▶︎ •၊၊||၊|။|||||||• 0:69
393 posts

▶︎ •၊၊||၊|။|||||||• 0:69
@pwnengine
Everything is going wrong like the time I hired that Bangkok prostitute to do my taxes while I fucked my accountant.
127.0.0.1 Katılım Eylül 2022
135 Takip Edilen96 Takipçiler

@GoobulousG @Ac7ionMann I took 60mg first time and nodded off in a casino. No throwing up but I never do even from over a gram dose of mdma (common for others to vomit).
English

@Ac7ionMann Cap, 7oh doesn't make you nod like that. Also if it was your first time and you took 100mg you would've been puking like crazy and super motion sick.
English
▶︎ •၊၊||၊|။|||||||• 0:69 retweetledi

How Kernel Anti-Cheats Work: A Deep Dive into Modern Game Protection
s4dbrd.github.io/posts/how-kern…
#reverse


English

@rahsaa_n @LASHYBILLS It’s real. This happened to me a couple months ago and customers service told me it’s super common. Actually they have a phone option for theft to talk to that departments
English

@oliviakrolczyk_ I’m on fucking steroids and just threw up from eating less than half (guessing) the calories he’s eating in this meal 😂
English

@305soulsnatcher @xDEXXSN @Rothmus He was talking quite loud. That’s a normal person’s louder end of spectrum. Most people aren’t capable of making noises as loud as the woman in the video.
English

@vxunderground The amount of idiots replying that seem to be mad it’s not malware lol. I would never use some shitware like this, but that’s because it’s shitware not malware 🙃
English

People tagged me saying this is malware. It's not malware. It's a false positive.
It's flagged as malware because it functionality present which modifies system components and settings (in the name of gaming, or something) which some malware families may also try to do.
It also has some unusual stuff inside which looks like malware, but it's not.
1. It's 144MB because it's the new fancy .NET "hostfxr" stuff, so it's all bundled together and comes with all the necessary dependencies. Inside of the binary though is an RCData section (custom section) which is (probably) flagged as malware because it contains a .DLL which is (yet another) .NET dependency. However, this is all unironically normal stuff.
2. The binary loads an internal module called "XillyGameMode". XillyGameMode is fancy, has a bunch of fancy graphics, but it ultimately contains a few core services
3. Internal "services"
- "GameDetector" + GameModeService
- MemoryService
- NetworkService
- PowerService
- RegistryService
- UpdateService
Each "service" also has settings associated with it.
4. GameModeService checks for the presence of a bunch of random video games based on their process in-memory string (how they appear in Task Manager). It looks for: Call of Duty, Fortnite, Apex, CS2, Valheim, DOTA2, LoL, Overwatch, Valorant, GTA5, RDR2, Cyberpunk2077, and Minecraft.
If any of these are identified it sets it to focus. In other words, it makes sure it's not in the background of something. This service also functions as the thingie that handles all the other services.
5. MemoryService invokes PSAPI!EmptyWorkSet and attempts to flush unused memory to disk.
6. NetworkService disables multicasting stuff, for DNS stuff, or something. It also disables NetBIOS.
7. PowerService attempts to determine if it's a desktop using Win32_SystemEnclosure from WMI. If it thinks it's a Desktop, it changes power settings to High Performance. If it thinks you're a laptop, or can't determine if it's a Desktop, it tries modifying power read scheme thingies. Some weird power stuff I never cared to look more into.
8. RegistryService modifies registry stuff to give GPU priority, disables explorer.exe restart functionality (???), enables Game Bar auto start stuff
9. UpdateService looks for updates on GitHub. It has some weird update logic by dropping a *.BAT file, but it just kills the current process. There is smarter ways to do this, but whatever.
10. It's not malware. It has malware-like functionality because it changes system settings. I don't think changing some of these things really matters a whole lot, but I'm not a gamer NERD, so I don't know.
Thanks
Xilly@x1lly
I've been gatekeeping this for months. Windows steals 30-40% of your FPS through background bloat. I built a tool that reclaims it in one click. Completely free. No BS. Download: github.com/xillyservices-…
English

▶︎ •၊၊||၊|။|||||||• 0:69 retweetledi
▶︎ •၊၊||၊|။|||||||• 0:69 retweetledi
▶︎ •၊၊||၊|။|||||||• 0:69 retweetledi





























