Jump to content

KangarooEA


Recommended Posts

  • Replies 431
  • Created
  • Last Reply

Top Posters In This Topic

 

 

 

watch out guys, there is a nasty virus in one of these downloads. i got it of course, removed it by backdating the computer, was lucky.

Link to comment
Share on other sites

Guest Jayman007
watch out guys, there is a nasty virus in one of these downloads. i got it of course, removed it by backdating the computer, was lucky.

 

 

You trying to say there is a virus n the mq4 file? Can't say as I've ever seen a mt4 based virus before. I'll look through the code and see.

 

I just looked at the code posted and it doesn't even compile. Not sure how that could possibly infect you.

Edited by Jayman007
Link to comment
Share on other sites

No virus in KangarooEA files.

 

In the other hand, Ziddu is infamous of its website viruses, so put/get your shares elsewhere if you don't want your pc becoming a spam relay zombie. File sharing feature on Ziddu is just a bait... ;)

 

the mq4 file is clean, the virus arrived as a hitchhiker from the file sharing site.

 

it was one of those virus programms which hijack your computer and wants you to pay for their software. i had these before, they can completely lock up your computer. this particular one was not as bad.

Edited by reinerh
Link to comment
Share on other sites

I think that is possible to crack it, this program uses a protection antidebug based on reading FS register (TIB Thread information block) , is possible to debug using ollydebugger step by step and bypass protection writing nops when read TIB.

 

you are able to do it pal??

Link to comment
Share on other sites

The first key is that we do not have a correct decompiled V5.1. I do not if the latest ex4-to-mq4 can decompile it since I wrote to the author but he said I did not buy it so no support for me.lol

 

If someone can offer a correct decompiled version, I would like to try eudcating this EA.

Link to comment
Share on other sites

You can use ollydebugger, is a ring3 debugger, it cant debug kernel level (ring0) but is very easy to learn and free. Other debugger very powerful and able kernel level is windbg from microsoft but is not such intuitive as ollydebug. There are others like sysser debug and softice, this last is the better but unfortunately its development is ended.
Link to comment
Share on other sites

You can use ollydebugger, is a ring3 debugger, it cant debug kernel level (ring0) but is very easy to learn and free. Other debugger very powerful and able kernel level is windbg from microsoft but is not such intuitive as ollydebug. There are others like sysser debug and softice, this last is the better but unfortunately its development is ended.

 

or you can use IDA Pro which is much the same as Softice...

Link to comment
Share on other sites

No virus in KangarooEA files.

 

In the other hand, Ziddu is infamous of its website viruses, so put/get your shares elsewhere if you don't want your pc becoming a spam relay zombie. File sharing feature on Ziddu is just a bait... ;)

 

Yeah, ziddu... Bad taste in my mouth. I got infected from this site last year and my PCs are not same since. Bad bad virus caught from this site. I ended up rebuild all of my PCs and resulting losing a lots of my files (my bad for not backing up my files on daily.. ) But, regardless, be careful where you downloading stuff or use good virus scanner. Symentec and other well known scanner didn't catch this "nasty" just slip through...

Link to comment
Share on other sites

I don't know if this is latest, but it's v4 and educated. I have not used it, so I do not know its system and how it works or what types of system it is. I heard good things about it, but don't know for sure. I guess we'll find out. :))

Enjoy it!

 

http://www.4shared.com/file/dlMX7zqx/KR_edu.html

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...