Page 1 of 1

Re: Kingdom Come: Deliverance: Trainer (+19) [1.2 - 1.3.1] {The Mogician}

Posted: Tue Mar 20, 2018 12:14 pm
by vBuster
This is most likely MALWARE!

Drops these files (use 7z to extract Kingdom_Come_v1.3.1_+19_Trainer.exe):

<AppData>\1337\TrainerEng.EXE
<AppData>\1337\winhost.exe

Creates these files after execution:

<AppData>\1337\winlogen.exe (Description: YandexDiskSetup v1.4.19.5465 / Language: Russian)
<AppData>\1337\lanhost.exe (Description: YandexDiskSetup v1.4.19.5465 / Language: Russian)

It has been reported that it installs a cryptocurrency miner (but this could not be verified), most likely YandexDisk is used to retrieve malware which then is activated!

So be careful and do not use this trainer, there are plenty of clean alternatives from fearlessrevolution and Fearlessrevolution!

Re: Kingdom Come: Deliverance: Trainer (+19) [1.2 - 1.3.1] {The Mogician}

Posted: Tue Mar 20, 2018 1:22 pm
by STN
vBuster wrote:
Tue Mar 20, 2018 12:14 pm
This is most likely MALWARE!

Drops these files (use 7z to extract Kingdom_Come_v1.3.1_+19_Trainer.exe):

<AppData>\1337\TrainerEng.EXE
<AppData>\1337\winhost.exe

Creates these files after execution:

<AppData>\1337\winlogen.exe (Description: YandexDiskSetup v1.4.19.5465 / Language: Russian)
<AppData>\1337\lanhost.exe (Description: YandexDiskSetup v1.4.19.5465 / Language: Russian)

It has been reported that it installs a cryptocurrency miner (but this could not be verified), most likely YandexDisk is used to retrieve malware which then is activated!

So be careful and do not use this trainer, there are plenty of clean alternatives from fearlessrevolution and MAF!
Thanks for letting me know!. This and 2 other aliases of his removed.

Re: Kingdom Come: Deliverance: Trainer (+19) [1.2 - 1.3.1] {The Mogician}

Posted: Tue Mar 20, 2018 1:35 pm
by vBuster
PMed