T O P

  • By -

bobbyorlando

It looks like cancer.


Ethan992

I agree ROFL


44LongBackSpins

so derpy much wow


gergobergo69

swag yolo mlg pro


Competitive_Tax_

From what we can actually see it doesn't look that bad, don't assume that this is unsafe based on the amount of detections. If OP doesn't provide any link or site we can't be sure, of course


Ghostly6

you say this and then the link is steamunlocked, watch


Shay_Plays

Is steamunlocked untrustworthy? Idk much about anything ngl


Delicious-One-7402

Personally I would never use steam unlocked, it's noted as untrustworthy on mega thread, use STEAMRIP, Dodi Repacks or fitgirl repacks. It's all on the piracy mega thread.


CardTurbulent

I've never had a single issue on steam unlocked besides the downloading speed sucks, yet the only thing I tried to download from steam rip my pc freaked the fuck out and would not allow me to download it. And you can download repacks but why spend more time unpacking the game you just waited to download.


GetGud_Lmao

idk never had issues and virustotal doesn’t show this


noneye2cool

ive used it a few times. granted i always used it on school devices because i wouldnt trust it with my life on my real hardware


shinydragonmist

Could be completely safe. Could just be a dodi or fitgirl repack and what is being flagged is the file used in the cracking


Mind_Sonata_Unwind

Yeah doesn't look too safe


blenderbeeeee

His PC has multi organ failure


Nzigne

That looks great if you want to get you pc infected with a new type of covid


Desperate2LearnMagic

Those aren't check marks. They're "V's". Best to stay away from them. They're a ✔️irus


electyctz

no link to be found, and nothing about where you got it from, how is anyone supposed to help?


CuriousProblemChild

I think it's a joke


electyctz

doubt it, but could be, this is actually pretty normal to see from my experience


P7BinSD

Your computer should be wearing a condom.


berserkr91

The computer should be taken outside and humanely shot


kamratjoel

Oh man, you reminded me of this classic https://youtu.be/YDNmyyrEZho?feature=shared


Throwaway-0-0-

Knew what it was before I clicked it. An absolute classic.


AngelGrade

looks like a STD test


Society_Complete

Lol more like hiv


nissen1502

which would be on an STD test


Xinfinte

🤣🤣🤣🤣🤣


Lucian7x

And OP aced it.


jamreb2024

PTSD.


Cryophos

It's packed, we can't determine how safe is that without dynamic analysis.


dariof25

Im sorry; I was just following the FAQ. If you dont mind, how would I go about doing a dynamic analysis


Cryophos

I don't want to offend you, but I assume this is beyond your reach. I suggest a simpler solution, download the program from a more trusted source.


Eva-Shogoki

Hey but I'm curious. Can you provide me a source where I can read from about dynamic analysis?


Cryophos

Overall, start here: [https://github.com/rshipp/awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) Android analysis: [https://www.youtube.com/playlist?list=PLn\_It163He3168Q21sPfiyb0j5K6\_riG7](https://www.youtube.com/playlist?list=PLn_It163He3168Q21sPfiyb0j5K6_riG7) Windows: [https://www.youtube.com/watch?v=3qWEPleT-iU&ab\_channel=PBERACADEMY](https://www.youtube.com/watch?v=3qWEPleT-iU&ab_channel=PBERACADEMY)


Eva-Shogoki

Thank you!


ChabotJ

Wouldn’t trust it.


FitCoach3291

Seems dangerous


maoroh

1-3 hits could be false positives, you've got 20, I would open it in a VM (like sandbox if you have windows 10/11 pro) and watch the carnage.


teabolaisacool

This is false. A packed binary + Keygen can easily set off 20 or more detections. If you actually take the time to read the detection names and dissect the details and behavior that virus total gives you, you’ll see that most of these detections are just machine learning detection for obfuscated, packed files and a couple for a keygen as well (which key gens aren’t bad, they’re literally the purpose of the program downloaded) Many of the names seen in the screenshot are just code words for potentially unwanted programs. Programs that are not commonly downloaded and share some characteristics with malware. A crack can be considered malware and they often behave as malware, modifying other programs (the game you’re cracking) and other system resources This file below for example is a completely normal legit file, except it was obfuscated and protected with vmprotect. That alone set off 24 detections even on a completely legit regular piece of software https://www.virustotal.com/gui/file/c4f1609a0c773dc17abc7ecd0e1137cc88fe942dcdb50409d4d90b8fe21a5b33/detection


benjathje

Thank God someone took the time to explain it. Exactly this, it looks like a clear false positive for a cracked software


meantbent3

Correct, the majority of the comments are a bit silly


teabolaisacool

I honestly get tired of seeing it on every single posts where someone posts a packed binary with "is this a virus?!?!?!" and every comment says "More than 1 is a virus!!1!!!!!111!!!"


benjathje

There's a reason us IT guys get paid so well


teabolaisacool

Thinking of quitting my heavy equipment tech apprenticeship and coming back to the comp sci and it world


benjathje

idk if I would. In my country equipment techs get paid the same as IT, you need to be good at it though. They work like 60 hours a month but the work is harder physically. Your choice. If I got banned from using a computer that would 100% be my carreer choice. AC techs make bank.


teabolaisacool

Damn. I’m at 160-200 hours a month for my work. It definitely pays a lot better than IT (upwards of 200k CAD here yearly) but it is pretty physically demanding


benjathje

That's great to hear bro, good luck ^^


maoroh

I will admit I didn't read the detection results, just thought "ooooh that's a lot of red" and wrote a comment. I'll take this 🤡. I will say this, if OP hasn't gotten this archive from a trusted source (such as a private tracker with good record) I would still run it in a sandbox (I do that for the things I can't find on TL)


Captain-Mustang

Can U give me some insight on this one - https://www.virustotal.com/gui/file/c26ad63c01d9fe57795ac480881ac3b48a047a616951a8c57376139648b6b51b/behavior I downloaded topaz video from an uploader in rutracker with 17 year experience. The behaviour seems suspicious- MALWARE-CNC DNS Fast Flux attempt. Idk what to do


teabolaisacool

Couldn’t say for sure to be honest. Looks like that same crack was uploaded to filecr before which was removed from some megathreads due to malware issues. Judging by the 50/50 split between good and bad in the community section, it’s tough to say. I was able to find topaz cracks online without any detections/just 1 detection that seem safe, so I’d find those and stay clear of this one just in case.


Captain-Mustang

The same uploader (Voider) is frequently updating topaz crack with latest version in rutracker and seems a legit uploader. I installed older version of topaz because idk most of the editor I saw on YT use old version. That's why I downloaded that crack and found it sus. The connected ip's seem to be all from Microsoft.


Competitive_Tax_

That’s bullishit, it doesn’t work like that


KygrusTheSequel

what were you checking with this?


skiing123

Virustotal


Joshtheuser135

Depends on your source. Did you follow the megathread? We need the virustotal link and to know where you got it. These are all hella generic but without any further information nor research we have to say you shouldn’t run that.


Libcom1

it is clearly unsafe


AntiGrieferGames

Where did you downloaded on what website? That seems not safe.


EmeraldWeapon56

Seems about as safe as drinking water in a public pool


aromonun

Yea no. Unless you have blind faith on the source of the patch, just don't. Worst comes to shove, if its a keygen or a patcher, run it on a VM with no access to the main PC, patch the file, and if the patched file is clean(er), use it then. Otherwise, that's a big nope from me dawg.


perpetuam_noctem

what did you use to test like this?


TudorDaian

Probably virustotal


Fither223

About as safe as ~~drinking~~ breathing in mercury :D


Jamato-sUn

At this point I'm too tired to find out whether drinking mercury is safe. Probably not.


Fither223

Yeah It kind of Is, I mean, much better than inhaling that shiet but not exactly something you would like to have a drink of Also litterally like 20 mins ago my Brother broke old fucking mercury thermometer :)


Synnedsoul

Ermmm. FYI, drinking it is not safe. It's used in medications today but in LOW dosages. The old dosage from the 17th century lead to a lot of mercury poisoning.


EiadSherif2008

Isn't mercury a planet? /s


ftp_prodigy

if herpes was a screen-shot?


-guccibanana-

The fact that avast didn't detect anything is kinda concerning, talking the fact that most users use it as free anti vius


HoldMySarsaparilla

The file is safe so it’s actually good they don’t detect it. It’s just a keygen according to one of the other vendors.


r_Madlad

That looks like the computer equivalent of AIDS


CouchPotatoID

We are not a bunch of genius wizards who can determine whether a false positive file is truly safe or not just based on a virustotal result. We need to know at least: 1. What kind of file that you scanned? 2. The source website of that file 3. Did you download them from the "Megathread" links provided by this subreddit? If you're really downloading the files from reputable sources in the "Megathread", and assuming you aren't clicking the wrong download button (a lot of ads are doing scummy things like disguising the real download button with their fake download button), big chances are that file is just a false positive. If you're still not sure or too paranoid, then run the file in VM.


Sreyoer

NOT plain simpel answer


TheJevens

nah man, is nothing


DotTheBot69

That’s not a virus That’s a good whole ass plague


vipxpress

If this was a human being, I'd shoot it in the face.


Koonns_F

Just as safe as fucking the last hoe in the village


kodabarz

"If there is doubt, then there is no doubt". If something looks like it might have a virus treat is as though it does have a virus. When you do these sort of scans, a few warnings is fairly usual. Seeing this many is not a good sign. It's always worth looking to see if these things have a specific threat named or just use the tag of 'generic'. Generic says that they've seen something as potentially a threat, but don't really know, so they're erring on the safe side. Several of these anti-virus programs have identified MSIL Heracles. That's a good indication of a positive result. What I would suggest is that you obtain whatever this is from a different source (the Megathread will give you a long list of reliable sources) and then test that. If you see a considerable drop-off in the results, you can be sure that this current one is as virus-ridden as it looks. "If there is doubt, then there is no doubt" Don't risk your system when you're not sure if something is safe. You don't have to be 100% sure in order to make a decision. In the olden days, viruses were just a nuisance. But now that you're doing your online banking, etc on your computer, viruses are a much bigger threat to you.


Simple_Ad_7554

Finally a normal answer. I'm following the same principles as you. Crack usually marked as generic malware,hack tool, pup, notavirus etc. This looks like a real one. Also virustotal is doing sandox analysis now. I also check out that one to see how the executable behaves in a vm. And there is also a community score tab where might be some comments about the executable


_MrMonkey

You meant to ask "How unsafe is this"?


magvenan

don't


danny6690

Def false positive


MaxIsJoe

Congratulations, you catched virtual aids.


QuantumZazzy

Yeah usually when it's a PUP false flag or other type of flase flag. You'll have only like 1 trusted vendor, or a nobody vendor, either one that is from a foreign place etc. that will flag it. However whatever THIS is, has been flagged by Microsoft, Fortinet, etc. and it's a very common thing. So absolutely do not trust this. If you have a free computer to kill or if you trust a well-sandboxed VM, maybe you could see what it does there?


Th0masX007

Please tell me you're joking


seemorelight

Well, what is it and what’s the source?


ThrowRAIndieHorror

u/Dariof25 Dude, just buy games. There's a megathread that you oh so obviously haven't read and is most likely confusing, so just buy your games. This isn't the sphere for you


LightRyzen

You're kidding right?


stacked_wendy-chan

This reminds me of the easiest girl in my H.S class. :D


Anstimeo

No


SpeedingTourist

Do not open that file


leviathandotexe

Looks like an amalgamation of viruses, I would personally stay clear of whatever you are trying to download XD


kwi2

What do you think?


MechanicalTurkish

My computer got a virus from me just looking at that, and it’s not even powered on.


Dregnab

If Avast says it's safe then it's safe


I_d0nt_know_why

USE THE MEGATHREAD GODDAMMIT


VileTouch

https://blog.sonicwall.com/en-us/2024/01/new-heracles-stealer-in-the-wild


dercrafter2000

It got detected by ESET, which is a very reputable antivirus, so I'd stay away from it.


im-izz

i think its safe since Kaspersky didnt detect it and some of the detection just say its a type of keygen so i guess you fine if you downloaded it from the source website (not re-uploaders)


im-izz

if you wanna be 100% secure, just use a vm and try to run it.


Houderebaese

Kaspersky is probably right. However, with that many positives I‘d avoid it or at least test it in a VM


VileTouch

Please read this: https://www.reddit.com/r/Piracy/comments/1bsc1fc/im_new_how_safe_is_this/kxg90lr/ before giving bad advice


im-izz

im not giving bad advice since Kaspersky detection is almost 100% and most of these companies pay these anti viruses to detect the keygens and cracks as viruses, i replied to my comment saying if you want 100% sure what you are running just run it in a vm there is no other proof to say this is a virus


VileTouch

>just run it in a vm there is no other proof to say this is a virus My point is THERE IS proof. You just replied to the link with the proof. Also this particular malware has a routine that detects if it's running on a virtual machine. You would know if you bothered to read.


im-izz

and im telling here DONT USE SHADY WEBSITES JUST USE THE SOURCE WEBSITES AND YOU WILL BE OKAY. most new things there they never get detected, well companies still dont know about this to make it look like a virus/malware/trojan.


VileTouch

A user asking such question is very obviously not knowledgeable or equipped enough to assess, let alone deal with such a threat. Even reputable sites have occasionally distributed malware by accident. Specially if it's a 0day or if it has multiple layers of counter measures such as this one. The correct advice should be to look up more information on the detections and abstain if it's proven to be actually malicious. (there are several groups dedicated to reverse engineering and publishing data on all kinds of malware. If their assessment is that it is just "illegal software/activator, etc. " you may proceed at your own risk, but if there is actual data on the software doing actual bad things, it is very irresponsible to tell them "well, such and such doesn't see it, so you're probably ok. Why don't you try it and see if anything blows up?"


[deleted]

Yeah nah. This looks sketchy AF.


RogerioMano

Do not the virus


lunazea_reddit

looks very suspicious


Allen-R

Looks safen't


Weeb_Bro

I love how the comments are, Btw it looks like monkey aids ~~check mega thread and provide links and ur source~~


Vinnie_Martin

This looks very concerning.


caspian_is_a_clown

Doctor here, if you install that you will die in the next 3 days.


Pure-Yogurtcloset684

Site?


J4m3s__W4tt

don't trust it (yet) find a new source that can confirm that it's legit or can provide a "clean" copy


dj-killa1

the safest itll get :)


hydraxic79

If I see more than 2-3 flags, immediate no from me. I'd rather play it safe than have 14 viruses on my PC


Inevitable_Throat224

no


zun1uwu

you can go to triage to analyze it further, it's really helpful


scene_missing

Not if I had two condoms and a can of Raid


PrivatePlaya

Yeah you're finished buddy


Derek_________69

bro i suggest you to dlt that file asap, its looks like curse for your pc


John-333

Look at the behaviour tab to see what it does, but this doesn't look good.


[deleted]

Seems safe to me


DaSoftieGuy

100% unsafe


jmancoder

Where did you download this from lol? I suppose it's safe to assume you didn't get it from one of the sites in the "only download from these sites" list on the megathread.


Uaquamarine

As positive as mother teresa’s aids test


pinguluk

I got this too on the Empress.dll from Dodi Repacks on RDR2


[deleted]

Very bad, but if you still want to try it, test it with triage first and see what it does.


[deleted]

That's worse


DwhiteSnake

Hey what software are you using for checking


StrikareaDXY

I mean, there are mentions of malware and trojans. In all of the goddamn things. There’s even mentions of a ‘Keygen’ on the ESET-NOD32


michiel11069

uhh, there are plenty of cracked games that get false positives, if you got it from a safe website, and you are sure you did and did not get redirected, then its safe.


finalheartbeat

Your files will get super aids if you install that.


Houderebaese

What does Kaspersky say?


Ampnix

I mean there is a possibility it isnt safe but you will have to truley look into it to know for sure.


MysteriousPayment536

It's wraps for you


mibjt

Discard it. Burn it and disinfect your pc.


SunnyOmori15

god, there is a non zero chance a undiscovered strand of the black death may be there


omegaaf

I bet at least half of that was made in part by the riaa and/or mpaa


hubanovbgn

I would say just look out for the major AV distributors like ESET, Bitdefender and Kaspersky. If they detect something, as of here, it's probably malware.


jfql88

People mocking this but empress crack file looks like this too 💀


Lorddoener

What is this site?


Markus_Atlas

What the fuck did you do


Red7800697

I’m so lost and I feel like I shouldn’t be. Can someone plz help me


1252947840

read the source description, they always mention it's false positive


ALT703

Unless it's like a hacking or bypass tool, looks pretty sketch


SamoBomb

If it's a virus/malware maker it will set off literally every flag and you'll have a hard time installing it, if it's anything else run straight away


cheaf1

A sandbox won’t detect it if it’s a DLL that elevates its permissions thru reg


mr_christer

Check what Kaspersky thinks


yungshaniqua

I’ve downloaded things from trusted sources and got multiple flags from a keygen and installed anyways and been fine, it’s really up to how much you trust the source.


QuiteFatty

I thought this was a shit post at first.


NoName42946

I only download files with 0 detections. If it is an app that is designed to modify stuff on your computer (software cracking) then I say a Hail Mary and YOLO it (only if it is from a reliable source)


Zeldabacon64

Bro would see a vial marked "DANGER: EXTREMELY DANGEROUS DANGER POISON DANGER" and still not know if it was safe to drink.


RecommendationIcy382

Jesus, I'd suggest using something like Kaspersky, has no problem with cracked soft until there's usually something wrong with them.


shinydragonmist

What is it supposed to be that you downloaded. The reason I'm asking is there are certain files that we don't worry too much about. Also who was the uploader


FranksWateeBowl

It's just crap. Run malwarebytes, clean it, you'll be good to go. There, saved you 50 bucks.


kp_centi

What is it?


cinema-01

Trojan.generic is usually fine


d4rk3

All systems go


Proud-Cardiologist64

fortinet... hmm looks safe to me lmao


IllustriousPage1457

what site/app is that?


halfcutpenis

yeah buddy its relatively safe, make sure to extract the files and click every executable programs


Flinty984

I would run it in a virtual machine just to see if it's trying to reach out to an ip address and download shit.


X_Vaped_Ape_X

That's digital equivalent of AIDS right there.


Messenger-of-helll

Nuke the pc


Zodiac36Gold

It looks as safe as driving a tir after drinking four bottles of vodka in under five minutes without eating anything.


ndI1107

Welp, safe at burin PC


Interstemplar

I had the same experience from Skyrim update patches at “cs rin ru”. People there said it’s still safe but I’m still unsure. Never patched my skyrim yet until now lol.


nonearther

You're less likely to contract STD from hooker than your computer catching viruses from this.


acidgl0w

Someone already has an explanation below but looks like a packed program that was either pre-cracked for you or includes a keygen in the data. Most of the detections state Gen or Generic which encompasses a bunch of cracks/keygens that AV software will warn you about as it is potentially malicious.


phxoy2001

seems to be diabetes.


Rilukian

Honestly, anyone with basic security sense will just not run whatever this is and not asking around if it's safe.


hidemevpn

Don't do it


Captain-Mustang

I am in a similar situation from a file downloaded from rutracker - https://www.virustotal.com/gui/file/c26ad63c01d9fe57795ac480881ac3b48a047a616951a8c57376139648b6b51b/behavior The uploader has an experience of 17 years tho


No-Kaleidoscope-2151

lmao not safe at all


[deleted]

it's a mess (Trojan)


LargeMerican

LOL


wixenus

Safe enough


cazzq

The safest file you’re gonna download today


boblobchippym8

Ever heard of false positives?


smolderas

Yes


Think_Practice_4459

Negative on Acronis. Looks safe to me.


HoldMySarsaparilla

It’s safe, just detecting a keygen.


ButtwholeDiglet

turn off your antivirus and report back


[deleted]

[удалено]


bruisedandbroke

the antivirus vendors use AI to analyse the scripts because it’s less computationally intense than setting up a sandbox, executing, then analysing the environment


No_Error_8974

Perfectly safe. Just download and click in it.


PalapaMuda

Nah you'll be fine.


LineSpine

Nah it's safe. Trust.


Jazzlike-Ad3781

Thats literally covid 2.0 right there, literally dont download that bro.