners.
04/15/2008 05:05 linuex#5
Do this WORK...
[ nagana b 2 ]

the Rfph still on maintenance.... i cant try it yet..

[ ung server ng rfph on maintenance p e gsu2 ko m try ]
04/15/2008 11:45 pekpek143#6
hmmmm the multiclient doesnt work...registry patch cant detect dude or no path detected....
04/15/2008 14:40 smash231#7
this was already posted hehe but its ok!nice job
04/15/2008 18:55 patawer#8
File YaRFOB_V1.15MH.exe received on 04.15.2008 18:45:20 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 23/32 (71.88%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
AhnLab-V3 2008.4.15.1 2008.04.15 Win-Trojan/Ardamax.14848.B
AntiVir 7.6.0.85 2008.04.15 SPR/Ardamax.K.Gen
Authentium 4.93.8 2008.04.14 W32/Trojan.AXGS
Avast 4.8.1169.0 2008.04.15 Win32:Agent-LWO
AVG 7.5.0.516 2008.04.15 Dropper.Agent.DYZ
BitDefender 7.2 2008.04.15 Backdoor.Hupigon.EMK
CAT-QuickHeal 9.50 2008.04.14 -
ClamAV 0.92.1 2008.04.15 Trojan.Spy.Ardamax-25
DrWeb 4.44.0.09170 2008.04.15 -
eSafe 7.0.15.0 2008.04.09 -
eTrust-Vet 31.3.5700 2008.04.15 -
Ewido 4.0 2008.04.15 Dropper.Agent.bit
F-Prot 4.4.2.54 2008.04.15 W32/Trojan.AXGS
F-Secure 6.70.13260.0 2008.04.15 Ardamax.gen2
FileAdvisor 1 2008.04.15 -
Fortinet 3.14.0.0 2008.04.15 Adware/Ardamax
Ikarus T3.1.1.26.0 2008.04.15 Trojan-Dropper.Win32.Agent.bjm
Kaspersky 7.0.0.125 2008.04.15 Trojan-Spy.Win32.Ardamax.e
McAfee 5274 2008.04.15 Keylog-Ardamax.dr.gen
Microsoft 1.3408 2008.04.14 TrojanSpy:Win32/Ardamax.C
NOD32v2 3028 2008.04.15 -
Norman 5.80.02 2008.04.15 W32/Ardamax.gen1
Panda 9.0.0.4 2008.04.14 Application/Ardamax
Prevx1 V2 2008.04.15 Heuristic: Suspicious Self Modifying File
Rising 20.40.11.00 2008.04.15 Trojan.Spy.Win32.Ardamax.e
Sophos 4.28.0 2008.04.15 Ardamax Installer
Sunbelt 3.0.1041.0 2008.04.12 -
Symantec 10 2008.04.15 -
TheHacker 6.2.92.278 2008.04.15 -
VBA32 3.12.6.4 2008.04.14 Trojan-Dropper.Win32.Agent.bjm
VirusBuster 4.3.26:9 2008.04.15 TrojanSpy.Ardamax.Q
Webwasher-Gateway 6.6.2 2008.04.15 Riskware.Ardamax.K.Gen

OMG! I think it isnt safe...
04/15/2008 20:18 Falkes#9
2. YaRFOB.rar (Yet another RF Online Bot)

- a premium bot shared

Antivírus Versão Última Atualização Resultado
AhnLab-V3 2008.4.15.1 2008.04.15 -
AntiVir 7.6.0.85 2008.04.15 SPR/Ardamax.K.Gen
Authentium 4.93.8 2008.04.14 W32/Trojan.AXGS
Avast 4.8.1169.0 2008.04.15 Win32:Agent-LWO
AVG 7.5.0.516 2008.04.15 Dropper.Agent.DYZ
BitDefender 7.2 2008.04.15 Backdoor.Hupigon.EMK
CAT-QuickHeal 9.50 2008.04.14 -
ClamAV 0.92.1 2008.04.15 Trojan.Spy.Ardamax-25
DrWeb 4.44.0.09170 2008.04.15 -
eSafe 7.0.15.0 2008.04.09 -
eTrust-Vet 31.3.5700 2008.04.15 -
Ewido 4.0 2008.04.15 Dropper.Agent.bit
F-Prot 4.4.2.54 2008.04.15 W32/Trojan.AXGS
F-Secure 6.70.13260.0 2008.04.15 Trojan-Spy.Win32.Ardamax.e
FileAdvisor 1 2008.04.15 -
Fortinet 3.14.0.0 2008.04.15 Adware/Ardamax
Ikarus T3.1.1.26 2008.04.15 Trojan-Dropper.Win32.Agent.bjm
Kaspersky 7.0.0.125 2008.04.15 Trojan-Spy.Win32.Ardamax.e
McAfee 5274 2008.04.15 Keylog-Ardamax.dr.gen
Microsoft 1.3408 2008.04.14 TrojanSpy:Win32/Ardamax.C
NOD32v2 3028 2008.04.15 -
Norman 5.80.02 2008.04.15 -
Panda 9.0.0.4 2008.04.14 Application/Ardamax
Prevx1 V2 2008.04.15 Heuristic: Suspicious Self Modifying File
Rising 20.40.11.00 2008.04.15 Trojan.Spy.Win32.Ardamax.e
Sophos 4.28.0 2008.04.15 Ardamax Installer
Sunbelt 3.0.1041.0 2008.04.12 -
TheHacker 6.2.92.278 2008.04.15 -
VBA32 3.12.6.4 2008.04.14 Trojan-Dropper.Win32.Agent.bjm
VirusBuster 4.3.26:9 2008.04.15 TrojanSpy.Ardamax.Q
Webwasher-Gateway 6.6.2 2008.04.15 Riskware.Ardamax.K.Gen



Lol
???
04/16/2008 23:52 squidol#10
bump
04/17/2008 04:04 trail1#11
Quote:
Originally Posted by squidol View Post
bump
youre bumping your thread even there's complaint on it being a malicious file? you didnt even try to explain your side. >.>
04/17/2008 07:18 TopOne#12
who ever dl this with that scan must be stupid :p

peace out :cool:
04/17/2008 12:55 joibilog#13
dont DL this.. promise.. ull thank me.. especially the patcher..
04/17/2008 12:56 joibilog#14
the patcher shouldnt be that large.. 400kb? the working patcher is only 125kb..
04/18/2008 02:48 squidol#15
bump