ZXBotV2.0 + zoom hack by Se7en.

03/07/2009 10:12 se7en.#1
Instructions:

1. set elementclient.exe to 800x600 resolution

2. open elementclient.exe

3. run ZXBotV2.0BySE7EN.exe, and Config_OffSet.ini will appear

4. configure bot settings

Notes:

*please can bot first at http://www.virustotal.com/

*bot only runs under 32 bit xp

*if the bot fails to run please intstall .NET framework at [Only registered and activated users can see links. Click Here To Register...]

*Bot runs on Tru Tien Online , ZX TH and ZX PH

Updates:

* Screenshot 1
[Only registered and activated users can see links. Click Here To Register...]
* Screenshot 2
[Only registered and activated users can see links. Click Here To Register...]

Virus total results:
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
Red results are falsed positives

Zip password:
Code:
se7en777
03/07/2009 12:45 zarimier#2
so??? who's gona try it first???? any volunteer ^^
03/07/2009 13:02 Nacirema#3
What does this mean?

[Only registered and activated users can see links. Click Here To Register...]
03/07/2009 14:54 se7en.#4
Quote:
Originally Posted by Nacirema View Post
What does this mean?

[Only registered and activated users can see links. Click Here To Register...]
run elementclient.exe first before executing the bot
03/07/2009 15:55 keile#5
Quote:
Originally Posted by se7en. View Post
run elementclient.exe first before executing the bot
Still doesn't work. Same old message.
03/08/2009 01:43 ColdFire_#6
Going to try this on MY-EN (Malaysia English) version later. hope it works
03/08/2009 04:01 harvzliar#7
The message still appears
03/08/2009 04:56 keile#8
Damn you se7en!!!!

GUYS DON'T TRY THIS!!

This contains a keylogger.. the reason that popup opens is that it copies a keylogger on C:\documents and settings\username\Local Settings\Temp\Tmp\sysinlt.exe

He hacked all my gold, my +6 armor, +7 weapon, all my 150+ refining phylacteries, my element pearls, my lv90 future armors and weapons, huh, you left one +3 lv90 armors huh

Are you happy now? Makakarma ka rin.
03/08/2009 05:23 se7en.#9
Quote:
Originally Posted by keile View Post
Damn you se7en!!!!

GUYS DON'T TRY THIS!!

This contains a keylogger.. the reason that popup opens is that it copies a keylogger on C:\documents and settings\username\Local Settings\Temp\Tmp\sysinlt.exe

He hacked all my gold, my +6 armor, +7 weapon, all my 150+ refining phylacteries, my element pearls, my lv90 future armors and weapons, huh, you left one +3 lv90 armors huh

Are you happy now? Makakarma ka rin.
please scan files first before executing, it does not contain any loggers

and the ones detected are false positives
03/08/2009 05:27 se7en.#10
[Only registered and activated users can see links. Click Here To Register...]

If this image still shows after execution please intstall .NET Framework Version 2.0 Redistributable Package (x86). Links can be found on my first post
03/08/2009 06:37 se7en.#11
Update

* Uploaded two screenshots of Zoom hack
03/08/2009 06:49 keile#12
The hack was written most probably using .NET that's why scanners can't see the keylogger.

It uses SetWindowsHookEx to attach to your keyboard and records all your keystrokes.

Gagu ka.
03/08/2009 13:06 se7en.#13
Quote:
Originally Posted by keile View Post
The hack was written most probably using .NET that's why scanners can't see the keylogger.

It uses SetWindowsHookEx to attach to your keyboard and records all your keystrokes.

Gagu ka.
The Microsoft .NET Framework is a software framework that is available with several Microsoft Windows operating systems. The .NET Framework is a key Microsoft offering and is intended to be used by most new applications created for the Windows platform. Therefore, no programs are written using it. It just serves as a prerequisite to run compatible software. On the otherhand SetWindowsHookEx will not be able to execute itself without the required libraries and is not associated with keyboards.
03/08/2009 17:42 tikman#14
Hmmm... Now its hard to tell weather this thing is legit or not because of an accusation BUT

[Only registered and activated users can see links. Click Here To Register...]

File ZhuxianBotV2.0BySE7EN.zip received on 03.08.2009 17:35:09 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 1/38 (2.64%)

Sunbelt 3.2.1858.2 2009.03.08 <Encrypted Archive>

Anyway, need more test and volunteer...
03/08/2009 23:14 str8killa#15
ya its a vrius rofl

[Only registered and activated users can see links. Click Here To Register...]