Font edit fix for 4346+

04/28/2007 00:01 Matt.dk#1
I have discovered that the new 4346 conquer.exe has a simple hash table that it uses to run a CRC check against the font.ini file. If it does not match, CO crashes. Attached to this post is the v4345 conquer.exe file which will allow you to edit fonts again. :bandit:

The file is clean, feel free to scan.

+k is always appreciated but never required. :)

Wow, the epvpers uploader is very gay... My hacking community is nearly just as busy and we limit to 2mb attachments, not 300kb lol... Why the hell would you limit to a 300kb attachment? That is useless...

conquer4345 exe rapidshared: [Only registered and activated users can see links. Click Here To Register...]
04/28/2007 00:47 coolboy0286#2
Code:
Complete scanning result of "Conquer.exe", received in VirusTotal at 04.28.2007, 00:38:29 (CET).

Antivirus	Version	Update	Result
AhnLab-V3	2007.4.28.0	04.27.2007	no virus found
AntiVir	7.4.0.15	04.27.2007	no virus found
Authentium	4.93.8	04.27.2007	no virus found
Avast	4.7.981.0	04.26.2007	no virus found
AVG	7.5.0.464	04.26.2007	no virus found
BitDefender	7.2	04.28.2007	no virus found
CAT-QuickHeal	9.00	04.27.2007	no virus found
ClamAV	devel-20070416	04.27.2007	no virus found
DrWeb	4.33	04.27.2007	no virus found
eSafe	7.0.15.0	04.27.2007	suspicious Trojan/Worm
eTrust-Vet	30.7.3601	04.27.2007	no virus found
Ewido	4.0	04.27.2007	no virus found
FileAdvisor	1	04.28.2007	no virus found
Fortinet	2.85.0.0	04.27.2007	suspicious
F-Prot	4.3.2.48	04.27.2007	no virus found
F-Secure	6.70.13030.0	04.28.2007	no virus found
Ikarus	T3.1.1.5	04.27.2007	no virus found
Kaspersky	4.0.2.24	04.28.2007	no virus found
McAfee	5019	04.27.2007	no virus found
Microsoft	1.2405	04.27.2007	no virus found
NOD32v2	2225	04.27.2007	no virus found
Norman	5.80.02	04.27.2007	no virus found
Panda	9.0.0.4	04.27.2007	no virus found
Prevx1	V2	04.28.2007	no virus found
Sophos	4.16.0	04.23.2007	no virus found
Sunbelt	2.2.907.0	04.19.2007	no virus found
Symantec	10	04.28.2007	no virus found
TheHacker	6.1.6.095	04.15.2007	no virus found
VBA32	3.11.4	04.27.2007	no virus found
VirusBuster	4.3.7:9	04.27.2007	no virus found
Webwasher-Gateway	6.0.1	04.27.2007	no virus found

Aditional Information
File size: 393728 bytes
MD5: 9d2633f470d718990bbc624b154823c8
SHA1: ee141bf4671a6f35b4b6d32759f6f60c580e6ae7
packers: UPX
packers: UPX
packers: UPX
04/28/2007 01:02 Matt.dk#3
Looks clean to me accept for this.
Quote:

eSafe 7.0.15.0 04.27.2007 suspicious Trojan/Worm
Try unpacking conquer.exe and re scanning the file and it will be 100% clean. you have a single result amongst 30 or so scanners? I smell a false positive due to the UPX packing used on conquer.exe by TQ. Again unpack and rescan.
04/28/2007 01:19 coolboy0286#4
Code:
Complete scanning result of "Conquer.exe", received in VirusTotal at 04.28.2007, 01:14:16 (CET).

Antivirus	Version	Update	Result
AhnLab-V3	2007.4.28.0	04.27.2007	no virus found
AntiVir	7.4.0.15	04.27.2007	no virus found
Authentium	4.93.8	04.27.2007	no virus found
Avast	4.7.981.0	04.26.2007	no virus found
AVG	7.5.0.464	04.26.2007	no virus found
BitDefender	7.2	04.28.2007	no virus found
CAT-QuickHeal	9.00	04.27.2007	no virus found
ClamAV	devel-20070416	04.27.2007	no virus found
DrWeb	4.33	04.27.2007	no virus found
eSafe	7.0.15.0	04.27.2007	no virus found
eTrust-Vet	30.7.3601	04.27.2007	no virus found
Ewido	4.0	04.27.2007	no virus found
FileAdvisor	1	04.28.2007	no virus found
Fortinet	2.85.0.0	04.27.2007	suspicious
F-Prot	4.3.2.48	04.27.2007	no virus found
F-Secure	6.70.13030.0	04.28.2007	no virus found
Ikarus	T3.1.1.5	04.27.2007	no virus found
Kaspersky	4.0.2.24	04.28.2007	no virus found
McAfee	5019	04.27.2007	no virus found
Microsoft	1.2405	04.27.2007	no virus found
NOD32v2	2225	04.27.2007	no virus found
Norman	5.80.02	04.27.2007	no virus found
Panda	9.0.0.4	04.27.2007	no virus found
Prevx1	V2	04.28.2007	no virus found
Sophos	4.16.0	04.23.2007	no virus found
Sunbelt	2.2.907.0	04.19.2007	no virus found
Symantec	10	04.28.2007	no virus found
TheHacker	6.1.6.095	04.15.2007	no virus found
VBA32	3.11.4	04.27.2007	no virus found
VirusBuster	4.3.7:9	04.27.2007	no virus found
Webwasher-Gateway	6.0.1	04.27.2007	Win32.Vulnerable.gen!High (suspicious)

Aditional Information
File size: 1265664 bytes
MD5: 65dffd4df2e940de16151df7bda94e1e
SHA1: 63239af28c4f59a66c6e32e8d76123d4b8dd9058
ya lost one and ya gained one, lol kinda evens out
04/28/2007 01:46 Matt.dk#5
Again the mark of a false positive. take your own conquer.exe and scan it.

By the way its common knowledge that Webwasher-Gateway is a new virus scanner that is currently going nuts on almost any file you scan it with. :P
04/28/2007 02:14 skyline_supra#6
ummm does this replace multiclient????
04/28/2007 02:22 tselek#7
can someone just give the name of the orginal font please???
04/28/2007 03:08 DM2000#8
Hi,

If you want the original old patch, you could visit Linklist at my signature.
There is a link to FTP (last section) where you could get back all the old version of CO patch.

*Edit - Change the .exe to .rar and use Winrar (in linklist) to open. Select the specific file that you would like to extract

DM :star:
04/28/2007 03:55 Ultidrag#9
Hmmm, i must be dumb, i pasted the file into the conquer folder and CO wont open at all...
04/28/2007 06:48 okoro300#10
i have a simple question regarding a much simpler.. fix can anyone give me the other fonts they used to edit conquer before this patch? other then
ËÎÌå somthing that i can actually write font in lol this is chinese and i dont have this on microsoft word thx ...
04/28/2007 07:37 imneveral0ne#11
yeah this doesnt open for me...
04/28/2007 07:47 nils66#12
where shall i copy the file to?
04/28/2007 08:11 MyStIcWiZaRd#13
sow, I want the old font back, before that fat one...
I have the font file, but if I paste it in my ini folder, co doesnt start...
then I extracted the new patch again and everything works again... but my font doesnt change :?
Anyone can help me? :)
04/28/2007 08:17 imneveral0ne#14
the exact same thing is happening to me
04/28/2007 08:39 Lord_Vampy#15
Yeah if you can give more information on how to use this it would be greatly appreciated. Also, does it replace your multi client?