PDA

View Full Version : Spore 1.01 crack by Battery contains malware


SporeVirus
21-09-2008, 15:23
It’s a self extracting (wrapped) EXE file which contains the proper cracked exe by battery, but also contains a keylogger dll.exe (runs from local settings/temp), an isntaller for some other trojan Setup_ver1.1779.2.exe (installs to c:\) and autorun.exe and autorun.inf. (installs to all drives)
If you run the file, it will unpack the contents to all your drives, install the virus for windows startup and then run the actual sporeapp.exe that is packed with it. So it might appear to actually work given the right circumstances and if spore is installed in its default location on C drive.
It is packed with Nbinder (you can see yourself if you use reshacker to open the file.
What I did was run the file on virtual PC and recovered the proper cracked exe from the packager, and rolled-back the VPC
The cracked exe is actually around 34Mb

Joe Forster/STA
21-09-2008, 16:27
I can confirm the extraction of dl.exe into the TEMP directory but nothing else. Also, NOD32 doesn't (3-day old database) complain about either the main executable or this dl.exe. Because of its size, Jotti's online virus scanner refused to scan it, but VirusTotal's results (http://www.virustotal.com/analisis/a69dfe6e0f60b5fe3f3c8f60d7ab15fc) show it's some kind of malware. Stay away from it.

porno reekan
21-09-2008, 16:45
Kaspersky 7 detects that ish easily. Thanks God i always check every downloaded executable with both nod32 and KAV7.
Damn! I guess i have to say good bye to nod after this ish.

NoX1911
22-09-2008, 14:42
Can you try to recover the original exe? The new exe from 19.Sep (Spore Creature v1.01 (v1.1.0.358) by Reloaded) doesn't work with the official patch 1.01. The exe just hangs when starting the game. Maybe the battery one works better.

Edit:
Forget it. The Reloaded crack works properly. Just had to delete my settings folder in 'documents and settings'.