- Mar 6, 2021
- 5
- 2
I have started the exe directly, without the batch file, and will leave it at that.For whatever it's worth, Malwarebytes didn't seem to have an issue with it, at least not for me.
I have started the exe directly, without the batch file, and will leave it at that.For whatever it's worth, Malwarebytes didn't seem to have an issue with it, at least not for me.
yes and it comes with malware for freeHoly shit, its alive?!
None of what you claim is actually happening, no reg keys modified, no temp files, nothing.DO NOT RUN THIS GAME
UNTIL THE DEVELOPER / OP CAN EXPLAIN THESE DETECTIONS, AND FILE OPERATIONS.
You must be registered to see the links
You must be registered to see the links
Both do the same, both have different anti virus results.
The virus one, injects into C:\Program Files (x86)\Google1608_1329478733\bin\updater.exe
View attachment 3764914
Does this really look like something this forum shouldn't look into?
Do I need to manually reverse engineer this executable to prove the developer (OR ORIGINAL POSTER !! ! ) is doing something fishy.
View attachment 3764915
Related parents, aka shared file hashes. Why is it affiliated with keygens, and random zips???
It establishes connections to multiple external IP addresses. These connections are potentially command-and-control (C2) servers, indicating the malware's attempt to communicate with an external source for instructions or data exfiltration.
Spawns new processes and services, indicating the execution of its payload and attempts to maintain control over the infected system.
It modifies registry entries in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run to ensure it runs every time the system starts.
Changes in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services to manipulate system services, often to disable security-related services or to create new malicious services.
Modifies the key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE, potentially to affect browser behavior and user credential handling.
View attachment 3764941 View attachment 3764942
The malware creates numerous .tmp files in the user's temporary directory (AppData\Local\Temp). These files are likely used as intermediate stages in the malware's execution process.
The malware uses cmd.exe to execute batch files (.bat) located in the temporary directory. These batch files are used to execute the primary malicious payload.
The malware masquerades as the Google updater to blend in with legitimate processes. This is indicated by paths like C:\Program Files (x86)\Google\Update\.
By creating and executing multiple batch files, the malware ensures persistence and continuous execution, making it harder to remove.
Same, i don't find a "Google1608_1329478733" folder anywhereNone of what you claim is actually happening, no reg keys modified, no temp files, nothing.
You're either intentionally misleading people or are just fucking stupid, not sure which. Yes there can be generic trojan warnings for this exe which relates to ntleas much like all previous versions but it's nothing to be concerned about, if you ran this, your PC is fine, don't worry.
Just basic software and virus knowldge i've acquired over this years. The game's files and behavior are far from what malware is. I've had viruses and bad .exe's on my computer, their behavior, although it tries to be stealthy, always in some way will show up.Do you work in IT or cyber security?
Kinda strange, i do use Malwarebytes and it detected nothing even after doing a full scan with rootkit included.I tried to verify it with Malwarebytes and there wasn't anything after first scan. Probably because all the files were already in quarantine, but in a spurt of stupidity, I pulled out the bin.exe file from there and immediately Malwarebytes flagged it as unsafe.
How do you connect these 2 events? It doesn't even make sense, a game cannot make some user access your computer files, Internet or PayPal, like never at all, they would need an specific .exe that injects special stuff in your OS so they can hijack it.I will only speak from my experience and without much computer knowledge. Last year I downloaded this game. Since that time some time passed and my PC stopped being the same. Even in the short period of time they withdrew 140 dollars from my bank account in my country through Paypal without authorizing or checking anything at the bank.
They added and removed my card like it was nothing. As if they knew all my details. In my experience I DO NOT RECOMMEND DOWNLOADING THIS GAME. Everyone is free to do as they please. It's a great game, really. But it's not worth the price xD
Luckily my bank recognized that it was an "attack" on my bank account and refunded me the money.
I am an active user and I try many games on this forum. This is the first time something similar has happened to me. True Facials has something very strange and dangerous in my opinion. Thank you for reading.
Yeah, from the guy that claimed the game is a super-duper malware, but only posted screenshots from Virus Total that simulates what the virus would do, but the actual game files do nothing, not even connect to the Internet, to like 3 users straight up buying the BS and saying they will reinstall Windows now instead of trying to investigate by themselves a bit, another guy claiming Malwarebytes says it's "malicious", but i used it myself and the game is clean, which means they probably had other sort of shit in their system and they blamed the game.the amount of tech illiterate people on this site is scary, there is nothing and never was anything wrong with the game, your opsec is just garbage and someone got into your account. reading this thread is actual torture, shit i've been using linux for 3 years now and i know more about windows than 90% of people here.
View attachment 3766001
A computer get get slow due to corrupt Windows install over time that needs repair, a lot of temporal/cache files that you haven't cleaned, dust, bad bios settings, overheating and so many things. I do believe the suff that happened to you, but you are only trying to blame one thing for it and i really don't know what to say. I checked the game's files behavior and even use Malwarebytes to check the whole game folder itself and it reports nothing.In my experience I couldn't do anything once installed. Maybe change the passwords on your computer and your accounts. But do it from another device. I have not formatted my PC because I have many important jobs... But I say again that installing this game was a before and after. Something really changed for the worse. And I don't care if they believe me or those who know a lot about computers give me shit. I'm just talking about my experience.
Nah i also played 0.5, i uninstalled it due to lack of characters, weird character bend and terrible performance, but it's the same story, non-suspicious behavior. I may re-download it again and do a scan on it too just to stop some stupid claims, but it won't do much since some here are convinced the game hacked their entire computer, so alas.To be clear, you're talking about version .42 and not the new 0.5 that some are complaining.
The previous has been amply discussed before in the thread since they used a system translator because the programer is corean ( if I'm not mistaken).
The "trojan" was a script to run the translator on the .exe that most antivírus flagged as a generic trojan.
This new "situation" might be something of the sort, don't know.
Yeah, that's the stuff i checked for first. I went through his post and followed the same registry keys and Windows folders he posted, checked my Windows services and literally nothing of what he claimed happened.None of what you claim is actually happening, no reg keys modified, no temp files, nothing.
You're either intentionally misleading people or are just fucking stupid, not sure which. Yes there can be generic trojan warnings for this exe which relates to ntleas much like all previous versions but it's nothing to be concerned about, if you ran this, your PC is fine, don't worry.
Right...some people just need to get off PC and buy a console lol I'm running it fineYeah, that's the stuff i checked for first. I went through his post and followed the same registry keys and Windows folders he posted, checked my Windows services and literally nothing of what he claimed happened.
I didn't even have some of the folder he claims the game's malware "generates", my registry keys were as they come, stock, no changes, you can check them on Google too to make sure. Opened the game and used Task Manager and Process Explorer to examine it in detail; zero attemps to connect to the internet, zero new .exe's created and no weird temp files stuff, it's an ordinary exe file.
To say his post is stupid falls short, he simply posted stuff the Virus Total site claims the false positive would do and he posted it as if it was real, without realizing Virus Total themselves can't truly predict or ever know if something is truly a virus or not.
I am still waiting for him to prove to us in a Virtual Machine the bunch of stuff he claims the game generates.
it's nothing, if you're running windows security and downloading anything online, chances are there will be some type of "own risk" warning lol always create a recovery point before downloading anything, including windows updates. rollback if your having issues; and if you're allowing web data settings or clouds to remember your passwords and not securing then yourself, well you've pretty much gave them the ok lolimagine risking every info, passwords for some cheap ass game...
"hey guys this game has trojan BUTT if you idiot download it anyway" (f95 team note from homepage)
You risk everything the moment you connect to the internet. Welcome to the future, son.imagine risking every info, passwords for some cheap ass game...
"hey guys this game has trojan BUTT if you idiot download it anyway" (f95 team note from homepage)