{"id":14624,"date":"2019-02-18T09:10:18","date_gmt":"2019-02-18T17:10:18","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/02\/18\/news-8373\/"},"modified":"2019-02-18T09:10:18","modified_gmt":"2019-02-18T17:10:18","slug":"news-8373","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/02\/18\/news-8373\/","title":{"rendered":"Crack hunting: not all it\u2019s cracked up to be"},"content":{"rendered":"<p><strong>Credit to Author: Tammy Stewart| Date: Mon, 18 Feb 2019 16:00:00 +0000<\/strong><\/p>\n<p>People sometimes ask us in the forums if a keygen or software crack is safe to use. Sometimes, these programs do what they say on the tin. Other times, they\u2019re not what they say they are. In this post, I\u2019ll describe what happened when I went crack hunting, and why it is often unsafe to carry out this activity.<\/p>\n<p>Researchers like myself often browse <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/crack\/\" target=\"_blank\" rel=\"noopener\">crack<\/a> and <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/Keygen\/\" target=\"_blank\" rel=\"noopener\">keygen<\/a> sites because they are known to host many affiliate links to third-party applications, many of which include Potentially Unwanted Programs (PUPs), adware, or worse. Many of these sites also host downloads for malware.<\/p>\n<p>These sources are important to research because users often browse crack and keygen sites looking to find paid software for free. This is risky practice, though, because the user may end up downloading unwanted software that can do more harm than good.<\/p>\n<p>In this case, I was looking for a crack for Windows 10 Pro, since it\u2019s popular software. The crack download itself was actually not a crack, but a file we detect as <a href=\"https:\/\/blog.malwarebytes.com\/detections\/pup-optional-installcore\/\" target=\"_blank\" rel=\"noopener\">PUP.Optional.InstallCore.Generic<\/a>. This \u201ccrack\u201d did not run properly on my test machine, most likely because of <a href=\"https:\/\/blog.malwarebytes.com\/101\/2013\/02\/sandbox-sensitivity\/\" target=\"_blank\" rel=\"noopener\">sandbox sensitivity<\/a>.<\/p>\n<p>While the \u201ccrack\u201d was being downloaded, the download page redirected to a page advertising DriverFix. The advertisement is one of many adverts offered by <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/ad-rotator\/\" target=\"_blank\" rel=\"noopener\">ad rotators<\/a>.<\/p>\n<p>I clicked on the link, which in turn opened the following site:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27154\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/redirected-download-landing-pagewm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/redirected-download-landing-pageWM.jpg\" data-orig-size=\"1581,1056\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1547202589&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"redirected download landing pageWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/redirected-download-landing-pageWM-300x200.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/redirected-download-landing-pageWM-600x401.jpg\" class=\"aligncenter wp-image-27154 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/redirected-download-landing-pageWM.jpg\" alt=\"\" width=\"1581\" height=\"1056\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/redirected-download-landing-pageWM.jpg 1581w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/redirected-download-landing-pageWM-300x200.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/redirected-download-landing-pageWM-600x401.jpg 600w\" sizes=\"auto, (max-width: 1581px) 100vw, 1581px\" \/><\/p>\n<p>Clicking the \u201cdownload now\u201d button downloaded the file from the DriverFix site and delivered basic instructions on how to get the program to run.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27155\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/downloading_driverfixwm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Downloading_DriverFixWM.jpg\" data-orig-size=\"977,621\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1547746874&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Downloading_DriverFixWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Downloading_DriverFixWM-300x191.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Downloading_DriverFixWM-600x381.jpg\" class=\"aligncenter wp-image-27155 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Downloading_DriverFixWM.jpg\" alt=\"\" width=\"977\" height=\"621\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Downloading_DriverFixWM.jpg 977w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Downloading_DriverFixWM-300x191.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Downloading_DriverFixWM-600x381.jpg 600w\" sizes=\"auto, (max-width: 977px) 100vw, 977px\" \/><\/p>\n<p>According to the website, DriverFix is a Windows application that scans your machine to find outdated drivers, and allows users to update those drivers from within the application with one click. So I tried it.<\/p>\n<p>Once the software was installed, it automatically launched, ran a scan, and displayed the results of the scan. Here are results from two different machines. Notice the results show drivers as being \u201cExtremely old.\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27156\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/scan_results_multiple-extremely_old_driverswm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM.png\" data-orig-size=\"1280,720\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Scan_Results_Multiple Extremely_Old_DriversWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM-300x169.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM-600x338.png\" class=\"aligncenter size-full wp-image-27156\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM.png\" alt=\"\" width=\"1280\" height=\"720\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM.png 1280w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM-300x169.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM-600x338.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM-900x506.png 900w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_Results_Multiple-Extremely_Old_DriversWM-400x225.png 400w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27157\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/scan_results_2_extremely_old_driverswm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_results_2_extremely_old_driversWM.jpg\" data-orig-size=\"1044,761\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1545199248&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Scan_results_2_extremely_old_driversWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_results_2_extremely_old_driversWM-300x219.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_results_2_extremely_old_driversWM-600x437.jpg\" class=\"aligncenter size-full wp-image-27157\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_results_2_extremely_old_driversWM.jpg\" alt=\"\" width=\"1044\" height=\"761\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_results_2_extremely_old_driversWM.jpg 1044w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_results_2_extremely_old_driversWM-300x219.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/Scan_results_2_extremely_old_driversWM-600x437.jpg 600w\" sizes=\"auto, (max-width: 1044px) 100vw, 1044px\" \/><\/p>\n<p>This gives users false ideas that their machine has issues that must be fixed. When I expanded the info for my batteries and checked it, indeed there are newer drivers available, though calling my drivers \u201cextremely old\u201d is a bit of a fallacy.<\/p>\n<p>When the user attempts to \u201cupdate all\u201d or update one driver, they are presented with a pricing page to pay for the services to update their drivers.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27158\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/clicking-download-driver-opens-payme-pagewm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/clicking-download-driver-opens-payme-pageWM.jpg\" data-orig-size=\"1019,645\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1545199577&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"clicking download driver opens payme pageWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/clicking-download-driver-opens-payme-pageWM-300x190.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/clicking-download-driver-opens-payme-pageWM-600x380.jpg\" class=\"aligncenter size-full wp-image-27158\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/clicking-download-driver-opens-payme-pageWM.jpg\" alt=\"\" width=\"1019\" height=\"645\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/clicking-download-driver-opens-payme-pageWM.jpg 1019w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/clicking-download-driver-opens-payme-pageWM-300x190.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/clicking-download-driver-opens-payme-pageWM-600x380.jpg 600w\" sizes=\"auto, (max-width: 1019px) 100vw, 1019px\" \/><\/p>\n<p>The user then has the choice to update one driver, update all drivers on their system, or purchase the \u201cfamily pack,\u201d which will update as many as three PCs. Many users will opt-out of purchasing the services at this point.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27159\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/driver-download-pricingwm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driver-download-pricingWM.jpg\" data-orig-size=\"1004,635\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1545199649&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"driver download pricingWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driver-download-pricingWM-300x190.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driver-download-pricingWM-600x379.jpg\" class=\"aligncenter size-full wp-image-27159\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driver-download-pricingWM.jpg\" alt=\"\" width=\"1004\" height=\"635\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driver-download-pricingWM.jpg 1004w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driver-download-pricingWM-300x190.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driver-download-pricingWM-600x379.jpg 600w\" sizes=\"auto, (max-width: 1004px) 100vw, 1004px\" \/><\/p>\n<p>This is where things get hairy. One does not have to buy new drivers. In my case, all I did was Google the driver description \u201cMicrosoft ACPI-compliant control method battery driver Windows 10\u201d and found results right from the <a href=\"http:\/\/www.catalog.update.microsoft.com\/Search.aspx?q=ACPI-Compliant+Control+Method+Battery\" target=\"_blank\" rel=\"noopener\">Microsoft Update Catalog<\/a> site.<\/p>\n<p>If this proves to be difficult for the not-so-tech-savvy folk, you can also open Device Manager, expand the driver in question, open the Driver tab, and click \u201cUpdate Driver.\u201d Microsoft will download the driver your system needs at no cost. Plus, you can be sure it is coming from Microsoft.<\/p>\n<p>If the user decides not to purchase and simply closes DriverFix, eventually they end up with warning messages from DriverFix regarding their outdated drivers when they do anything on their machine that uses the drivers flagged in the initial scan. Below is the notification I received from DriverFix when I was saving a file to my machine.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27160\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/warning-from-driverfix-when-saving-file-to-diskwm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/warning-from-driverfix-when-saving-file-to-diskWM.jpg\" data-orig-size=\"559,189\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1545201295&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"warning from driverfix when saving file to diskWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/warning-from-driverfix-when-saving-file-to-diskWM-300x101.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/warning-from-driverfix-when-saving-file-to-diskWM.jpg\" class=\"aligncenter size-full wp-image-27160\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/warning-from-driverfix-when-saving-file-to-diskWM.jpg\" alt=\"\" width=\"559\" height=\"189\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/warning-from-driverfix-when-saving-file-to-diskWM.jpg 559w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/warning-from-driverfix-when-saving-file-to-diskWM-300x101.jpg 300w\" sizes=\"auto, (max-width: 559px) 100vw, 559px\" \/><\/p>\n<p>This is not typical behavior from benign software. This behavior is designed to scare the user into thinking they have severe issues that will only be solved by purchasing services from DriverFix.<\/p>\n<p>This is after the user might have thought they were getting a free product that promised to fix driver issues in one click when they ran into the initial advertisement.<\/p>\n<p>Unless your machine is very old, Microsoft provides compatible drivers, or the computer manufacturer automatically provides driver updates through its own built-in software at no cost.<\/p>\n<p>Between discovery of this program on December 19, 2018 and January 9, 2019, the installer for this product has been detected 3,245 times by Malwarebytes. There have also been 839 reported traces detected as a result of installs during the same time frame.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27161\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/driverfix_detection_rates_since_seenwm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driverfix_detection_rates_since_seenWM.jpg\" data-orig-size=\"2222,186\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1547133044&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"driverfix_detection_rates_since_seenWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driverfix_detection_rates_since_seenWM-300x25.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driverfix_detection_rates_since_seenWM-600x50.jpg\" class=\"aligncenter size-full wp-image-27161\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driverfix_detection_rates_since_seenWM.jpg\" alt=\"\" width=\"2222\" height=\"186\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driverfix_detection_rates_since_seenWM.jpg 2222w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driverfix_detection_rates_since_seenWM-300x25.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/driverfix_detection_rates_since_seenWM-600x50.jpg 600w\" sizes=\"auto, (max-width: 2222px) 100vw, 2222px\" \/><\/p>\n<p>Malwarebytes blocks the website that hosts DriverFix downloads, and stops the application installer from launching.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27162\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/mbam-blocks-sitewm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/MBAM-blocks-siteWM.jpg\" data-orig-size=\"535,270\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1546871687&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"MBAM blocks siteWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/MBAM-blocks-siteWM-300x151.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/MBAM-blocks-siteWM.jpg\" class=\"aligncenter size-full wp-image-27162\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/MBAM-blocks-siteWM.jpg\" alt=\"\" width=\"535\" height=\"270\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/MBAM-blocks-siteWM.jpg 535w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/MBAM-blocks-siteWM-300x151.jpg 300w\" sizes=\"auto, (max-width: 535px) 100vw, 535px\" \/><\/p>\n<p>We detect the application as <a href=\"https:\/\/blog.malwarebytes.com\/detections\/pup-optional-driverfix\/\" target=\"_blank\" rel=\"noopener\">PUP.Optional.DriverFix<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"27163\" data-permalink=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/attachment\/launching-app-blockedwm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/launching-app-blockedWM.jpg\" data-orig-size=\"518,199\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;Research-02&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;1546871914&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"launching app blockedWM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/launching-app-blockedWM-300x115.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/launching-app-blockedWM.jpg\" class=\"aligncenter size-full wp-image-27163\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/launching-app-blockedWM.jpg\" alt=\"\" width=\"518\" height=\"199\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/launching-app-blockedWM.jpg 518w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/launching-app-blockedWM-300x115.jpg 300w\" sizes=\"auto, (max-width: 518px) 100vw, 518px\" \/><\/p>\n<p>If you installed DriverFix, we have <a href=\"https:\/\/forums.malwarebytes.com\/topic\/241580-removal-instructions-for-driverfix\/\">instructions<\/a> on how to remove it or how to add exclusions if you decide to keep it.<\/p>\n<p>As long as sites continue to try pushing cracked software that seem too good to be true (and thus, is actually harmful to users), we will continue to detect such programs in order to protect our customers.<\/p>\n<p>And for those looking for the silver bullet software in crack or keygen sites, we suggest making sure you can spot benign programs from those that try to squeeze a few bucks out of unsuspecting users. Exploring these sites is not for the uninitiated\u2014best to stick to tried and true, legitimate versions of software programs instead of risking illegal crack or keygen sites and programs.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/\">Crack hunting: not all it\u2019s cracked up to be<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Tammy Stewart| Date: Mon, 18 Feb 2019 16:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/' title='Crack hunting: not all it\u2019s cracked up to be'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/02\/shutterstock_275967710.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>People sometimes ask us in the forums if a keygen or software crack is safe to use. In this post, we&#8217;ll describe what happened when one of our researchers went crack hunting, and why it is often unsafe to carry out this activity.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/puppum\/\" rel=\"category tag\">PUP<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/crack-hunting\/\" rel=\"tag\">crack hunting<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/keygen\/\" rel=\"tag\">keygen<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pups\/\" rel=\"tag\">PUPs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/software-crack\/\" rel=\"tag\">software crack<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/' title='Crack hunting: not all it\u2019s cracked up to be'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/puppum\/2019\/02\/crack-hunting-not-all-its-cracked-up-to-be\/\">Crack hunting: not all it\u2019s cracked up to be<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[20956,20957,10566,2130,20958],"class_list":["post-14624","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-crack-hunting","tag-keygen","tag-pup","tag-pups","tag-software-crack"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14624"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14624\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14624"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}