WARNING SA-MP - stealing/keyloggers - mainly to CLEO users

SobFoX

Expert
Joined
Jul 14, 2015
Messages
1,390
Solutions
4
Reaction score
893
Location
Israel
I recently discovered that computers infected with SAMP's DIALOG "thief" in ASI, CS, SF, LUA
Doing something else besides stealing users...

It turns out that they create an additional process for you on the computer that they load in several methods through FONTS files of weapons and more in the game.
Then they connect you to the botnet server. The connection type appears to be UDP
And then do whatever they want on your computer, mostly it seems they use it to use their computer as a zombie computer for personal purposes

Search your computer if you find one of these files I would recommend a full format and don't save anything related to this game at all.
As it seems there are thousands who have been infected and are also infecting without knowing at all.

access.exe,samp_connect.exe,basmp3.asi,samp.dat,bs.asi,gtaweap4.saa
 

SobFoX

Expert
Joined
Jul 14, 2015
Messages
1,390
Solutions
4
Reaction score
893
Location
Israel
I recommend it even if you found and deleted it, and even if you didn't take into account that it's for you to clean if you have detailed things on the computer.
Because they can stick any file they want on your computer with the help of PE, and then the files like chrome.exe will continue to look "legitimate"
 
Top