Removing Malwate/ Virus from Cracked .EXE

Disassembly, Reassembly, Tools and devleopment. Going deep with Hardware and Software.
Post Reply
mytunes
Posts: 10
Joined: Fri Aug 26, 2022 10:44 am

Removing Malwate/ Virus from Cracked .EXE

Post by mytunes »

Please delete if not allowed...

So I found a cracked version of win ols 4.7 floating around on the webs...

It uses the standard E VC installer, but then uses a cracked (chinese) version of the .exe file to run it.

Virus Total shows some stuff with the .exe (gee can't imagine that):https://www.virustotal.com/gui/file/845 ... d/behavior

It is beyond my capability to dissect the .EXE and possibly the one .DLL file to remove said garbage, so I thought i'd ask if any of you gents could take a go at it.

If so, i'm more than happy to share the file on here...
BennVenn
Posts: 487
Joined: Fri Mar 04, 2016 10:35 am
cars: R33 GTST, '60 Vw Bug, Express (4G63T), GW X200
Location: Windellama, NSW
Contact:

Re: Removing Malwate/ Virus from Cracked .EXE

Post by BennVenn »

It's a whole lot less effort just to set up a VM and run it in there. Pass through whatever hardware you need but keep that chinese crap isolated. It's the same with the chinese K-tag and pretty much anything from there. They may be false positives but not worth the headache. A lot of that software must be run in Win7 mode or earlier anyway. I use pastebin and other file sharing sites to transfer binaries from the VM back to my main machine.
User avatar
antus
Site Admin
Posts: 8253
Joined: Sat Feb 28, 2009 8:34 pm
cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Contact:

Re: Removing Malwate/ Virus from Cracked .EXE

Post by antus »

Ill leave this for now because its good general advice for any software, but please support the original companies that make this software. If I change my mind or we receive complaints i'll delete the thread. This forum is a place for free tools and knowledge, not piracy.
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
mytunes
Posts: 10
Joined: Fri Aug 26, 2022 10:44 am

Re: Removing Malwate/ Virus from Cracked .EXE

Post by mytunes »

BennVenn wrote: Sun Apr 14, 2024 8:47 am It's a whole lot less effort just to set up a VM and run it in there. Pass through whatever hardware you need but keep that chinese crap isolated. It's the same with the chinese K-tag and pretty much anything from there. They may be false positives but not worth the headache. A lot of that software must be run in Win7 mode or earlier anyway. I use pastebin and other file sharing sites to transfer binaries from the VM back to my main machine.
I could be wrong, but I thought some of the new virus's and such could somehow port through VM Ware?
mytunes
Posts: 10
Joined: Fri Aug 26, 2022 10:44 am

Re: Removing Malwate/ Virus from Cracked .EXE

Post by mytunes »

antus wrote: Mon Apr 15, 2024 1:46 pm Ill leave this for now because its good general advice for any software, but please support the original companies that make this software. If I change my mind or we receive complaints i'll delete the thread. This forum is a place for free tools and knowledge, not piracy.
Thank you, and I normally do try to support vendors, this is one that I would rarely use right now, when I get to a point where I would use it more I will definitely purchase it.
User avatar
antus
Site Admin
Posts: 8253
Joined: Sat Feb 28, 2009 8:34 pm
cars: TX Gemini 2L Twincam
TX Gemini SR20 18psi
Datsun 1200 Ute
Subaru Blitzen '06 EZ30 4th gen, 3.0R Spec B
Contact:

Re: Removing Malwate/ Virus from Cracked .EXE

Post by antus »

mytunes wrote: Mon Apr 15, 2024 11:02 pm I could be wrong, but I thought some of the new virus's and such could somehow port through VM Ware?
You may be thinking of this, stay up to date and you should be OK.

https://arstechnica.com/security/2024/0 ... abilities/
Have you read the FAQ? For lots of information and links to significant threads see here: http://pcmhacking.net/forums/viewtopic.php?f=7&t=1396
Post Reply