32.gif

Search (advanced search)
Use this Search form before posting, asking or make a new thread.
Tips: Use Quotation mark to search words (eg. "How To Make Money Online")

10-04-2013, 05:52 AM (This post was last modified: 10-04-2013 12:37 PM by CharlieBrown.)
Post: #1
[GET] Covert Viral Wizard and Covert Content Wizard (Needs NULLING)
Requested here:

Code:
http://bestblackhatforum.com/Thread-Req-Covert-Viral-Wizard-theme?highlight="covert+viral+wizard"

Salespage:

Code:
http://covertviralwizard.com






Zippyshare All-In-One:
Magic Button :
Code:
http://www48.zippyshare.com/v/52158746/file.html

VirusTotal (1/48):
Code:
http://www.virustotal.com/en/file/6e1fd268829f58b15babf3a5180d80323c82ecec4fcd37485330589e922f8125/analysis/1380829827/

I have yet to install and test, may need nulling.



If you find this helpful, please add max [+] Reputation,
keeps me motivated to share ;) Thanks!
10-04-2013, 06:00 AM
Post: #2
RE:
Thanks, but the "PHP/Kryptik.AB" can be a nasty problem IF that is really what the scan is. Could be a false positive but few years back got one site infected and it spread to all sites hosted on the account.
if you think everyone else stupid, might be good time to look in a mirror...
10-04-2013, 06:03 AM (This post was last modified: 10-04-2013 06:05 AM by CharlieBrown.)
Post: #3
RE:
I got the drop box link from a pal, then compressed all files into one rar.

I have not modified otherwise, but yes, always use at your own risks that's why I provide virus results whenever permitted ;)
(10-04-2013 06:00 AM)justanumber Wrote:  Thanks, but the "PHP/Kryptik.AB" can be a nasty problem IF that is really what the scan is. Could be a false positive but few years back got one site infected and it spread to all sites hosted on the account.
10-04-2013, 06:10 AM
Post: #4
RE:
I hope someone can help out with this. Thanks guys
10-04-2013, 09:36 AM (This post was last modified: 10-04-2013 09:45 AM by CharlieBrown.)
Post: #5
RE:
I did individual scans of both files separate for the theme and plugin on virustotal and got the same result. I researched it on the internet and got results that indicate it may be a false positive due to encryption in the footer. Others state may be malware. Can an experienced coder/cracker/hacker look at this?

Ran a scan on Virscan.org with again ENOD-32 the only one coming up with the alert:

Code:
http://r.virscan.org/report/6234f82679536dd9d82c34f47dafccb7.html

I have a clean server with space available and testing now, will report results.

Thanks!
47.gif
10-04-2013, 11:03 AM
Post: #6
RE:
great thanx....already repped u....so anyone can nulled this....?
10-07-2013, 03:19 AM
Post: #7
RE:
Hi,
I can see it's got "base64_decode" and "codelock_code", double encoding.

Let's see who can clean this

Thank you
10-07-2013, 03:43 AM
Post: #8
RE:
(10-07-2013 03:19 AM)wprocker Wrote:  Hi,
I can see it's got "base64_decode" and "codelock_code", double encoding.

Let's see who can clean this

Thank you

Working with waraxe to decode, I'll keep you posted.
10-07-2013, 04:34 AM
Post: #9
RE:
Looking forward to it!

Tyfricko admits being new to it so encrypted is probably not going to work for him.

Maybe Sista or Simey69 if you have no success?!

Thanks!

(10-07-2013 03:43 AM)wprocker Wrote:  
(10-07-2013 03:19 AM)wprocker Wrote:  Hi,
I can see it's got "base64_decode" and "codelock_code", double encoding.

Let's see who can clean this

Thank you

Working with waraxe to decode, I'll keep you posted.
10-07-2013, 05:06 AM
Post: #10
RE:
Try my nulled version of this


I have nulled covert viral wizard only. Test it and reply how it is working, then I will post another content wizard plugin nulled




Enter activation code is 1234



Magic Button :
Code:
http://www50.zippyshare.com/v/95928067/file.html
16.gif




53.gif