The repackers would then strongly advocate that any virus warnings are mere false positives, even sometimes going into details about how the crack needs to access memory and other running processes to generate keys or otherwise. I usually check the "behavior" section of the crack exe or dll in virustotal and compare those behaviors with the original exes. If there is any suspicious file/registry access or access to remote host that should not be happening, then its a red flag. For example, some of the earlier crack of m0nkrus used an exe to add hosts information in the etc/hosts file to prevent automatic license validation. Genuine concerns, but sloppy and suspicious implementations triggering virus warnings, when the same could have been achieved through direct means.