Office 2010 Toolkit and EZ-Activator.

Discussion in 'MDL Projects and Applications' started by CODYQX4, Apr 27, 2010.

Thread Status:
Not open for further replies.
  1. TonyTones

    TonyTones MDL Novice

    Jul 13, 2010
    35
    27
    0
    Did you happen to use a USB flash drive or a portable hard drive at any stage after installing windows? If so, it could be that they are infected and the malware installs itself into whatever PC you plug it into... It's happened to me once.

    Tip: Creating a new folder in your USB drive and naming it "Autorun.inf" without the quotes, will stop any malware from executing... A general Windows rule is that a file can never overwrite a folder.
     
  2. jpmonette

    jpmonette MDL Novice

    Sep 5, 2010
    3
    0
    0
    I didn't insert a USB / CD disk in my PC. Everytime I install a new Windows, I turn off the auto-boot feature to avoid USB virus.

    The virus came from keygen.exe (created by the EZ-Activator), I honestly can't see any other way. I know what are fake antivirus blocking application. I finally got over it, but I'll probably still reformat to make sure it's not hidding somewhere.
     
  3. CODYQX4

    CODYQX4 MDL Developer

    Sep 4, 2009
    4,813
    45,775
    150
    Are you sureyou couldn't have been infected some other way? You are the only one who claims infection via keygen.

    Still, I find it weird my NIS 2011 says it blocked remote host from connecting to keygen and I can totally block it in my firewall and it still work. Unless somone can make a open source KMS keygen we are stuck using the current one.
     
  4. jpmonette

    jpmonette MDL Novice

    Sep 5, 2010
    3
    0
    0
    Still, why is this keygen.exe connecting to the Internet? It must get some code from a server out there. Someone should reverse the application or use Wireshark to see the packets transferred.

    Like I said, I'm almost sure at 100% that the infection comes from keygen.exe created by Office 2010 Toolkit. If it doesn't come from this, it's coming from the Channel Switcher. The only clue pushing me toward the toolkit is the firewall notice about keygen.exe, Microsoft Security Essentials detecting a trojan JUST after the Firewall warning and a couple of seconds after, I start getting Antimalware Doctor popups.

    If it's not infecting everyone, it might also infect hosts randomly or for some other reasons to avoid being detected as a source of infection.
     
  5. xscess

    xscess MDL Senior Member

    Jul 27, 2009
    371
    367
    10
    I don't know if there's a new/different keygen in mini-kms v1.31 but wzor has posted it since last few days.

    also an honest question for CODYQX4: what exactly keygen does anyway? (within EZ activator) 'cos usually keygens activates softwares permanently and so far there isn't any keygen out there for Office 2010 that does it... so for what exact part EZ activaor needs a keygen ?

    many thanks in advance
     
  6. CODYQX4

    CODYQX4 MDL Developer

    Sep 4, 2009
    4,813
    45,775
    150
    They have a unpacked Keygen (its double size but still heavliy complained about by AV). It Listens on port 1688 (The default port PCs listen for KMS). It runs on that PC so if ou send a KMS activation request the Keygen will generate activation code and this sends to Office to try and activate it. It emulates a KMS server. The exact details how it does this are unknown as we can't see the code. The Emluation is needed to KMS activate else attempting KMS activation won't do anthing at all.
     
  7. rocky1234

    rocky1234 MDL Novice

    Sep 5, 2010
    3
    0
    0
    #787 rocky1234, Sep 5, 2010
    Last edited: Sep 5, 2010
    Isn't it possible to have a loader like one for Windows 7 to activate Office. Windows 7 loader doesn't want to connect to internet.
     
  8. CODYQX4

    CODYQX4 MDL Developer

    Sep 4, 2009
    4,813
    45,775
    150
    Even if activation worked the same, we lack the key. The Windows loader installs OEM Key/Cert and emulates the SLIC in BIOS.
     
  9. rocky1234

    rocky1234 MDL Novice

    Sep 5, 2010
    3
    0
    0
    #789 rocky1234, Sep 5, 2010
    Last edited: Sep 5, 2010
    Got it, thanks for the info.
     
  10. Airclocker

    Airclocker MDL Novice

    Nov 17, 2009
    48
    0
    0
    Hi guys. I just downloaded MS Office 2010, but i'm having difficulty installing it. Is there a way to install Office without a product key(registry hack)?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  11. CODYQX4

    CODYQX4 MDL Developer

    Sep 4, 2009
    4,813
    45,775
    150
    You have Retail, use Stannieman Channel switcher to make it VL or DL a VL copy. You could also use a leaked retail key but you will mke it easier on yourself to go to VL (as all Office cracks/activation are VL based).
     
  12. Airclocker

    Airclocker MDL Novice

    Nov 17, 2009
    48
    0
    0
    Where can i get the Stannieman Channel
    switcher?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  13. timesurfer

    timesurfer MDL Developer

    Nov 22, 2009
    8,524
    4,112
    270
    Just a few threads down
     
  14. Airclocker

    Airclocker MDL Novice

    Nov 17, 2009
    48
    0
    0
    #797 Airclocker, Sep 6, 2010
    Last edited: Sep 6, 2010
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  15. Airclocker

    Airclocker MDL Novice

    Nov 17, 2009
    48
    0
    0
    I'm using v1.1, but i've downloaded v1.2 and busy trying to create the ISO
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. kdo2milger

    kdo2milger MDL Senior Member

    Jan 5, 2010
    371
    25
    10