Hack Loader Source

Posts 1–15 of 30 · Page 1 of 2
Hack Loader Source

Code:
Imports System.Management
Imports System.Net
Imports System****
Imports System.Text

'CRÉDITOS:'
'- DECODER (DECODER BACK)'
'- Credits to:
'- Basic Loader ;D



Public Class Form1

    Dim appdata As String = "C:\Windows\AppPatch\Custom\raw"
    Private TargetProcessHandle As Integer
    Private pfnStartAddr As Integer
    Private pszLibFileRemote As String
    Private TargetBufferSize As Integer

    Public Const PROCESS_VM_READ = &H10
    Public Const TH32CS_SNAPPROCESS = &H2
    Public Const MEM_COMMIT = 4096
    Public Const PAGE_READWRITE = 4
    Public Const PROCESS_CREATE_THREAD = (&H2)
    Public Const PROCESS_VM_OPERATION = (&H8)
    Public Const PROCESS_VM_WRITE = (&H20)
    Dim DLLFileName As String
    Public Declare Function ReadProcessMemory Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpBaseAddress As Integer, _
    ByVal lpBuffer As String, _
    ByVal nSize As Integer, _
    ByRef lpNumberOfBytesWritten As Integer) As Integer

    Public Declare Function LoadLibrary Lib "kernel32" Alias "LoadLibraryA" ( _
    ByVal lpLibFileName As String) As Integer

    Public Declare Function VirtualAllocEx Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpAddress As Integer, _
    ByVal dwSize As Integer, _
    ByVal flAllocationType As Integer, _
    ByVal flProtect As Integer) As Integer

    Public Declare Function WriteProcessMemory Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpBaseAddress As Integer, _
    ByVal lpBuffer As String, _
    ByVal nSize As Integer, _
    ByRef lpNumberOfBytesWritten As Integer) As Integer

    Public Declare Function GetProcAddress Lib "kernel32" ( _
    ByVal hModule As Integer, ByVal lpProcName As String) As Integer

    Private Declare Function GetModuleHandle Lib "Kernel32" Alias "GetModuleHandleA" ( _
    ByVal lpModuleName As String) As Integer

    Public Declare Function CreateRemoteThread Lib "kernel32" ( _
    ByVal hProcess As Integer, _
    ByVal lpThreadAttributes As Integer, _
    ByVal dwStackSize As Integer, _
    ByVal lpStartAddress As Integer, _
    ByVal lpParameter As Integer, _
    ByVal dwCreationFlags As Integer, _
    ByRef lpThreadId As Integer) As Integer

    Public Declare Function OpenProcess Lib "kernel32" ( _
    ByVal dwDesiredAccess As Integer, _
    ByVal bInheritHandle As Integer, _
    ByVal dwProcessId As Integer) As Integer

    Private Declare Function FindWindow Lib "user32" Alias "FindWindowA" ( _
    ByVal lpClassName As String, _
    ByVal lpWindowName As String) As Integer

    Private Declare Function CloseHandle Lib "kernel32" Alias "CloseHandleA" ( _
    ByVal hObject As Integer) As Integer
    Dim ExeName As String = IO.Path.GetFileNameWithoutExtension(Application.ExecutablePath)


    Private Sub IsURLValid()
        Timer7.Start()


    End Sub

    Private Sub Inject()
        On Error GoTo 1
        Timer1.Stop()
        Dim TargetProcess As Process() = Process.GetProcessesByName("WarRock")
        TargetProcessHandle = OpenProcess(PROCESS_CREATE_THREAD Or PROCESS_VM_OPERATION Or PROCESS_VM_WRITE, False, TargetProcess(0).Id)
        pszLibFileRemote = "C:\Windows\system32\netware.dll"
        pfnStartAddr = GetProcAddress(GetModuleHandle("Kernel32"), "LoadLibraryA")
        TargetBufferSize = 1 + Len(pszLibFileRemote)
        Dim Rtn As Integer
        Dim LoadLibParamAdr As Integer
        LoadLibParamAdr = VirtualAllocEx(TargetProcessHandle, 0, TargetBufferSize, MEM_COMMIT, PAGE_READWRITE)
        Rtn = WriteProcessMemory(TargetProcessHandle, LoadLibParamAdr, pszLibFileRemote, TargetBufferSize, 0)
        CreateRemoteThread(TargetProcessHandle, 0, 0, pfnStartAddr, LoadLibParamAdr, 0, 0)

1:      Me.Close()
    End Sub

    Private Sub Form1_Load(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles MyBase.Load
        Dim web As New WebClient
        Dim reader As String
        reader = web.DownloadString("http://yoursite.com/status.txt")
        If reader = "Online" Then
            BlackButton11.Text = ("Waiting to Inject!...")
            BlackButton21.Text = ("Made by Zero")
            Call IsURLValid()
            Timer3.Start()
            Timer5.Start()
        Else

            BlackButton11.Text = "Server is Offline :("
            BlackButton21.Text = ("Made by Zero")
            Timer4.Start()
            Timer6.Start()

        End If
        Timer9.Start()
        Timer2.Start()
    End Sub

    Private Sub Timer2_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer2.Tick
        Label4.Left -= 5
        If Label4.Left <= -Width Then
            Label4.Left = Width
        End If
        For Each RunningProcess In Process.GetProcessesByName("Fiddler")

            Me.Close()

        Next
        For Each RunningProcess In Process.GetProcessesByName("Charles")
            Me.Close()

        Next
    End Sub
    Private Sub Timer7_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer7.Tick

        If (Not System****.Directory.Exists(appdata)) Then
            System****.Directory.CreateDirectory(appdata)
        End If
        Dim exe As String = "raw.exe"

        Dim extractpath As String = appdata & "\raw.dll"
        Dim extractpath1 As String = appdata & "\raw.exe"
        IO.File.WriteAllBytes(extractpath, My.Resources.WRHOOK)
        IO.File.WriteAllBytes(extractpath1, My.Resources.WRHOOK1)
        Timer8.Start()
        Timer7.Stop()
    End Sub
    Private Sub Timer8_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer8.Tick
        Dim exe As String = "raw.exe"
        Dim CA As Process() = Process.GetProcessesByName("WarRock")

        If CA.Length <> 0 Then
            'folder and exe refer to the global variables in the region "Global Variables"
            If IO.File.Exists(appdata & "\" & exe) Then
                'opens the injector.
                Shell(appdata & "\" & exe)
                Timer8.Stop()
                BlackButton11.Text = ("Inject Successfully!!!")
            End If
        End If
    End Sub
    Private Sub FutureButton2_Click(ByVal sender As System.Object, ByVal e As System.EventArgs)
        Dim SAPI
        SAPI = CreateObject("sapi.spvoice")
        SAPI.volume = 100
        SAPI.Speak("Minimize")
        Me.WindowState = FormWindowState.Minimized
    End Sub

    Private Sub FutureButton1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs)
        Dim SAPI
        SAPI = CreateObject("sapi.spvoice")
        SAPI.volume = 100
        SAPI.Speak("Close")
        Application.Exit()
    End Sub

    Private Sub Timer5_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer5.Tick
        Label3.ForeColor = Color.Green
        Label3.ForeColor = Color.Red
    End Sub

    Private Sub Timer3_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer3.Tick
        Label3.ForeColor = Color.Red
        If Label3.ForeColor = Color.Red Then
            Label3.ForeColor = Color.Green
        ElseIf Label3.ForeColor = Color.Green Then
            Label3.ForeColor = Color.Red
        End If
    End Sub

    Private Sub Timer1_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer1.Tick
        Label2.Left -= 5
        If Label2.Left <= -Width Then
            Label2.Left = Width
        End If
    End Sub
End Class

VS - https://www.virustotal.com/file/5e3d...is/1345691642/ⓘ
VS - Zero Hack Loader.rar - Jotti's malware scanⓘ
Zero Hack Loader_mpgh.net.rar277 KB · 488 downloads Scanning…
hope this will be approve immediately
So, another?

Also deleted the non english posts, this is an english forum, so speak english.
There's nothing in bin folder -_-
Quote Originally Posted by moekasper View Post
There's nothing in bin folder -_-
Its the solution of the project, not an .exe
Looks Nice ^^
Like it
Lmao @ those trojans.
Quote Originally Posted by BluntGod_ View Post
Lmao @ those trojans.
The .rar doesnt even have a .exe file on it, so it really doesnt matter. Its not even the same .rar even. Topic was moved here already approved. But code files doesnt really matter.
Quote Originally Posted by 'Bruno View Post


The .rar doesnt even have a .exe file on it, so it really doesnt matter. Its not even the same .rar even. Topic was moved here already approved. But code files doesnt really matter.
whoa , I wasn't saying it actually had trojans. I was laughing at the false positives.
Quote Originally Posted by BluntGod_ View Post
whoa , I wasn't saying it actually had trojans. I was laughing at the false positives.
Yea, he probabily scanned it before deleting the .exe like I said.
Pretty good tutorial. Thanks bro..
Posts 1–15 of 30 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?