Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Potential trojan? #16

Open
SoftColours opened this issue Dec 3, 2021 · 29 comments
Open

Potential trojan? #16

SoftColours opened this issue Dec 3, 2021 · 29 comments

Comments

@SoftColours
Copy link

After downloading and using this to active MS Office, Windows Defender flagged a threat called "Win32/Uwamson.A!ml". Different google results indicate that this is either a trojan, ransomware or just a false positive. I was able to quarantine and remove it without any problems, but I thought I'd bring it up here just in case.

@KcrPL
Copy link

KcrPL commented Dec 3, 2021

False positive. One thing Defender is particularly good at is detecting activators for Micro$oft's own products.

@Francismori7
Copy link

False positive.

@ChrisChrome
Copy link

False positive

1 similar comment
@greysilly7
Copy link

False positive

@CitizenDroid
Copy link

Could really do with some help as Eset security keeps removing the KMS_VL_ALL_AIO even after excluding it. I have installed
ok with eset disabled but does any one know how to set up exclusions in eset properly as I seem to be missing something here!.
in Quarantine, Restore and exclude from scanning is greyed out for thsi file and I can't find any info on how to get that working eset are no help, I'm eally starting to dislike eset lately. also concerned that even though I have excluded SppExtComObjHook.dll that eset will still ignor the exclusion and stop that working. any help here would be really appreciated.
has any one else got this file working with eset!.

@Francismori7
Copy link

Could really do with some help as Eset security keeps removing the KMS_VL_ALL_AIO even after excluding it. I have installed ok with eset disabled but does any one know how to set up exclusions in eset properly as I seem to be missing something here!. in Quarantine, Restore and exclude from scanning is greyed out for thsi file and I can't find any info on how to get that working eset are no help, I'm eally starting to dislike eset lately. also concerned that even though I have excluded SppExtComObjHook.dll that eset will still ignor the exclusion and stop that working. any help here would be really appreciated. has any one else got this file working with eset!.

ESET Endpoint Security is managed by an ESET Protect server in which you now create the exclusions and they get sent through the agents to your endpoints.

From what I can tell you, SppExtComObjHook.dll is not flagged when it renews the KMS licence periodically, VMs have no issue renewing their licence even without the file excluded, just setting up the auto renewal at the beginning gets flagged

@CitizenDroid
Copy link

CitizenDroid commented Dec 11, 2021

Could really do with some help as Eset security keeps removing the KMS_VL_ALL_AIO even after excluding it. I have installed ok with eset disabled but does any one know how to set up exclusions in eset properly as I seem to be missing something here!. in Quarantine, Restore and exclude from scanning is greyed out for thsi file and I can't find any info on how to get that working eset are no help, I'm eally starting to dislike eset lately. also concerned that even though I have excluded SppExtComObjHook.dll that eset will still ignor the exclusion and stop that working. any help here would be really appreciated. has any one else got this file working with eset!.

ESET Endpoint Security is managed by an ESET Protect server in which you now create the exclusions and they get sent through the agents to your endpoints.

From what I can tell you, SppExtComObjHook.dll is not flagged when it renews the KMS licence periodically, VMs have no issue renewing their licence even without the file excluded, just setting up the auto renewal at the beginning gets flagged

Thanks for the info well appreciated. at least I don't have to worry about the SppExtComObjHook.dll file which is handy as for the other part I have kept the KMS_VL_ALL_AIO in a zipped file and eset seems to leave that alone so at least I know I just have to disable eset while installing.
Does that mean once it's sent to endpoints eset will eventually stop flagging the file!
again many thanks for your reply.

@Francismori7
Copy link

Could really do with some help as Eset security keeps removing the KMS_VL_ALL_AIO even after excluding it. I have installed ok with eset disabled but does any one know how to set up exclusions in eset properly as I seem to be missing something here!. in Quarantine, Restore and exclude from scanning is greyed out for thsi file and I can't find any info on how to get that working eset are no help, I'm eally starting to dislike eset lately. also concerned that even though I have excluded SppExtComObjHook.dll that eset will still ignor the exclusion and stop that working. any help here would be really appreciated. has any one else got this file working with eset!.

ESET Endpoint Security is managed by an ESET Protect server in which you now create the exclusions and they get sent through the agents to your endpoints.
From what I can tell you, SppExtComObjHook.dll is not flagged when it renews the KMS licence periodically, VMs have no issue renewing their licence even without the file excluded, just setting up the auto renewal at the beginning gets flagged

Thanks for the info well appreciated. at least I don't have to worry about the SppExtComObjHook.dll file which is handy as for the other part I have kept the KMS_VL_ALL_AIO in a zipped file and eset seems to leave that alone so at least I know I just have to disable eset while installing. Does that mean once it's sent to endpoints eset will eventually stop flagging the file! again many thanks for your reply.

Yep! The exclusion gets sent and will apply straight away. I no longer need to disable ESET at all

@CitizenDroid
Copy link

Thanks so much for clearing that up for me I hope that is the case eventually! but have added KMS_VL_ALL_AIO.cmd and just KMS_VL_ALL_AIO to both Performance and Detection exclusions but it's still quarantining the file when I click on it but as long as it doesn't pick up SppExtComObjHook.dll doing it's job I don't mind have added that as well. just have to keep the file zipped and turn off AV before installing but hopefully it kicks in with endpoints and leaves it alone, I've been testing differant software so hence my need to silence AV as eset is getting on my last nerve :/ .
cheers for that at least I know what it is supposed to do! :)

@CitizenDroid
Copy link

CitizenDroid commented Dec 12, 2021

Allow me to rephrase that :) seems to have finally kicked hooray. I just tried again after posting comment lol and eset haven't eaten it wow . did take quite a while though not sure why that was!.
again thanks for your help really appreciated.
Regards

@Macleykun
Copy link

Issue can be closed
https://www.virustotal.com/gui/file/e4834aaf04092bbd62048c9182a9d92fd527f900c72666d1e9f2dabbc6dddd03
running latest Microsoft Defender on W11 results no false positives :-)

@CitizenDroid
Copy link

Issue can be closed https://www.virustotal.com/gui/file/e4834aaf04092bbd62048c9182a9d92fd527f900c72666d1e9f2dabbc6dddd03 running latest Microsoft Defender on W11 results no false positives :-)

It's not that I'm worried about this any more as I have pretty much given up trying as I thought it had stopped!!. but it's still flagging it up looks like exclusions not being accepted for what ever reason no matter how many times I add it. starting to really dislike eset. I have never had problems with eset like this before it has always been easy to control and have used many cracks, trainers and patches with no issues after adding them to list if needed.
would complain to eset but whats the point they would only suck more of my life away with pointless BS emails.
thank you though for trying to help and enlighten me was much appreciated.
Kind regards

@DeathGOD7
Copy link

Issue can be closed https://www.virustotal.com/gui/file/e4834aaf04092bbd62048c9182a9d92fd527f900c72666d1e9f2dabbc6dddd03 running latest Microsoft Defender on W11 results no false positives :-)

It's not that I'm worried about this any more as I have pretty much given up trying as I thought it had stopped!!. but it's still flagging it up looks like exclusions not being accepted for what ever reason no matter how many times I add it. starting to really dislike eset. I have never had problems with eset like this before it has always been easy to control and have used many cracks, trainers and patches with no issues after adding them to list if needed. would complain to eset but whats the point they would only suck more of my life away with pointless BS emails. thank you though for trying to help and enlighten me was much appreciated. Kind regards

Some antivirus really hates the windows activator. That's why I had installed Kaspersky but its license got expired back in 2019 so for now I have added Avast but planning to remove them aswell. I always disable windows defender as it's naggy as hell.

I have used that same script in 5 devices including mine (Windows Defender, Avast, Kaspersky) not one single reported as malware nor removed it. Maybe change the antivirus?

@CitizenDroid
Copy link

CitizenDroid commented Jan 13, 2022

Yer as I said not really worried about it being a malware as such as I know most AVs pick up activators, patches and allot of game trainers even ones I know are 100% safe, this thread was more about trying and get Eset to stop being a massive pain the the arse and exclude a file when told to but like most software and governments today just seem to want to force their wants on you :/ which Eset now seems to be no exception. it used to be bang on software and never flagged trainers or cracks but now it's just picking up everything maybe their being paid to embarrass the wants of the copyright brigade, who knows. anyway pretty much given up with asking Eset to exclude it just doesn't want to comply. might think twice about installing Eset again when it acts as stroppy as all the freeware.
thanks for the input :)

@parth-8vgft
Copy link

@Francismori7 @KcrPL @ChrisChrome @CitizenDroid

First of all, I don't know much about batch file language.

But can you guys tell me the meaning of the code between line number 3979 to 4722 ( stated below )? it looks like some hidden encoded malicious code with some decoded function.

@WindowsAddict
Copy link

WindowsAddict commented May 18, 2022

From read me,

image
https://github.com/AveYo/Compressed2TXT

The traditional pack is posted here
https://forums.mydigitallife.net/posts/838808/

@ChaseKnowlden
Copy link

Windows Defender resulted this activator as a virus.

@radoslew
Copy link

Windows Defender resulted this activator as a virus.

It was discussed hundred of times. Read the discussion!

@CitizenDroid
Copy link

While once upon a time it was handy using cracks like this it’s not really needed anymore you can obtain a licence via ebay or other sites offering ms office and loads of other usefull software at a Rez till of the normal cost just Google it the hard legit licences I paid £12 fof office so why take any risk any more. You don’t need to bug a as licence for windows so don’t bdd ed filled use your old windows licence it will activate windows 10 or 11 you can check places like kinguin. net for legit stuff and other sites like it don’t use Etsy they allow cracked bent software and ard a pin to get your money back

@rautamiekka
Copy link

While once upon a time it was handy using cracks like this it’s not really needed anymore you can obtain a licence via ebay or other sites offering ms office and loads of other usefull software at a Rez till of the normal cost just Google it the hard legit licences I paid £12 fof office so why take any risk any more. You don’t need to bug a as licence for windows so don’t bdd ed filled use your old windows licence it will activate windows 10 or 11 you can check places like kinguin. net for legit stuff and other sites like it don’t use Etsy they allow cracked bent software and ard a pin to get your money back

Doesn't make it worth the time nor the hassle, a total waste of a rant.

@CitizenDroid
Copy link

While once upon a time it was handy using cracks like this it’s not really needed anymore you can obtain a licence via ebay or other sites offering ms office and loads of other usefull software at a Rez till of the normal cost just Google it the hard legit licences I paid £12 fof office so why take any risk any more. You don’t need to bug a as licence for windows so don’t bdd ed filled use your old windows licence it will activate windows 10 or 11 you can check places like kinguin. net for legit stuff and other sites like it don’t use Etsy they allow cracked bent software and ard a pin to get your money back

Doesn't make it worth the time nor the hassle, a total waste of a rant.

Much like your pointless comment! but here you are still taking the time and hassle replying to something that you need not! what a Knobend!.

@radoslew
Copy link

radoslew commented Apr 1, 2024

While once upon a time it was handy using cracks like this it’s not really needed anymore you can obtain a licence via ebay or other sites offering ms office and loads of other usefull software at a Rez till of the normal cost just Google it the hard legit licences I paid £12 fof office so why take any risk any more. You don’t need to bug a as licence for windows so don’t bdd ed filled use your old windows licence it will activate windows 10 or 11 you can check places like kinguin. net for legit stuff and other sites like it don’t use Etsy they allow cracked bent software and ard a pin to get your money back

You cannot use W7 keys to activate new versions of Windows anymore. Maybe you should learn something first and then try to teach someone else.

@CitizenDroid
Copy link

While once upon a time it was handy using cracks like this it’s not really needed anymore you can obtain a licence via ebay or other sites offering ms office and loads of other usefull software at a Rez till of the normal cost just Google it the hard legit licences I paid £12 fof office so why take any risk any more. You don’t need to bug a as licence for windows so don’t bdd ed filled use your old windows licence it will activate windows 10 or 11 you can check places like kinguin. net for legit stuff and other sites like it don’t use Etsy they allow cracked bent software and ard a pin to get your money back

You cannot use W7 keys to activate new versions of Windows anymore. Maybe you should learn something first and then try to teach someone else.

Jesus do sad little twats like you just troll people because your bird of life or does it make you feel clever and important. even if that’s true had it harmed any one ! F***ing sad twat

@NordicPegasus
Copy link

I upgraded from Win10 LTSC to Win11 LTSC. I was used to permantly disable Defender via GPO/registry. This seems not work with Win11 anymore. So I experienced the anoying security alerts concerning the KMS script. I made an exclusion for the unzipped file, so it does not get deleted by Defender.

Just for my understanding, what part of the script gets the false positive reaction from Defender? Is it the script in general or the autorenewal part? If its the ladder, would a "light version" with only manual activation do the trick? I personally only use the manual option and run the script after the activation expired. Is a manual only version available?

@abbodi1406
Copy link
Owner

I upgraded from Win10 LTSC to Win11 LTSC. I was used to permantly disable Defender via GPO/registry. This seems not work with Win11 anymore. So I experienced the anoying security alerts concerning the KMS script. I made an exclusion for the unzipped file, so it does not get deleted by Defender.

Just for my understanding, what part of the script gets the false positive reaction from Defender? Is it the script in general or the autorenewal part? If its the ladder, would a "light version" with only manual activation do the trick? I personally only use the manual option and run the script after the activation expired. Is a manual only version available?

Mostly the embedded dll files (required for activation regardless mode)
you can check the Traditional pack and see which files are flagged
https://pastebin.com/raw/cpdmr6HZ

@NordicPegasus
Copy link

Mostly the embedded dll files (required for activation regardless mode) you can check the Traditional pack and see which files are flagged https://pastebin.com/raw/cpdmr6HZ

The AIO gets quarantined right after the download (zipped and password protected). The unzipped cmd-file gets quarantined too.

Your "traditional" version is neither quarantined as a zipped file nor after unpacking. I could run the cmd (Defener active) and it completed the manual activation without any notification. It seems the "AIO" part is the problem.

Where can I download the traditional version for future updates? Is that a different Github project?

Anyway, thanks for the alternative version.

@abbodi1406
Copy link
Owner

Mostly the embedded dll files (required for activation regardless mode) you can check the Traditional pack and see which files are flagged https://pastebin.com/raw/cpdmr6HZ

The AIO gets quarantined right after the download (zipped and password protected). The unzipped cmd-file gets quarantined too.

Your "traditional" version is neither quarantined as a zipped file nor after unpacking. I could run the cmd (Defener active) and it completed the manual activation without any notification. It seems the "AIO" part is the problem.

Where can I download the traditional version for future updates? Is that a different Github project?

Anyway, thanks for the alternative version.

The AIO.7z is specifically flagged by its hash (probably because it's more popular and published here)

https://pastebin.com/cpdmr6HZ or https://rentry.co/KMS_VL_ALL (also listed in AIO ReadMe) always point to latest AIO and Traditional
Traditional pack doesn't have a Github project

@enigmaelectronica
Copy link

Si bien en algún momento fue útil usar cracks como este, ya no es realmente necesario. Puede obtener una licencia a través de eBay u otros sitios que ofrecen MS Office y un montón de otros programas útiles a un costo menor del normal. Simplemente busque en Google las licencias legítimas. Pagué £12 por Office, así que ¿por qué correr más riesgos? No necesita crear una licencia para Windows, así que no use su antigua licencia de Windows; activará Windows 10 u 11. Puede buscar en sitios como Kinguin.net para obtener material legítimo y otros sitios similares. No use Etsy, ya que permiten software pirateado y pide un PIN para recuperar su dinero.

¿Y qué haces acá entonces? Si no te gusta, vete a comprarlo por tu cuenta y deja de molestar.

@ilez0660
Copy link

top

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests