Page 1 of 5 123 ... LastLast
Results 1 to 15 of 69
  1. #1
    master131's Avatar
    Join Date
    Apr 2010
    Gender
    male
    Location
    Melbourne, Australia
    Posts
    8,858
    Reputation
    3438
    Thanks
    101,674
    My Mood
    Breezy

    *SteamStealer Trojan* CSGO Simple External ESP

    The aforementioned thread, "CSGO Simple External ESP v1.0 By Synconan" was approved but appeared to be actually malicious. It is estimated that over 800 users downloaded and potentially ran the file without realising they may have been infected with a SteamStealer trojan.

    The trojan was hidden under many layers of code making it hard to detect. It operates by decrypting these layers and then injecting the trojan into the original "CSGO ESP.exe" process.

    The trojan operates by scanning Steam.exe for your Steam ID and initiating a hidden trade by trading items belonging to the following game IDs:
    - 730 (Counter-Strike: Global Offensive)
    - 570 (Dota 2, looks for items with these tags: common, uncommon, rare, mythical, legendary, immortal, arcana)
    - 440 (Team Fortress 2)

    It sends the items to the following Steam ID: 76561198136701777. Resolving this ID produces the following Steam profile page:
    https://steamcommunity.com/id/synconan/

    His IP's are 58.173.1.145 and 82.8.41.117 for anyone that wants revenge.

    The process does appear to be "persistent" meaning that works to ensure that it keeps running no matter what you do. It does this by continuing to restart the process whenever one is closed and sets a registry key on startup called "Multimedia Class Scheduler". It is found at the following location:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\Run\M ultimedia Class Scheduler

    Once solution suggested by @UnfairestB to combat the persistent nature of the trojan is the following:
    Code:
    Once the 'atiesrx.exe' pops up:
    -Start task manager.
    -Find "atiesrx.exe" in the list and right click it > Properties > Security tab > Edit... > Deny everything, on all accounts in the list above (if possible).
    -Now apply your changes and press Ok.
    -Go back to your task manager and right click "atiesrx.exe" once again > End process tree.
    -Once the process is terminated it should not come back.
    After the process is successfully killed along with "CSGO ESP.exe", delete the startup entry from the registry.

    On behalf of MPGH Staff, I would like to apologise for what has occurred despite not being directly involved the the situation and will try my best to help those affected. I have not personally run the file myself but this is what I could gather purely from static analysis.
    Last edited by Color; 10-28-2014 at 04:25 PM.
    Donate:
    BTC: 1GEny3y5tsYfw8E8A45upK6PKVAEcUDNv9


    Handy Tools/Hacks:
    Extreme Injector v3.7.3
    A powerful and advanced injector in a simple GUI.
    Can scramble DLLs on injection making them harder to detect and even make detected hacks work again!

    Minion Since: 13th January 2011
    Moderator Since: 6th May 2011
    Global Moderator Since: 29th April 2012
    Super User/Unknown Since: 23rd July 2013
    'Game Hacking' Team Since: 30th July 2013

    --My Art--
    [Roxas - Pixel Art, WIP]
    [Natsu - Drawn]
    [Natsu - Coloured]


    All drawings are coloured using Photoshop.

    --Gifts--
    [Kyle]

  2. The Following 23 Users Say Thank You to master131 For This Useful Post:

    Angelix (10-29-2014),Cataclypse (10-28-2014),Ceelker (11-20-2014),Color (10-28-2014),eLemonator (10-30-2014),Fidz (11-13-2014),[MPGH]Flengo (10-28-2014),[MPGH]Jim Morrison (10-30-2014),joeramone (11-03-2014),KaKeBoKsEn (12-05-2014),Kieeeeeran (10-28-2014),LEGiiTxCHAOTiiC (12-08-2014),[MPGH]Liz (10-28-2014),[MPGH]Mayion (10-28-2014),mmaaxx129 (10-31-2014),Quiet (11-30-2014),Sky_____ (11-11-2014),Surpia (12-10-2014),Symmetrical (10-28-2014),TheDigitalReach (11-08-2014),TheFlyingDutchman' (10-31-2014),UnfairestB (10-28-2014),unholy1096 (10-28-2014)

  3. #2
    Airule's Avatar
    Join Date
    Oct 2014
    Gender
    female
    Posts
    2
    Reputation
    10
    Thanks
    0
    Thank you!

  4. #3
    Color's Avatar
    Join Date
    Aug 2012
    Gender
    male
    Posts
    19,896
    Reputation
    2588
    Thanks
    7,864
    My Mood
    Lurking
    I would also like to apologize on my behalf for approving the file, apparently I had not taken a look at the file at the best of my abilities. I sincerely am sorry and I hope that you all may forgive me one day.
    //Stickied

    I will leave the thread open to all of those who need questions answered by Master131 or other members.
    Last edited by Color; 10-28-2014 at 04:22 PM.

    Member Since 8/05/2012
    Editor 4/04/13 - 4/21/13
    Middleman 7/14/13 - 11/4/13

    Battlefield Minion 6/13/14-3/20/15
    Steam Minion 7/16/14-3/20/15

    Minion+ 10/1/14-3/20/15
    M.A.T. Minion 10/19/14-3/20/15
    ROTMG Minion 1/14/15-3/20/15

    Donator Since 2/26/15 (Thanks @Cursed!)
    Steam Minion 5/9/15 - 11/5/15
    OSFPS Minion 9/15/15 - 11/5/15


  5. The Following 12 Users Say Thank You to Color For This Useful Post:

    CanaAdrianE (10-28-2014),Cataclypse (11-01-2014),eLemonator (10-30-2014),jusikapide (12-15-2014),[MPGH]Mayion (10-28-2014),Raple (10-28-2014),Sky_____ (11-11-2014),Trollaux (10-28-2014),Tsuchiro (10-28-2014),UnfairestB (10-28-2014),unholy1096 (10-28-2014),xzilum (11-01-2014)

  6. #4
    Doctor Fetus's Avatar
    Join Date
    Sep 2014
    Gender
    male
    Posts
    12
    Reputation
    10
    Thanks
    2
    My Mood
    Bored
    Quote Originally Posted by Color View Post
    I would also like to apologize on my behalf for approving the file, apparently I had not taken a look at the file at the best of my abilities. I sincerely am sorry and I hope that you all may forgive me one day. As for me this will be my last moderation as minion since I can't forgive myself for approving a file that's infected so many people.

    //Stickied

    I will leave the thread open to all of those who need questions answered by Master131 or other members.
    obviesly no one could stay mad at the one who aproves liek most of the files. i wish u could forgive urself

  7. #5
    Doctor Fetus's Avatar
    Join Date
    Sep 2014
    Gender
    male
    Posts
    12
    Reputation
    10
    Thanks
    2
    My Mood
    Bored
    btw how can i fix this cuz i downloaded it a while ago

  8. #6
    unholy1096's Avatar
    Join Date
    Nov 2011
    Gender
    male
    Location
    My basement
    Posts
    251
    Reputation
    29
    Thanks
    1,008
    My Mood
    Yeehaw
    Quote Originally Posted by Color View Post
    I would also like to apologize on my behalf for approving the file, apparently I had not taken a look at the file at the best of my abilities. I sincerely am sorry and I hope that you all may forgive me one day. As for me this will be my last moderation as minion since I can't forgive myself for approving a file that's infected so many people.
    Color, you're only human.. You really can't blame yourself for something like this. Shit happens sometimes and ultimatley we can't stay stuck in the past and think of "What if I did this instead" but instead think of what YOU can do in the future to prevent something like this happening again.

  9. The Following User Says Thank You to unholy1096 For This Useful Post:

    cameorn (12-10-2014)

  10. #7
    Kieeeeeran's Avatar
    Join Date
    Jul 2014
    Gender
    male
    Posts
    10
    Reputation
    10
    Thanks
    0
    Thank you, kind sir. This was really a lot of help !

  11. #8
    Polygon's Avatar
    Join Date
    Apr 2011
    Gender
    male
    Location
    CS:GO/CS:S
    Posts
    1,706
    Reputation
    202
    Thanks
    796
    My Mood
    Bored
    Isn't this the second time that this has happend?

  12. #9
    Bayley_LOL's Avatar
    Join Date
    Jun 2014
    Gender
    female
    Location
    Trollaux's Leeching Grounds
    Posts
    527
    Reputation
    74
    Thanks
    1,437
    My Mood
    Bored
    Quote Originally Posted by Polygon View Post
    Isn't this the second time that this has happend?
    Yes, this has happened before.

  13. #10
    Quentlor's Avatar
    Join Date
    Jun 2014
    Gender
    male
    Location
    'murica
    Posts
    216
    Reputation
    10
    Thanks
    163
    My Mood
    Lurking
    Since turb0z "left" every hack released thus far was either fake or complete shit. Anyways, @Color, dont blame yourself, everyone makes mistakes.
    Over the night of the 1st May we lost one of the most important websites ever created. Godspeed Grooveshark
    .


  14. #11
    Bayley_LOL's Avatar
    Join Date
    Jun 2014
    Gender
    female
    Location
    Trollaux's Leeching Grounds
    Posts
    527
    Reputation
    74
    Thanks
    1,437
    My Mood
    Bored
    Quote Originally Posted by Quentlor View Post
    Since turb0z "left" every hack released thus far was either fake or complete shit. Anyways, @Color, dont blame yourself, everyone makes mistakes.
    Thanks mate, appreciate it.

    In other words, fuck you.

  15. The Following 2 Users Say Thank You to Bayley_LOL For This Useful Post:

    Legithackslol (10-29-2014),wizdee (11-23-2014)

  16. #12
    Quentlor's Avatar
    Join Date
    Jun 2014
    Gender
    male
    Location
    'murica
    Posts
    216
    Reputation
    10
    Thanks
    163
    My Mood
    Lurking
    Quote Originally Posted by Bayley_LOL View Post
    Thanks mate, appreciate it.

    In other words, fuck you.
    You are welcome!
    Last edited by Quentlor; 10-28-2014 at 04:48 AM.
    Over the night of the 1st May we lost one of the most important websites ever created. Godspeed Grooveshark
    .


  17. #13
    232's Avatar
    Join Date
    Oct 2009
    Gender
    male
    Location
    England
    Posts
    34
    Reputation
    10
    Thanks
    4
    Quote Originally Posted by Color View Post
    I would also like to apologize on my behalf for approving the file, apparently I had not taken a look at the file at the best of my abilities. I sincerely am sorry and I hope that you all may forgive me one day. As for me this will be my last moderation as minion since I can't forgive myself for approving a file that's infected so many people.

    //Stickied

    I will leave the thread open to all of those who need questions answered by Master131 or other members.
    I don't think you should leave over such thing, it's just, I think we'd prefer you'd download and run the hack through Sandboxie and see whether these hacks are legit. I know it's effort, which is why I do it myself when I download hacks, just in case it decides to run some other bullshit on my PC. Also, you should make a sticky which shows a guide which shows a user how to block the program from editing anything in the SYSTEM. Regarding the hack, I disabled the access the hack had on my PC, which minimalised what the hack could do. Disabled the 'rights' the program had to SYSTEM

  18. #14
    Glugnie's Avatar
    Join Date
    Oct 2014
    Gender
    male
    Posts
    0
    Reputation
    10
    Thanks
    0
    Sooo... Should I change my password?

  19. #15
    exsunny's Avatar
    Join Date
    Jun 2010
    Gender
    male
    Posts
    12
    Reputation
    10
    Thanks
    3
    ehmm... ive a process called atiersxx.exe so with 2 x`s, is this the same or not ?

Page 1 of 5 123 ... LastLast

Similar Threads

  1. [Release] Oldschool External Esp for Call of Duty 4 (V1.7 Compitable)
    By Archangel in forum Call of Duty 4 - Modern Warfare (MW) Hacks
    Replies: 240
    Last Post: 01-12-2011, 07:50 PM
  2. [Release] Sumol+Kn4ck3r's External ESP v2 ( For XP Users =)
    By Melodia in forum Call of Duty Modern Warfare 2 Private Servers
    Replies: 45
    Last Post: 08-02-2010, 01:06 AM
  3. [SOLVED] External Esp source code editing question
    By Demented420 in forum Call of Duty Modern Warfare 2 Help
    Replies: 6
    Last Post: 06-04-2010, 11:13 AM
  4. [Detected] Undetected External ESP+Radar+Bot V4.1 - Build 1.0.184
    By Archangel in forum Call of Duty 6 - Modern Warfare 2 (MW2) Hacks
    Replies: 167
    Last Post: 04-24-2010, 09:02 AM
  5. External ESP won't work?
    By loban911 in forum Call of Duty Modern Warfare 2 Help
    Replies: 5
    Last Post: 04-06-2010, 10:35 PM