PDA

View Full Version : msn-priv.exe [Leaked League PROOF!], fully working on XP/Vista 32 & 64 bit.



quin123
27th August 2009, 16:59
here is the recoded version help by Mops & btan1zer

Features ///

similar to the vent. exe bot although no blatant anti recoil/nospread etc.

it was sold for 150 euro by mops but leaked

aimbot
silent aimbot
radarhack
bunnyhop

Proofings ///
CMN3
ESEA [only for the moment]
ESL
XRAY
VAC2
ECO [?? NO CONFIRM]

adadadasdad




Note: Use at your own risk! Once again its a cheat! *GOT THIS FROM A FRIEND WHO CONFIRMED*

ghett0recoil
27th August 2009, 17:45
I dont trust you :o


// edit:

__________________________________________________ _______________
msn-priv.exe : Not detected by Sandbox (Signature: NO_VIRUS)


[ DetectionInfo ]
* Filename: C:\analyzer\scan\msn-priv.exe.
* Sandbox name: NO_MALWARE
* Signature name: NO_VIRUS.
* Compressed: NO.
* TLS hooks: NO.
* Executable type: Application.
* Executable file structure: OK.
* Filetype: PE_I386.

[ General information ]
* Anti debug/emulation code present.
* **Locates window "The Wireshark Network Analyzer [class NULL]" on desktop.
* **Locates window "Process Monitor - Sysinternals: www.sysinternals.com [class NULL]" on desktop.
* **Locates window "File Monitor - Sysinternals: www.sysinternals.com [class NULL]" on desktop.
* **Locates window "Registry Monitor - Sysinternals: www.sysinternals.com [class NULL]" on desktop.
* File length: 226816 bytes.
* MD5 hash: 1eb9421ce79a902754a759a7e91286ed.
* Entry-point detection: Microsoft Visual C++.

[ Process/window information ]
* Creates a window with name "NULL".

__________________________________________________ _______________

Why would you locate Process Monitor's window, etc...

CampStaff
28th August 2009, 00:23
Hmm.. lets see.


Connections

* Server: http://2g00d.blackapplehost.com
* Service: INTERNET_SERVICE_FTP
* Successful: 0
* Api-Function: InternetConnectA


# Store Created Files Section...

* Source: C:\Documents and Settings\Jim\Local Settings\Temp\msn.exe (45568 Bytes.)
* Destination: b4b3a691c549d8ab2de16d13d433a442.exe

* Source: C:\Documents and Settings\Jim\Local Settings\Temp\u16event.dat (248 Bytes.)
* Destination: 9543eebb06ce76c048a0243635e47dc9.dat

1 0.000000 192.168.0.2 192.168.0.1 DNS Standard query A http://2g00d.blackapplehost.com
2 0.157425 192.168.0.1 192.168.0.2 DNS Standard query response A 69.162.86.4
7 1.844233 192.168.0.2 69.162.86.4 FTP Request: USER 2g00d
9 2.011633 69.162.86.4 192.168.0.2 FTP Response: 331 User 2g00d OK. Password required
10 2.027957 192.168.0.2 69.162.86.4 FTP Request: PASS 321buttsex
11 2.467162 69.162.86.4 192.168.0.2 FTP Response: 230-User 2g00d has group access to: vhosts
12 2.502027 192.168.0.2 69.162.86.4 FTP Request: CWD /
13 2.659240 69.162.86.4 192.168.0.2 FTP Response: 250 OK. Current directory is /
22 3.907159 69.162.86.4 192.168.0.2 FTP Response: 150 Accepted data connection



250 OK. Current directory is /
PASV
227 Entering Passive Mode (69,162,86,4,127,64)
RETR index.html
150-Accepted data connection
150 6.6 kbytes to download
226-File successfully transferred
226 0.000 seconds (measured here), 213.62 Mbytes per second
DELE index.html
NOOP
NOOP
NOOP
250-3 Kbytes used (0%) - authorized: 5120000 Kb
250 Deleted index.html
DELE WOLF_270809_0940.html
200 Zzz...
200 Zzz...
200 Zzz...
250-2 Kbytes used (0%) - authorized: 5120000 Kb
250 Deleted WOLF_270809_0940.html
DELE UOSL08-D418241B_270809_1219.html
250-1 Kbytes used (0%) - authorized: 5120000 Kb
250 Deleted UOSL08-D418241B_270809_1219.html
DELE YOUR-02AE785C02_270809_1550.html
250-0 Kbytes used (0%) - authorized: 5120000 Kb
250 Deleted YOUR-02AE785C02_270809_1550.html
DELE 278C64C72130478_270809_1325.html
250-0 Kbytes used (0%) - authorized: 5120000 Kb
250 Deleted 278C64C72130478_270809_1325.html
DELE PAL44_270809_1642.html
250-0 Kbytes used (0%) - authorized: 5120000 Kb
250 Deleted PAL44_270809_1642.html
DELE pc8_020709_1421.html
250-0 Kbytes used (0%) - authorized: 5120000 Kb
250 Deleted pc8_020709_1421.html
TYPE A
200 TYPE is now ASCII
PASV
227 Entering Passive Mode (69,162,86,4,173,27)
MLSD
150 Accepted data connection
226-Options: -l

albator
28th August 2009, 01:01
So there is a worm is this sheat ?

I active it on my brotha's computer...:x

charlie
28th August 2009, 20:28
So there is a worm is this sheat ?

I active it on my brotha's computer...:x
time to rebuild it then

albator
28th August 2009, 21:24
Sorry I don't understand.

You mean I must re-install my brother's computer ? It's not ****ed up. I just launch this shitty .exe and nothing happen. There is no steam on this computer but this .exe may have steal passwords (internet forums...).

CampStaff delete FTP's infos. So mybrother's passwords may have been deleted ?

charlie
28th August 2009, 22:51
just reinstall the operating system, and it maybe next time you wont run random exe files

albator
29th August 2009, 12:45
Reinstall windows ? :disappointed:

Ok thank you ;)

But I thought a member with 500 messages won't post bullshits...