Results 1 to 8 of 8
  1. #1
    OncePhoenix's Avatar
    Join Date
    Sep 2013
    Gender
    male
    Posts
    790
    Reputation
    121
    Thanks
    285
    My Mood
    Angelic

    Found this interesting

    Just thought I'd throw this out there.
    More than likely a false positive as the file modifies your host and "Disguises???" as a different file (Skype using port 80).






    still, to prevent anything could always just buy from a certain somebody and not be a pirating scumbag

  2. #2
    R1S3's Avatar
    Join Date
    Jan 2016
    Gender
    male
    Location
    █▄█▄█▄█▄█▄█▄█
    Posts
    123
    Reputation
    10
    Thanks
    58
    My Mood
    Devilish
    I tried saying this before, it's SCELLOW, he knows his shit gets released on mpgh, THE SITE THAT BANNED HIM, so obviously (hes the type of person to do this) hell pull some shit like this and infect his own programs so when they get released on mpgh we all get fucked. The orape v3 client released here last time had a negative in the virus scan and I said the same exact thing about how he probably did it on purpose.
    Anyways, nothing we can do about it, its on his site, obviously itll get disapproved if released on here, 1) because its ruining krazyshanks program and 2) bc of this exact screenshot.

    Just buy it from krazyshank, risk this one, or idk, I scanned it myself and I got 0 negatives, dont know what you did there to get 30 negatives..

  3. #3
    JustAnoobROTMG's Avatar
    Join Date
    Aug 2012
    Gender
    male
    Posts
    1,916
    Reputation
    185
    Thanks
    18,230
    Lmao, bullshit .

    If you carefully look at the results, it says "Confuser".
    ConfuserEX is the .net protector used by kronks HIMSELF to protect Kronkboxer.

    The scan above shows that Kronkboxer inside the archive was detected as "Protected with Confuser/Ex", not "virus".
    This protector is also WIDELY used by malware authors and AV cant really analyse it so they just tag the file as BAD.
    Basically you are saying krazyshank gives viruses

    Also :

    * The crack HAS to modify the host file to bypass Kronkboxer auth. Ever heard about "Server check?"
    Virus does this for BAD purposes, but this is legit this time. You can modify the host to block ads too, and its not "virus".

    * The crack source code is easily readable and not crypted or obfuscated , therefore i am waiting for anyone to prove there is malware code in it

    * I coded it, i 've already said that on this forum. And yeah, i am known for infecting everyone with trapped clients /s...


    TLDR : FALSE POSITIVE AS LONG AS YOU GET IT FROM THE *CENSORED* WEBSITE
    (other people can spread real virus ofc)

    If only you knew how to actually READ THE README

    inb4 this thread/post vanishes
    Last edited by JustAnoobROTMG; 01-26-2016 at 01:49 PM.
    Due to a recent DMCA takedown attempt we had to remove Faintmako brain. Please do not paid attention to what he say or do.


  4. The Following User Says Thank You to JustAnoobROTMG For This Useful Post:

    superhazza (01-26-2016)

  5. #4
    OncePhoenix's Avatar
    Join Date
    Sep 2013
    Gender
    male
    Posts
    790
    Reputation
    121
    Thanks
    285
    My Mood
    Angelic
    inb4 you read my post again and feel like an idiot for typing all that

  6. The Following User Says Thank You to OncePhoenix For This Useful Post:

    Plus22 (01-27-2016)

  7. #5
    lkdjnfoskjednfblksjdfn's Avatar
    Join Date
    Apr 2014
    Gender
    male
    Location
    127.0.0.1
    Posts
    1,340
    Reputation
    198
    Thanks
    841
    My Mood
    Inspired
    Quote Originally Posted by JustAnoobROTMG View Post
    Lmao, bullshit .

    If you carefully look at the results, it says "Confuser".
    ConfuserEX is the .net protector used by kronks HIMSELF to protect Kronkboxer.

    The scan above shows that Kronkboxer inside the archive was detected as "Protected with Confuser/Ex", not "virus".
    This protector is also WIDELY used by malware authors and AV cant really analyse it so they just tag the file as BAD.
    Basically you are saying krazyshank gives viruses

    Also :

    * The crack HAS to modify the host file to bypass Kronkboxer auth. Ever heard about "Server check?"
    Virus does this for BAD purposes, but this is legit this time. You can modify the host to block ads too, and its not "virus".

    * The crack source code is easily readable and not crypted or obfuscated , therefore i am waiting for anyone to prove there is malware code in it

    * I coded it, i 've already said that on this forum. And yeah, i am known for infecting everyone with trapped clients /s...


    TLDR : FALSE POSITIVE AS LONG AS YOU GET IT FROM THE *CENSORED* WEBSITE
    (other people can spread real virus ofc)

    If only you knew how to actually READ THE README

    inb4 this thread/post vanishes
    i spy with my little eye 2 "confuse" one, but the other 28 nuh uh, gtfo.

  8. #6
    SlickEashy's Avatar
    Join Date
    Jul 2014
    Gender
    male
    Location
    Under the Ocean
    Posts
    213
    Reputation
    21
    Thanks
    521
    My Mood
    Relaxed
    I looked into this. If you unrar it the only file that shows up with viruses on virustotal is kronkboxer.exe. I also scanned kmasutra.exe and it came up with nothing. If you compare the results of the kronkboxer.exe in the rar and the legit kronkboxer.exe, you will see they both show up with different viruses. This is probably because the cracked one has an older version packed with it or Scellow is trying to pull something.

    If they did something, it is more than likely in kronkboxer.exe. A place where you wouldn't suspect it.

    Also, I know nothing about malware and reverse engineering but this is what I was able to find and you can even do these tests yourself.
    Last edited by SlickEashy; 01-26-2016 at 09:43 PM.

  9. #7
            (╭ರ_•)          
    Premium Member
    ~V~'s Avatar
    Join Date
    May 2014
    Gender
    male
    Location
    Posts
    628
    Reputation
    29
    Thanks
    1,478
    Kemu.exe and Kmasutra.exe itself are clean files i checked code as well but on the other hand kronkboxer.bin and kronkboxer.exe are both packed so i can't say anything for this files

    Here are virus scans:

    Kemu.exe : https://www.virustotal.com/en/file/b0fc3afe7c9333d7a9a85e630e5a3ff964393ae3a0e391944c 0e4d8b3190f82d/analysis/1453930942/
    Kmasutra.exe : https://www.virustotal.com/en/file/8fd7a58dc03362cdc4fb120bcbc7600fe971bb38eb9966ffa9 1a349c2cbd8b32/analysis/1453931001/
    KronkBoxer.bin(exe) : https://www.virustotal.com/en/file/74f3d84cbec17eb68df347386c6d01088c04e528a9768b7c31 e4717caededd68/analysis/1453931017/
    KronkBoxer.exe : https://www.virustotal.com/en/file/8838cf81ad4d0db39961a87bde05ab3b6db495b2c2b7234c41 4f7de0c3f78a87/analysis/1453931047/
    Last edited by ~V~; 01-27-2016 at 02:58 PM. Reason: typo

  10. #8
    gldrk's Avatar
    Join Date
    Oct 2015
    Gender
    male
    Posts
    18
    Reputation
    10
    Thanks
    0
    My Mood
    Angelic
    Going to try and see if it works with the default KronkBoxer you get from the normal website.

Similar Threads

  1. I found this hat list...
    By invaliddownloader in forum Combat Arms Discussions
    Replies: 6
    Last Post: 09-01-2009, 06:50 PM
  2. I searched and found this tutorial...
    By Dillonz in forum C++/C Programming
    Replies: 4
    Last Post: 08-31-2009, 05:18 PM
  3. hey i found this funny
    By gunslinger55 in forum General
    Replies: 17
    Last Post: 04-05-2009, 03:21 PM
  4. I found this vid
    By password911 in forum General
    Replies: 5
    Last Post: 10-15-2008, 06:37 PM
  5. Lol found this :D
    By Hababam in forum General
    Replies: 15
    Last Post: 08-29-2008, 09:51 AM