Please delete if not allowed...
So I found a cracked version of win ols 4.7 floating around on the webs...
It uses the standard E VC installer, but then uses a cracked (chinese) version of the .exe file to run it.
Virus Total shows some stuff with the .exe (gee can't imagine that):https://www.virustotal.com/gui/file/845 ... d/behavior
It is beyond my capability to dissect the .EXE and possibly the one .DLL file to remove said garbage, so I thought i'd ask if any of you gents could take a go at it.
If so, i'm more than happy to share the file on here...
Removing Malwate/ Virus from Cracked .EXE
-
- Posts: 533
- Joined: Fri Mar 04, 2016 10:35 am
- cars: R33 GTST, '60 Vw Bug, Express (4G63T), GW X200
- Location: Windellama, NSW
- Contact:
Re: Removing Malwate/ Virus from Cracked .EXE
It's a whole lot less effort just to set up a VM and run it in there. Pass through whatever hardware you need but keep that chinese crap isolated. It's the same with the chinese K-tag and pretty much anything from there. They may be false positives but not worth the headache. A lot of that software must be run in Win7 mode or earlier anyway. I use pastebin and other file sharing sites to transfer binaries from the VM back to my main machine.
- antus
- Site Admin
- Posts: 9007
- Joined: Sat Feb 28, 2009 8:34 pm
- cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B - Contact:
Re: Removing Malwate/ Virus from Cracked .EXE
Ill leave this for now because its good general advice for any software, but please support the original companies that make this software. If I change my mind or we receive complaints i'll delete the thread. This forum is a place for free tools and knowledge, not piracy.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
Re: Removing Malwate/ Virus from Cracked .EXE
I could be wrong, but I thought some of the new virus's and such could somehow port through VM Ware?BennVenn wrote: ↑Sun Apr 14, 2024 8:47 am It's a whole lot less effort just to set up a VM and run it in there. Pass through whatever hardware you need but keep that chinese crap isolated. It's the same with the chinese K-tag and pretty much anything from there. They may be false positives but not worth the headache. A lot of that software must be run in Win7 mode or earlier anyway. I use pastebin and other file sharing sites to transfer binaries from the VM back to my main machine.
Re: Removing Malwate/ Virus from Cracked .EXE
Thank you, and I normally do try to support vendors, this is one that I would rarely use right now, when I get to a point where I would use it more I will definitely purchase it.antus wrote: ↑Mon Apr 15, 2024 1:46 pm Ill leave this for now because its good general advice for any software, but please support the original companies that make this software. If I change my mind or we receive complaints i'll delete the thread. This forum is a place for free tools and knowledge, not piracy.
- antus
- Site Admin
- Posts: 9007
- Joined: Sat Feb 28, 2009 8:34 pm
- cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B - Contact:
Re: Removing Malwate/ Virus from Cracked .EXE
You may be thinking of this, stay up to date and you should be OK.
https://arstechnica.com/security/2024/0 ... abilities/
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
-
- Posts: 203
- Joined: Tue Oct 12, 2021 10:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
- Contact:
Re: Removing Malwate/ Virus from Cracked .EXE
Being known that the file is infected, I'd keep the VM off line, setup a folder on the host pc and "share" it to the guest OS, pretty sure it shows up as an external drive, been a while since I've done that. That works in Virtual Box at least on Linux. If the VM can access your network, it can data log and track info, attack other devices on your network, etc so best to not allow that. The other route is to setup a firewall that blocks all traffic except for a white list of allowed ip's.BennVenn wrote: ↑Sun Apr 14, 2024 8:47 am It's a whole lot less effort just to set up a VM and run it in there. Pass through whatever hardware you need but keep that chinese crap isolated. It's the same with the chinese K-tag and pretty much anything from there. They may be false positives but not worth the headache. A lot of that software must be run in Win7 mode or earlier anyway. I use pastebin and other file sharing sites to transfer binaries from the VM back to my main machine.
For the OP, removing viruses and such from an existing exe file might be somewhat easy, or could be very hard depending on how integrated it is. From the little I've looked into that stuff, most use packers/droppers where you open the file, it dumps a section of the orig exe to a location on your drive (encrypted generally), then runs that file which is the actual virus. If you remove the code that drops the virus and the run command line, in theory you can remove the encrypted data out of the file (generally at the end) and have the exe in the original form (cracked but no virus).
Realistically it should never be trusted if it's from a shady source, there's some nasty stuff out there that exists. In theory if you run it in a VM, and inside a sandbox, the sandbox would show you the temp file it creates and such. I used to use Sandboxie long long ago.
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file