![]() |
(Not a bash thread) h4x0r trainers dropping dll's
1 Attachment(s)
Yep a few dll's are dropped by his trainers and no doubt loaded via regsvr32. And some other crap.
They are.. h4x0r.dll scs.dll scx.dll Along with game.jpeg (probably the box art) chip.dll in windows\system32 ((would have said this is for chip tune playback, but does his trainers have tunes?)). Along with Pvt.tmp in the same folder. a sicheats.dll on your desktop. Also in the same folder as the trainer is running from, it creates a skins folder also. So do avoid this crap, not only is he stealing from trainer makers, he is also potentially malware'ing your system (not sure but there has been reports, he could be looking for ways of getting CH accounts or something). It is also reported that the injected h4x0r.dll is causing problems with other trainers from editing memory locations, thusly making them not work (not tried this myself and dont want to) Psych was nice enough to create a good old DOS batch file, to be run from root of your system drive, mostly being C:\ |
I can also vouch for these mysterious dll files being left behind after using one of h4x0r's trainers that I downloaded from this site. Not only are they left behind, they are marked as hidden system files on the root of C:\. I always trusted software I download from GCW, but not any more.
|
popsoda this is nothing to do with GCW. Its h4x0r's doing.
|
I understand that but they willingly host his files even after numerous people have complained about them over the last 6 months or more. Obviously he's taken that for granted and is now using GCW to spread his password stealing malware through his trainers. Not sure how many more strikes this guy is allowed before he's 'out'.
|
Dunno lets hope not for long :)
But lets not go into bashing h4x0r time, lets hope this helps people :) |
I could care less about the whole h4x0r vs Ch thing, but I don't appreciate the malware.
|
Quote:
HAHAHAHAHAHA!, another sucker CH friend here, LIE!, ARE EQUALLY TO ALL THAT SHIT COME AGAINST ME great JUDAS are you DABhand, go to CH to cry GOGOGOGO, malware? XDD please no edit my trainers a hex editor, loser and thanks, another user reported to EMPIRE, FALSE ACUSATIONS. and chip.dll¿?¿?¿?, pleae man, install an antivirus in your pc and format xD PD: I suppose you FREE access to CH to help bury my reputation not it, though that is something you will not get:), people know what kind shit you are, YES OR YES? ;) |
Easy enough for any staff to check your trainers.
And if you learned to read English you will see this wasnt a bashing attempt. And you will also see I didnt say IT IS malware, so get it right, maybe one of your bum chums in your forums can tell you in spanish what is said. And as for trainer making, I make you look like a sunday school picnic lad. You have no skill what so ever. So dont even sit there and act big. Your trainers drop .dll's and no this was not started by CH it was found out by others, so your little stupid CH comment has gone right out the window. Sure report me to Empire, I bet I know who is going to trust more between us 2. Effin loser. |
Quote:
Quote:
Quote:
Whetever.. Lock? |
Can anyone please tell me which specific trainers are leaving/creating dll's anywhere on disk
I tried a few and could not find any of the files anywhere... And reports that the h4x0r.dll is causing problems which you did not see for yourself is a bit useless info as we can do nothing with it... And calling it potential malware is again ridiculous without actual proof that it is malware. Any application in existence could be potential malware when run... Without giving actual examples it is just bashing h4x0r, can't call it anything else! Can you?! I am not saying that he is doing nothing wrong, it could be an error on his part or it could be doing this on purpose. But without proof that he is doing this on purpose it is plain useless information! If anyone is spreading malware to gain access to private information than they are treated accordingly! So it the end none is being "helped" with this info or are they really?! It is quite the opposite... So I am not defending anyone, just proof your case before attacking anyone, as you can already see that ignorant users pick this up as GCW is doing this and I really do not like this kind of stupid/useless thinking. It will only result in a complete ban here of this subject in any way! |
Wow, never thought I would live to see the day where Empire is actually defending the actions of h4x0r. I guess those kickback rumors were true after all. Man, that's a true shame.
|
BTW, I have submitted all of these .dll files to over 20 antivirus companies for further analysis and inclusion in their new signature updates. Hopefully they can help to eradicate this crap.
It was pretty sneaky slipping malware into trainer files since most sites (including this one) tell people that trainers are safe and to disable their AV to let them run. |
Empire, I was only relaying information.
I said Potentially that doesnt mean IT IS. Same with the h4x0r.dll I said it was reported by a number of people, I didnt try, because I dont want to use his trainers on principle. So I shouldnt tell people to be careful? You are encouraging people to be less careful and just carry on? If his new trainers aren't dropping the dll's anymore, there is a chance he has redone them so they dont. Since his trainers were caught doing so. At NO TIME should they be dropping dll's and hidden at that on the root of the system drive, what purpose does that have? Thats suspicious in itself. Proof it does drop dll's, popsoda just said it did, if you check the net on other places they said it did. Ergo it does. Anyways, I can see im wasting my time. I shouldn't have bothered to warn people about the guy trying to get people to visit a link that would infect them either.. Since I didnt try it, perhaps its false yes? hmmm |
Here is a pic Psych posted lately, I thought it was Psych's desktop but it turns out to be someone elses. So another piece of proof it drops dll's.
http://img18.imageshack.us/img18/3074/screen2vn.jpg And check the date, back in december last year so this has been going on for a while. |
Just to clarify, this was only intended as a clean-up utility to use if people wish, and not as a bash against h4x0r. Hell, there are other trainer makers who drop .dll's (although for specific hack purposes and only the one). Perhaps I could include it to scan for them too. Bottom-line, I don't care, nor do I need the crap :)
|
@ Dabhand: Your post does NOT suggest that you are relying this "info" thus makes this even more untrustful...
As for suggesting it could possibly be malware, be very careful doing this as even idiots like this popsoda guy thinks it is... who the f*ck is this guy, if he says one more thing here he is gone But think of it, if h4x0r wanted to spread malware why have EVERTHING pointing at yourself (filename, file details, etc), it is plain ridiculous even thinking this If I look logical at this I think he made a mistake creating them on disk instead of memory (or wherever he wanted them to be created), I can not think of anything else right now If you really wanted to know why his dll are appearing in the C: root why not just ask him plain and simple without attacking/bashing him, you know what kind of answer you will get back if you do... obviously |
This thread was just a heads up nothing more, no point in bashing h4x0r cause he hasn't a clue either way.
Here is the thing... Even if I asked what does it do, do you trust his word 100%? He already lied about stealing options from not just CH but others too. So sorry if I dont take his word. And then if his dll was to help with trainer running, why drop 4 or more at a time. And why the need to +h them. And why in the root directory of the system drive. I never said they were malicious, I have heard from others and from Psych's initial post that others had problems. He posted a clean up batch file, and I did the same here. And as for your logical look, > disk instead of memory, that would be a good chance of being correct if all dll's didnt go into specific directorys. One on the desktop, upto 3 on the root, and 1 in the system32 folder. For me thats not a mistake that was set deliberately to drop them there. Again I didnt accuse of him of malware attempts etc, I said potentially and was giving a heads up to people who use his trainers. Maybe they can go ask, and if they did they would probably get banned anyway on his forum, except for the bum chums who would worship and kiss his ass even if he stole money from them (not saying he does, was an example). I dont have to run his trainers to see the info collected from different sources is not a coincidence or a mistake in compiling his trainers. |
Oh, my god, people! Take a step back and look at yourself: like stupid users reporting Q: "your software doesn't work"; A: "okay but what do you mean?"; Q: "I mean it doesn't work"; A: "can you give a specific example?"; Q: "I already told you it doesn't work" etc. ad infinitum.
Anyone give one example for this supposed malware-ridden trainer (or other software) by h4x0r? (Hint: Give us a working URL on GCW.) Until then, this is just bashing. (A screen capture taken for a proof? Ridiculous.) This thread is left open for the only reason that, perhaps, some useful information will arrive, after a dozen useless posts. |
My God.. I said its POTENTIALLY malware as reported by others.
I didnt say I think its malware, although it is suspicious. English, its great when you know it. As for the pic it was to sure it does drop the dll's. It wasnt to prove it was Malware, so stop twisting words Joe. Actually read what is being said. Which sadly nobody seems to have the fortitude to do in this thread. |
people who run his trainers are also reporting on our site that these files are left in place. more troubling is that several of our trainers do not work when some of these files are left in place. i did not reverse them nor did i mess with them too much as i have no idea what kind of crap these trainers are dropping or where they are dropping it.
1) i can confirm that our bioshock trainer (and several other ones) does not function any more (keys dont work) if his files are present/located. once removed and rebooted the trainer functions again. 2) i am not going to 'post files or proof or screenshots' or anything because i been there and done that and nothing gets done so why waste my time- 3) thank you dabhand and psych for making this tool for removing that crap from people's harddrives. i realize you have ties here and this causes friction for you. at least you are trying to help people- best, Cal |
Yet another suspicion that may be right but I cannot check it (in Sandboxie) as I don't have the necessary files. Care to send me (one of) your trainer(s) in an E-mail attachment, along with a URL to (one of) h4x0r's trainer(s)?
By the way, a lot of trainers/cracks/patches/keygens unpack bassmod.dll and other similar ones to the Windows system directory and leave it there, too. It annoys me but most people don't mind; it's not malware, though... [...] As for comparing reports about malware with reports about code ripping, you can't be serious. Do you understand the difference between the difficulty of proving this one and that one? |
Thought id chime in with my point of view. The last screenshot was of my machine. I started having problems with CH trainers not properly working when ME2 came out. The trainer would auth and activate yet my numkeys failed. I thought it was just a failure on my part with win 7, my firewall/AV combo. Then Bioshock 2 came out and, i had the same problem, with a completely different trainer. After going through the whole common sense checks of keyboard check, numlock check i posted in CH's forums. PW assisted me and suggested i post a file list of my C drive.
I made a few screenshots, but the final one i had to unhide system files and discovered the h4x0r dll. I deleted the file and my CH trainers immediately began working again without a reboot. My firewall never sent out a warning of data being sent one way or the other, but im not sure what the dll itself does. It does seem to interfere with CH trainers functions however. Thanks to this thread i also found the scs.dll and deleted that one. I do not understand why this h4x0r person coded a trainer that needed to drop multiple dlls onto my drive. I checked h4x0r site out at the end of december thinking it would be an alternative. Due to this dll issue, Ill never return to it. |
Quote:
Quote:
Quote:
|
Quote:
over and over this guy lies to you, and he actually HAS lied to you and i have never once told you anything that wasn't untrue. you even now bad-mouth long-time helpers of GCW like dabhand who has helped countless users (and mods) here. maybe there will be a place soon people can post thier game modification work and download game modification files safely. a place that moderates this stuff away and rebukes people like hax0r. now i don't want to escalate this nor get caught up in this and get 'banned' for my reporting a LEGITIMATE finding. i didn't come in here first, nor did i ask anyone to report this stuff. the fact that there is a tool that had to be created to remove these files SHOULD bring you pause, but it doesn't- |
Quote:
Quote:
Quote:
I know that you two know each other and, therefore, are obviously on the same side but I can't bother: this still won't make me partial either towards or against you. Also, if you had read my objective reasons, you would know exactly why I don't like him. However, there have been several cases in the last few years when he should've been banned - most importantly accusations against other forum members that turned out to be unjustified - and I've actually been partial towards him by letting him get away as he's undoubtedly such a useful member of this forum. See a counter-example, senseman, who was caught warezing and whose ban was requested by several persons until I gave up trying to help him and did ban him, after all. See, I have nothing to hide... Quote:
|
Banned for what? Im not moderating anything, but you think I am, I am just following the rules and pointing out people who misuse/break them to help the forum be clear of it.
Im not the one who leaves people who are obviously breaking them for days and nothing is done. I was someone who sat and made sure people didnt click on links by posting about them, so no users would end up being infected etc. Your the one with the problem Joe not me, and has been since your "Hungarian law" post. Just because I did not agree with what you said, and I debated back, I have noticed that attitude towards me since then. Then this thread, AT NO TIME did I say his dll's were spreading malware, I said POTENTIAL.. need a dictionary definition for that? And offered a batch file made by Psych to help remove them. Better safe than sorry. But no I must have been attacking h4x0r, no benefit of the doubt. What a joke. I left once, I shouldnt have come back, I obviously wasted my time here. Bring back the good old mods, ones who do follow the rules set and act accordingly. And ones who dont just delete posts because of the hell of it. And dont deny it some of the posts you deleted from me were nothing bad. So you can go ahead and let empire delete my account, enjoy your time with h4x0r and people like him, cause its obvious that FF/GCW has become quantity over quality these days, and of course the old code has been thrown out the window when it comes to rippers/thieves. Here is a reason to ban me... YOU ARE A FUCKTARD JOE. |
Incase that didnt make a difference.
JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD JOE IS A FUCKTARD |
oh look it fit nicely too.
|
Quote:
Quote:
Quote:
Quote:
And I still haven't banned you although many times it were only TippeX and Empire who made me refrain from doing so... Quote:
I ask you, too: what are you trying to achieve? I'm sure you know - or, at least, think to know - the answer but I don't. Do judges in your country sentence someone guilty based on indirect proofs only, even contributed by their friends? You people lack the objectivity which I'm not surprised at at all. Quote:
Quote:
Quote:
Quote:
Quote:
Quote:
Quote:
[...] But don't overdo it: such an "argument" is also bad for your image. |
Okay, I think everyone had their say. Thread closed; report specific cases in the GameCopyWorld forum.
|
Thread cleaned up from all the off-topic crap.
We're currently investigating a specific pair of h4x0r's and CheatHappens' trainers, both sent to us by Caliber, at the moment. Check out this thread in a few days for the results. Until then, everyone who has a C:\h4x0r.dll file, please, zip it up and send it to me in an E-mail attachment and tell me which h4x0r trainer you found it in (don't attach it, gimme the URL on www.sicheats.com where it can be downloaded instead). |
| All times are GMT -7. The time now is 00:22. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
FileForums @ https://fileforums.com