MALWATE WARNING: (2Moons hack Trainer v3)

08/22/2009 08:37 6Drako9#1
sorry I meant MALWARE

If have read [Only registered and activated users can see links. Click Here To Register...]
then you better hope you haven't played 2Moons after you downloaded the trainer (I didn't ^.^)

michas91 posted the Trainer, however L.e.v.i.a.t.h.a.n (aka \/xWx\/) apparently says he made it
So in my opinion they should both be IP banned.


For those of you how downloaded the trainer...
Here are the malware removal instructions: (made quickly by me after I made sure that the trainer was responsible)
1. Delete the trainer and never run it again... (this is just common sense)
2. Press Ctrl+Alt+Delete to open Task Manager
(if you are using Vista select the last option wich is Task Manager)
3. You will see a proses named gadu-gadu.exe, so highlight it and click Delete on your keyboard to stop it
4. go to C:\Windows\system\svhost, at this moment you can open the pictures to look at those beautiful unknown shots of your computer that the progam has taken. (mine looked [Only registered and activated users can see links. Click Here To Register...])
5. DELETE the shit out of that folder
6. Go to C:\Windows and run a program called regedit.exe
(Careful inside the registry, dont remove anything you are not sure about)
7. Go to Edit\Find... or click Ctrl+F to open the Find window
8. In the Find window write gadu-gadu and click Find Next
(to look for any traces of the progam on your computer
9. You may find a file that says gadu-gadu on the right box of the Registry Editor, so delete it if you do
10. to continue your search go to Edit\Find Next or press F3
11. one thing you will definitely find is a folder named Gadu-Gadu (if you look on the left box on the Registry Editor window)
12. Delete the entire Gadu-Gadu folder when you find it
After everything restart your computer and open the Task Manager again to check if gadu-gadu.exe started up again after the restart
if it still shows up do not play 2Moons and ask for more help

EZasπ (π is supposed to be "pie" but it doesn't come out right with this font -_-)

Good Luck, hopefully you won't need it

Ps. Is a mod able to change the tittle of this thread from MALWATE to MALWARE pls, lol

Edit:
here is a script to make this thread about 2Moons hacking, or just for fun...^.^
Code:
[ENABLE]
alloc(MonsterRange,1024)
label(ReturnMonsterRange)

0053A2F5: //89 54 24 48 8B 01 FF
jmp MonsterRange
nop
ReturnMonsterRange:

MonsterRange:
mov [esp+48],edx
mov [esp+30],00000000
mov [esp+4c],00000000
mov eax,[ecx]
jmp ReturnMonsterRange

[DISABLE]
dealloc(MonsterRange)
0053A2F5:
mov [esp+48],edx
mov eax,[ecx]
08/22/2009 08:40 ~Twister~#2
ummmmmm no offense but
+#1 reported at 21/08/09 GMT -8 cause wrong section.
you should've posted in his thread that he made before since this section is for hacks only. But I guess thank you from thouse who actially downloaded it not knowing it was keylogger :)
08/22/2009 08:41 Vaidas B#3
wow thats worth a thanks drako, leave it here twister, some people have to know, im happy i didint use that shit, and only my CT
08/22/2009 08:45 ~Twister~#4
Quote:
Originally Posted by waidas123 View Post
wow thats worth a thanks drako, leave it here twister, some people have to know, im happy i didint use that shit, and only my CT
Well it deserves a tnx :) But still rules are rules. I didn't dowload anything made by \/xWx\/ since i know his nature :)
eather way it's up to MODs to decide if it should stay here for a while or not, as waidas said we guards are cops with no guns xD
08/22/2009 08:47 Vaidas B#5
me too, i hate that guy, hes a real drama queen
08/22/2009 08:53 6Drako9#6
I know it is the wrong section and I knew it was the wrong section before even writing this thread
but I felt that it had to be done
I don't care if I do get a black mark because I know that even tho it was wrong I had to take one for the team
and it had to be done fast
08/22/2009 08:55 Vaidas B#7
U wont, couse its a useful tut about a 2moons "hack" and the shit in it lol
08/22/2009 08:56 ~Twister~#8
Quote:
Originally Posted by 6Drako9 View Post
I know it is the wrong section and I knew it was the wrong section before even writing this thread
but I felt that it had to be done
I don't care if I do get a black mark because I know that even tho it was wrong I had to take one for the team
you are not gonna get anything since your post is actially helpfull :) I hope it's gonna stay here for a while, i was just doing my job. the worst thing that can happen is the thread is gonna be moved lol :) but still tnx for making that :)
08/22/2009 08:58 6Drako9#9
there I fixed it hahahahah ;)
08/22/2009 08:59 ~Twister~#10
Quote:
Originally Posted by 6Drako9 View Post
there I fixed it hahahahah ;)
lol smartass xD
08/22/2009 14:17 HellSpider#11
Nice findings. Never even downloaded the trainer before but I'm sure a lot of people did. I think the IP ban would be well deserved :).
08/22/2009 14:26 Cr0_Fr3aK#12
Quote:
Originally Posted by InstantDeath View Post
Nice findings. Never even downloaded the trainer before but I'm sure a lot of people did. I think the IP ban would be well deserved :).
Agree.
LoL, but without him this forum would be bored :P.
08/22/2009 14:30 HellSpider#13
Looks like the Malware has been appended to the trainer by Microsoft CAB SFX. I managed to extract the trainer from the SFX. So what I'm saying is that the trainer isn't a malware but there has been a malware appended to the trainer in the form as an runtime SFX archive.
08/22/2009 16:25 vitorjun#14
so this thread [Only registered and activated users can see links. Click Here To Register...] are a KL too ?
08/22/2009 16:35 OmgPwnz#15
Like Instant said, you can actually download it, extract the Trainer inside and keep it, and discard the extra that we don't want. BUT IT IS FOR EXPERIENCED PERSONNEL ONLY!

Just to think i wanted to try out the trainer....:pimp: