JamCrumpet
Newbie
- Apr 28, 2018
- 52
- 189
How have you linked the two though? What direct evidence do you have?I will only speak from my experience and without much computer knowledge. Last year I downloaded this game. Since that time some time passed and my PC stopped being the same. Even in the short period of time they withdrew 140 dollars from my bank account in my country through Paypal without authorizing or checking anything at the bank.
They added and removed my card like it was nothing. As if they knew all my details. In my experience I DO NOT RECOMMEND DOWNLOADING THIS GAME.
In my experience I couldn't do anything once installed. Maybe change the passwords on your computer and your accounts. But do it from another device. I have not formatted my PC because I have many important jobs... But I say again that installing this game was a before and after. Something really changed for the worse. And I don't care if they believe me or those who know a lot about computers give me shit. I'm just talking about my experience.I run the 0.5 version one time.
I'm doomed?
Which antimalware to use?
Look, you are very right. What happened is when I installed the game my PC alarmed not one but many viruses in quarantine. I was never able to eliminate the alert or apparently the virus. Even every time I do a check on my PC it still shows the same thing. Let me look in my email for the evidence of paypal.How have you linked the two though? What direct evidence do you have?
Otherwise it seems like coincidental superstition, like, "hey I want to the bakers on the same day I got hacked I bet the bakers stole my card info when I paid for my buns!"
The mods always check the files, and the comment specifically calls it a "false positive"
Ive since checked some of the listed folders people mentioned here and... nada, they dont even exist.
Sounds like people are getting viruses from other sources, or just THINKING they have a virus and attributing to a false positive from the game. FYI, I didnt get any warning.
Though I have deleted the game because they removed all the fucking characters.
My main rollar coaster ride is see the battle of either the game is malware or not XD, i am on non malware side thoman, this update was a roller coaster of emotion:
Seeing that it exists at all and Henry is alive:
Seeing the absolutely horrible framerate and briefly wondering if my PC is busted:
Seeing that dickgirls are now an option:
Seeing that almost all the other options, including characters, are gone:
Seeing that it's just a demo, so there's hope:![]()
the amount of tech illiterate people on this site is scary, there is nothing and never was anything wrong with the game, your opsec is just garbage and someone got into your account. reading this thread is actual torture, shit i've been using linux for 3 years now and i know more about windows than 90% of people here.I will only speak from my experience and without much computer knowledge. Last year I downloaded this game. Since that time some time passed and my PC stopped being the same. Even in the short period of time they withdrew 140 dollars from my bank account in my country through Paypal without authorizing or checking anything at the bank.
They added and removed my card like it was nothing. As if they knew all my details. In my experience I DO NOT RECOMMEND DOWNLOADING THIS GAME. Everyone is free to do as they please. It's a great game, really. But it's not worth the price xD
Luckily my bank recognized that it was an "attack" on my bank account and refunded me the money.
I am an active user and I try many games on this forum. This is the first time something similar has happened to me. True Facials has something very strange and dangerous in my opinion. Thank you for reading.
and another Linux user who tells you that he is a Linux user and therefore knows everything better.the amount of tech illiterate people on this site is scary, there is nothing and never was anything wrong with the game, your opsec is just garbage and someone got into your account. reading this thread is actual torture, shit i've been using linux for 3 years now and i know more about windows than 90% of people here.
View attachment 3766001
the amount of tech illiterate people on this site is scary, there is nothing and never was anything wrong with the game, your opsec is just garbage and someone got into your account. reading this thread is actual torture, shit i've been using linux for 3 years now and i know more about windows than 90% of people here.
View attachment 3766001
To be clear, you're talking about version .42 and not the new 0.5 that some are complaining.It was not my intention to put on a drama, I do declare myself ignorant of computers. Chances are there are plenty of people here who know more than me. I am only telling my personal experience and my recommendation from my discretion. Everyone is free to do whatever you want! If someone is doing great and hasn't had a virus alarm go off, please comment here![]()
This admin's quote triggered me.specialist? on a pirate forum? what's next? and if you missed
View attachment 3766127
now either move on or play the game, but please stop posting nonsense
Downloaded via Gofile. (Original link on 22.06.24 before 12:32)DO NOT RUN THIS GAME
UNTIL THE DEVELOPER / OP CAN EXPLAIN THESE DETECTIONS, AND FILE OPERATIONS.
You must be registered to see the links
You must be registered to see the links
Both do the same, both have different anti virus results.
The virus one, injects into C:\Program Files (x86)\Google1608_1329478733\bin\updater.exe
View attachment 3764914
Does this really look like something this forum shouldn't look into?
Do I need to manually reverse engineer this executable to prove the developer (OR ORIGINAL POSTER !! ! ) is doing something fishy.
View attachment 3764915
Related parents, aka shared file hashes. Why is it affiliated with keygens, and random zips???
It establishes connections to multiple external IP addresses. These connections are potentially command-and-control (C2) servers, indicating the malware's attempt to communicate with an external source for instructions or data exfiltration.
Spawns new processes and services, indicating the execution of its payload and attempts to maintain control over the infected system.
It modifies registry entries in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run to ensure it runs every time the system starts.
Changes in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services to manipulate system services, often to disable security-related services or to create new malicious services.
Modifies the key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE, potentially to affect browser behavior and user credential handling.
View attachment 3764941 View attachment 3764942
The malware creates numerous .tmp files in the user's temporary directory (AppData\Local\Temp). These files are likely used as intermediate stages in the malware's execution process.
The malware uses cmd.exe to execute batch files (.bat) located in the temporary directory. These batch files are used to execute the primary malicious payload.
The malware masquerades as the Google updater to blend in with legitimate processes. This is indicated by paths like C:\Program Files (x86)\Google\Update\.
By creating and executing multiple batch files, the malware ensures persistence and continuous execution, making it harder to remove.
I have started the exe directly, without the batch file, and will leave it at that.For whatever it's worth, Malwarebytes didn't seem to have an issue with it, at least not for me.