ARWoW 3.0 内部优化版
y7.oy"
y7.oy"
y7.oy" 不知道大家注意到了没有, ARWoW 3.0 内部优化版启动后会多一个东西,
y7.oy" 其实ARWOW只是加了壳的WOWEMU.相关的东西大家可以去
www.WOWEMU.CN去了解。
y7.oy" 网络本来就是拿来主义,这没什么但。
y7.oy" 但是不要害人啊,不知道大家注意到了没有。本来是8080.3274.8085这三个端口的
y7.oy" 却被ARK改成了8848.3274.8085这三个端口,8848这个端口稍微懂点电脑的人都知道这是什么端口了!
y7.oy" 上面我说 分享 ARWoW UT 共享版启动后会多一个东西,
y7.oy" 多了什么呢?MOUNT.exe大家可以到进程里看到!
y7.oy" 这个是什么东西我也不知道,但是我知道不启动这个也一样能玩。
y7.oy" ===========================================================
y7.oy" 8848,是个远程控制端口
y7.oy" 黑客一般是用这个端口入侵他人计算机的!以下是该版本原始数据运行结果:
y7.oy"
y7.oy" 赏屯屯屯屯屯屯屯屯屯屯屯屯?Loader by ST3V0 ?
y7.oy" 荷屯屯屯屯屯屯屯屯屯屯屯屯屯屯屯屯屯屯屯屯突?
y7.oy" 汉 ..:: OldOne & ST3V0 Lab Engine ::.. 汉
y7.oy" 汉 presents 汉
y7.oy" 汉 WoWEmu 4878.0.1 Rebild 汉
y7.oy" 汉 START DARK PROJECT 汉
y7.oy" 喝屯屯屯屯屯屯屯屯蚚2.0.0]屯屯屯屯屯屯屯屯图?
y7.oy" 韧屯屯屯屯 Greetings to all Members 屯屯屯屯?
y7.oy"
y7.oy" :: ST3V0 DLL Memory Loader...START
y7.oy" :: Inject DLLs...
y7.oy" :: Start Needed Programs...
y7.oy" :: Start EXE SetTitle.exe...OK
y7.oy" :: ST3V0 DLL Memory Loader...OK
y7.oy" :: WoWEmu WE_DK-Core...OK
y7.oy" + Set Console Title...
y7.oy" + Set Console Title...OK
y7.oy" OS version 5.1.2600 (Service Pack 2) platform 2
y7.oy" 13:11:01:U:Computer ID: 0AD1024D-AC98
y7.oy" 13:11:01:U: *** WoWEmu v0.4735.1.9 win2k/win2k3/winxp console release
y7.oy" 13:11:01:M:Config file scripts/extra/defines.scp loaded, 0 sections done.
y7.oy" 13:11:01:M:Config file scripts/extra/AR_No_addons.conf loaded, 113 sections done
y7.oy" .
y7.oy" 13:11:01:M:Config file scripts/extra/addons.conf loaded, 297 sections done.
y7.oy" 13:11:01:M:Config file scripts/emu.conf loaded, 301 sections done.
y7.oy" 13:11:01:M:Spells loaded, max=25333
y7.oy" 13:11:01:M:SpellItemEnchantment loaded, total=1432
y7.oy" 13:11:01:M:ItemRandomProperties loaded, total=2011
y7.oy" 13:11:01:M:ItemSet loaded, total=115
y7.oy" 13:11:01:M:WorldSafeLocs loaded, total=120
y7.oy" 13:11:01:M:AreaTable loaded, total=1068
y7.oy" 13:11:01:M:WorldMapArea loaded, total=51
y7.oy" 13:11:01:M:Talents loaded, total=428
y7.oy" 13:11:01:M:Taxinodes loaded, total=77
y7.oy" 13:11:01:M:Taxipathes loaded, total=231
y7.oy" 13:11:01:M:Taxipathnodes loaded, total=8563
y7.oy" 13:11:01:M:EmotesText loaded, total=169
y7.oy" 13:11:01:M:Factions loaded, total=177
y7.oy" 13:11:01:M:FactionTemplates loaded, total=288
y7.oy" 13:11:01:MurabilityCosts loaded, total=100
y7.oy" 13:11:01:Mock loaded, total=194
y7.oy" 13:11:01:M:MapCache inited, 42 maps.
y7.oy" 13:11:01:M:water.dat loaded, 19392 recs.
y7.oy" 13:11:01:M:Config file scripts/classes.scp loaded, 58 sections done.
y7.oy" 13:11:01:M:classes.scp stat tables loaded.
y7.oy" 13:11:01:M:File scripts/extra/items_loot.scp, max 1000000, total 71 sections.
y7.oy" 13:11:01:M:File scripts/extra/items__VFevo.scp, max 1000000, total 304 sections.
y7.oy"
y7.oy" 13:11:01:M:File scripts/extra/items__ARK.scp, max 1000000, total 5 sections.
y7.oy" 13:11:01:M:File scripts/items.scp, max 1000000, total 13152 sections.
y7.oy" 13:11:01:M:Config file scripts/gameobjects.scp loaded, 8590 sections done.
y7.oy" 13:11:01:M:Config file scripts/extra/loot_fishing.scp loaded, 345 sections done.
y7.oy"
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_BWL.scp loaded, 365 s
y7.oy" ections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_DrangonKing.scp loade
y7.oy" d, 373 sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_ZulGurub.scp loaded,
y7.oy" 389 sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_MC.scp loaded, 399 se
y7.oy" ctions done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_anqila.scp loaded, 40
y7.oy" 8 sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates__VFevo.scp loaded, 42
y7.oy" 0 sections done.
y7.oy" 13:11:01:M:Config file scripts/extra/loot_fishing.scp loaded, 4715 sections done
y7.oy" .
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_BWL.scp loaded, 4715
y7.oy" sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_DrangonKing.scp loade
y7.oy" d, 4715 sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_ZulGurub.scp loaded,
y7.oy" 4715 sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_MC.scp loaded, 4715 s
y7.oy" ections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates_anqila.scp loaded, 47
y7.oy" 15 sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates/loottemplates__VFevo.scp loaded, 47
y7.oy" 15 sections done.
y7.oy" 13:11:01:M:Config file scripts/loottemplates.scp loaded, 4715 sections done.
y7.oy" 13:11:01:M:File scripts/extra/creatures__VFevo.scp, max 9999994, total 72 sectio
y7.oy" ns.
y7.oy" 13:11:01:M:File scripts/extra/creatures_Pet.scp, max 9999994, total 6 sections.
y7.oy" 13:11:01:M:File scripts/creatures.scp, max 9999994, total 8360 sections.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost__Skill.scp, max 24279, total 2261 se
y7.oy" ctions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Druid.scp, max 24279, total 376 sect
y7.oy" ions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Hunter.scp, max 24279, total 201 sec
y7.oy" tions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Mage.scp, max 24279, total 317 secti
y7.oy" ons.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Paladin.scp, max 24279, total 310 se
y7.oy" ctions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Priest.scp, max 24279, total 367 sec
y7.oy" tions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Rogue.scp, max 24279, total 221 sect
y7.oy" ions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Shaman.scp, max 24279, total 349 sec
y7.oy" tions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Warlock.scp, max 24279, total 314 se
y7.oy" ctions.
y7.oy" 13:11:01:M:File scripts/spellcost/spellcost_Warrior.scp, max 24279, total 196 se
y7.oy" ctions.
y7.oy" 13:11:01:M:File scripts/spellcost.scp, max 24279, total 22208 sections.
y7.oy" 13:11:01:M:File scripts/areatriggers.scp, max 4013, total 366 sections.
y7.oy" 13:11:01:M:File scripts/quests.scp, max 123004, total 3421 sections.
y7.oy" 13:11:01:M:File scripts/pages.scp, max 2785, total 971 sections.
y7.oy" 13:11:01:M:File scripts/extra/qdbtexts.scp, max 900102, total 4749 sections.
y7.oy" 13:11:01:M:File scripts/npctext.scp, max 900102, total 14350 sections.
y7.oy" Error: Original Commands.tcl loaded too late!
y7.oy" Texts: 1 configuration variable loaded.
y7.oy" Honor: 17 configuration variables loaded.
y7.oy" 13:11:14:M:MasterScript v3.1.0 by smartwork loaded
y7.oy" Race System v0.1.1 by Snake Loaded
y7.oy" Speed: 2 configuration variables loaded.
y7.oy" 13:11:15:M:StatSystem v0.6b by Raverouk loaded
y7.oy" SQLite: Setting SQLite connection...
y7.oy" SQLite: Done
y7.oy" 13:11:01:M:TCL:1.4
y7.oy" 13:11:01:M:Main thread started.
y7.oy" 13:11:01:M:HeapCreate() OK bufhandle=0x04F80000 prochandle=0x00140000
y7.oy" 13:11:01:Moading guilds...
y7.oy" 13:11:01:M:done.
y7.oy" 13:11:01:Moading world...
y7.oy" 13:11:01:M:Rehashing.
y7.oy" 13:11:01:MEBUG: checking account [ARK]
y7.oy" 13:11:01:E:Wrong character [DD000000DD38EAFD] from account [ARK] deleted.
y7.oy" 13:11:01:M:done.
y7.oy" 13:11:01:M:Loading PP...
y7.oy" 13:11:01:M:done, 26276 ppoints.
y7.oy" 13:12:58:M:HS:Socket opened TCP port 8848
y7.oy" 13:12:58:M:RS:Socket opened TCP port 3724
y7.oy" 13:12:58:M:WS:Socket opened TCP port 8085
y7.oy" 13:12:58:M:HS:IO Completion Port initialized, acceptors=4 workers=2
y7.oy" 13:12:58:M:RS:IO Completion Port initialized, acceptors=20 workers=10
y7.oy" 13:12:58:M:WS:IO Completion Port initialized, acceptors=20 workers=10
y7.oy" ===================================================
y7.oy" 注意:13:12:58:M:HS:Socket opened TCP port 8848
y7.oy" 此为打开8848端口 。
y7.oy" 以下是运行了分享 ARWoW UT 共享版后用端口工具在MS-DOS方式下找出来的东西!
y7.oy" Fport的最新版本是2.0。在很多网站都提供下载,但是为了安全起见,当然最好还是到它的老家去下:
http://www.foundstone.com/knowledge/zips/fport.zip 此工具为各个端口究竟是什么程序打开的就都在你眼皮底下了
y7.oy" 最好先查毒,我用的没问题
y7.oy" netstat -a这个命令是系统自带的!
y7.oy" ===============================================================
y7.oy" Microsoft Windows XP [版本 5.1.2600]
y7.oy" (C) 版权所有 1985-2001 Microsoft Corp.
y7.oy"
y7.oy" C:\>netstat -a
y7.oy"
y7.oy" Active Connections
y7.oy"
y7.oy" Proto Local Address Foreign Address State
y7.oy" TCP blue:epmap blue:0 LISTENING
y7.oy" TCP blue:microsoft-ds blue:0 LISTENING
y7.oy" TCP blue:3077 blue:0 LISTENING
y7.oy" TCP blue:3724 blue:0 LISTENING
y7.oy" TCP blue:8085 blue:0 LISTENING
y7.oy" TCP blue:8848 blue:0 LISTENING
y7.oy" TCP blue:1035 blue:0 LISTENING
y7.oy" TCP blue:netbios-ssn blue:0 LISTENING
y7.oy" TCP blue:2380 219.153.42.69:http CLOSE_WAIT
y7.oy" UDP blue:microsoft-ds *:*
y7.oy" UDP blue:isakmp *:*
y7.oy" UDP blue:1025 *:*
y7.oy" UDP blue:1028 *:*
y7.oy" UDP blue:2280 *:*
y7.oy" UDP blue:2373 *:*
y7.oy" UDP blue:2376 *:*
y7.oy" UDP blue:2401 *:*
y7.oy" UDP blue:4000 *:*
y7.oy" UDP blue:4500 *:*
y7.oy" UDP blue:5060 *:*
y7.oy" UDP blue:6000 *:*
y7.oy" UDP blue:ntp *:*
y7.oy" UDP blue:1056 *:*
y7.oy" UDP blue:1158 *:*
y7.oy" UDP blue:1900 *:*
y7.oy" UDP blue:2370 *:*
y7.oy" UDP blue:3500 *:*
y7.oy" UDP blue:8090 *:*
y7.oy" UDP blue:ntp *:*
y7.oy" UDP blue:netbios-ns *:*
y7.oy" UDP blue:netbios-dgm *:*
y7.oy" UDP blue:1900 *:*
y7.oy"
y7.oy" C:\>fporn
y7.oy" 'fporn' 不是内部或外部命令,也不是可运行的程序
y7.oy" 或批处理文件。
y7.oy"
y7.oy" C:\>fport
y7.oy" FPort v2.0 - TCP/IP Process to Port Mapper
y7.oy" Copyright 2000 by Foundstone, Inc.
y7.oy" http://www.foundstone.com
y7.oy"
y7.oy" Pid Process Port Proto Path
y7.oy" 760 svchost -> 135 TCP C:\WINDOWS\system32\svchost.exe
y7.oy" 4 System -> 139 TCP
BZ!v%4^9 4 System -> 445 TCP
BZ!v%4^9 1132 alg -> 1035 TCP C:\WINDOWS\System32\alg.exe
BZ!v%4^9 3764 Thunder -> 2380 TCP C:\Program Files\Thunder Network\Thunder\Th
BZ!v%4^9 under.exe
BZ!v%4^9 1900 IEXPLORE -> 2431 TCP C:\Program Files\Internet Explorer\IEXPLORE
BZ!v%4^9 .EXE
BZ!v%4^9 3764 Thunder -> 3077 TCP C:\Program Files\Thunder Network\Thunder\Th
BZ!v%4^9 under.exe
BZ!v%4^9 1004 WoWEmuOrig -> 3724 TCP E:\3.0内部优化版本\WoWEmuOrig.exe
BZ!v%4^9 1004 WoWEmuOrig -> 8085 TCP E:\3.0内部优化版本\WoWEmuOrig.exe
BZ!v%4^9 1004 WoWEmuOrig -> 8848 TCP E:\3.0内部优化版本\WoWEmuOrig.exe
BZ!v%4^9 0 System -> 123 UDP
BZ!v%4^9 23 -> 137 UDP
BZ!v%4^9 564 lsass -> 138 UDP C:\WINDOWS\system32\lsass.exe
BZ!v%4^9 760 svchost -> 445 UDP C:\WINDOWS\system32\svchost.exe
lPe&h]@ > 4 System -> 500 UDP
lPe&h]@ > 3764 Thunder -> 1025 UDP C:\Program Files\Thunder Network\Thunder\Th
lPe&h]@ > under.exe
lPe&h]@ > 1004 WoWEmuOrig -> 1028 UDP E:\3.0内部优化版本\WoWEmuOrig.exe
lPe&h]@ > 0 System -> 1056 UDP
lPe&h]@ > 0 System -> 1158 UDP
lPe&h]@ > 0 System -> 1900 UDP
lPe&h]@ > 880 svchost -> 1900 UDP C:\WINDOWS\system32\svchost.exe
lPe&h]@ > 1004 WoWEmuOrig -> 2280 UDP E:\3.0内部优化版本\WoWEmuOrig.exe
lPe&h]@ > 0 System -> 2370 UDP
lPe&h]@ > 1004 WoWEmuOrig -> 2373 UDP E:\3.0内部优化版本\WoWEmuOrig.exe
lPe&h]@ > 1132 alg -> 2376 UDP C:\WINDOWS\System32\alg.exe
lPe&h]@ > 4 System -> 2401 UDP
lPe&h]@ > 0 System -> 3500 UDP
lPe&h]@ > 3764 Thunder -> 4000 UDP C:\Program Files\Thunder Network\Thunder\Th
lPe&h]@ > under.exe
lPe&h]@ > 1900 IEXPLORE -> 4500 UDP C:\Program Files\Internet Explorer\IEXPLORE
lPe&h]@ > .EXE
lPe&h]@ > 0 System -> 5060 UDP
lPe&h]@ > 0 System -> 6000 UDP
lPe&h]@ > 0 System -> 8090 UDP
lPe&h]@ > lPe&h]@ > lPe&h]@ > C:\>
lPe&h]@ > ===========================================================
lPe&h]@ > TCP blue:8848 blue:0 LISTENING
lPe&h]@ > 看到了,但是我还是不确定到底是什么程序打开这个端口的呢?
lPe&h]@ > 用
lPe&h]@ > C:\>fport(这里的这个命令是我上面提到的工具,我把他放在C盘了没有文件夹就是在根目录下)
lPe&h]@ > 1004 WoWEmuOrig -> 8848 TCP E:\3.0内部优化版本\WoWEmuOrig.exe