Exetools  

Go Back   Exetools > General > Community Tools

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-26-2023, 18:43
CodeCracker CodeCracker is offline
VIP
 
Join Date: Jun 2011
Posts: 905
Rept. Given: 68
Rept. Rcvd 660 Times in 278 Posts
Thanks Given: 64
Thanks Rcvd at 3,819 Times in 717 Posts
CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699
https://www.virustotal.com/gui/file/e4f32d000f0d02380aadbf91785650ca8baee1519baf6becc439b7293d7b4f0b

trojan.scarletflash/themida

Alibaba Packed:Win64/Themida.5b4b1a04
ESET-NOD32 A Variant Of Win64/Packed.Themida.L Su

Com'on!
From what I could tell the file is protected by Themida so this is why is flagged.
Reply With Quote
  #2  
Old 10-26-2023, 21:04
vetgrapje vetgrapje is offline
Guest
 
Join Date: Oct 2023
Location: in a house
Posts: 2
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
vetgrapje Reputation: 0
Quote:
Originally Posted by CodeCracker View Post
https://www.virustotal.com/gui/file/e4f32d000f0d02380aadbf91785650ca8baee1519baf6becc439b7293d7b4f0b

trojan.scarletflash/themida

Alibaba Packed:Win64/Themida.5b4b1a04
ESET-NOD32 A Variant Of Win64/Packed.Themida.L Su

Com'on!
From what I could tell the file is protected by Themida so this is why is flagged.
Thank you for your reply and checking out the file, The version I had downloaded before differs from the original version (This topic). I searched if Jasi2169 released a different version of this hook before, this does not seem to be the case so I assume the version I had downloaded before is bundled with something else. I can't think of a good reason to pack a perfectly functioning hook with something other then a virus.

Thanks Jasi2169 I'll have to check out "tsrh team forums", (I'm not finished reading topics on this forum yet, reserve engineering and patching is very interesting to me, I may have found a new hobby )
Reply With Quote
  #3  
Old 10-27-2023, 00:51
Jasi2169's Avatar
Jasi2169 Jasi2169 is offline
Family
 
Join Date: Sep 2015
Location: India/TSRh
Posts: 326
Rept. Given: 3
Rept. Rcvd 74 Times in 50 Posts
Thanks Given: 47
Thanks Rcvd at 526 Times in 204 Posts
Jasi2169 Reputation: 74
Quote:
Originally Posted by CodeCracker View Post
https://www.virustotal.com/gui/file/e4f32d000f0d02380aadbf91785650ca8baee1519baf6becc439b7293d7b4f0b

trojan.scarletflash/themida

Alibaba Packed:Win64/Themida.5b4b1a04
ESET-NOD32 A Variant Of Win64/Packed.Themida.L Su

Com'on!
From what I could tell the file is protected by Themida so this is why is flagged.
Plus leaked themida we all use in scene i guess, i never checked though
Reply With Quote
  #4  
Old 10-27-2023, 08:20
Moe Moe is offline
Banned User
 
Join Date: Sep 2023
Posts: 28
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 2
Thanks Rcvd at 11 Times in 7 Posts
Moe Reputation: 2
Quote:
Originally Posted by Jasi2169 View Post
Plus leaked themida we all use in scene i guess, i never checked though
"We all" ? No... Most crackers do not use such leaked packers since they get blacklisted on most of modern windows systems. You can check if you don't believe me.
Reply With Quote
The Following User Says Thank You to Moe For This Useful Post:
X0rby (11-28-2023)
  #5  
Old 10-27-2023, 10:27
Jasi2169's Avatar
Jasi2169 Jasi2169 is offline
Family
 
Join Date: Sep 2015
Location: India/TSRh
Posts: 326
Rept. Given: 3
Rept. Rcvd 74 Times in 50 Posts
Thanks Given: 47
Thanks Rcvd at 526 Times in 204 Posts
Jasi2169 Reputation: 74
Quote:
Originally Posted by Abdul Moeed View Post
"We all" ? No... Most crackers do not use such leaked packers since they get blacklisted on most of modern windows systems. You can check if you don't believe me.
I dnt know abt ur experience, since last decade i have seen, the releases are packed most of the time, to save its integrity , no one will purchase or use purchased protectors own copies on cracks and stuff.

Some might use open source as well, but once the release is packed most AV companies just mark it as virus false positive without taggent or know publisher tag.

Even mine purchased eazfuscator and it was marked as virus on packed a simple file, just a signature based games
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How can I hook DllMain ? ioannis General Discussion 12 07-29-2015 01:09
Techsmith Morae Manager squareD General Discussion 2 01-08-2010 01:10
SST Hook -> Bluescreen!? Cobi General Discussion 12 05-04-2005 09:37


All times are GMT +8. The time now is 19:29.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )