A quick warning!

05/12/2018 00:52 DerMoench14#1
Time to spread out a warning to you guys.
There are Bots here around in this forum which obviously contain malicious Code.

eg this thread here:[Only registered and activated users can see links. Click Here To Register...]

The .rar archive contains a compiled .exe and the source-code.
If you take a look at line 316 in CommonFunction.au3 you see this:
Code:
Func Setting1()
   Run("KurzickFarmingBot.exe" ,"","workingdir")
EndFunc   ;==>Runx86VersionIfNeed
This Function will be called in Line 14 in KurzickFarmingBot.au3.
I didn't decompile the KurzickFarmingBot.exe because im pretty sure there IS Malware inside!

So just be careful when you download anything here ... take a deeper look in ANY included file before you gona start such shit.

Take care!
05/14/2018 18:42 liyetong#2
Thank you, thank you very much for your remind.
06/08/2018 23:50 ThR1LL#3
What else should we be looking for in the code that's considered malicious?
06/17/2018 17:13 phat34#4
I search for words like server and tcp before I execute unknown code... You can do a search for .exe ... I also scan the code briefly and change passwords often as a failsafe. Also search for an IP looking address as well '000.000.000.000' AND compare the Assembly part of the gwa2 or bible (the red part on 'Scite'). Virus Check! Don run any .exe files.