Friendly warning.

Home Page › Forums › General Chat › Friendly warning.

Viewing 4 posts - 16 through 19 (of 19 total)
  • Author
    Posts
  • #2070236
    eelgoo
    Moderator
    Rank: Rank 7

    The last line there.....

    That is so true in many things.

    🙂

    #2070281
    ulysses
    Participant
    Rank: Rank 3

    Top@z products almost all have viruses imbedded from gcpeers. I just get those off of TPB, which seems to do a better job of deleting infected torrents. ad0be products also often are infected. Why people just don't go directly to m0nkus to get his rips of ad0be I'll never know. Instead, 1000+ people will d/l his cracks from gcpeers torrents that end up having a virus injected. cgp is still one of the best places to get k1tbash3d kits. Haven't seen a virus in those yet.

    #2070393
    sandeep
    Participant
    Rank: Rank-2

    Generally speaking, there are two types of vendors in piracy. The ones that actually develop the cracks and the the ones that distribute them to the public. The ones that actually develop the crack sell them via private channels/forums to the "repackers". It is these repackers that add viruses and other malicious code to steal information from naive end users. Most pirated software that you encounter easily on the public internet are from these repackers. Rule of thumb: there is always a cost of hosting and bandwidth for distributing software freely. If you are unsure how the filehost is recovering those costs then it is highly likely that the software contains malware.

    #2070394
    sandeep
    Participant
    Rank: Rank-2

    The repackers would then strongly advocate that any virus warnings are mere false positives, even sometimes going into details about how the crack needs to access memory and other running processes to generate keys or otherwise. I usually check the "behavior" section of the crack exe or dll in virustotal and compare those behaviors with the original exes. If there is any suspicious file/registry access or access to remote host that should not be happening, then its a red flag. For example, some of the earlier crack of m0nkrus used an exe to add hosts information in the etc/hosts file to prevent automatic license validation. Genuine concerns, but sloppy and suspicious implementations triggering virus warnings, when the same could have been achieved through direct means.

Viewing 4 posts - 16 through 19 (of 19 total)
  • You must be logged in to reply to this topic.

 

Post You Might Like