Quote:
Originally posted by user751139@Oct 20 2005, 12:11
This is what i got:
Conquer_Partner_Full__cracked_.zip
clear
Conquer_Partner_Full__cracked_.zip/id
clear
Conquer_Partner_Full__cracked_.zip/S3DHook.dll
clear
Conquer_Partner_Full__cracked_.zip/TQprogram.exe
infected - Win32:Crypto
here's some info on Win32:Crypto
[Only registered and activated users can see links. Click Here To Register...]
|
I checked my system for that Win32:Crypto virus, and I haven't found any trace of it, nor any registry keys that it uses.
That Crypto virus works by hooking into the Kernel32.dll and infecting it and other DLLs. For Conquer Partner to work, it has to hook into Kernel32.dll so it can load its S3DHook.dll into the Conquer process. They are similar in function, yet Conquer Partner does not cause any harm that I've seen.
These virus scanners are using various heuristics to scan for the Crypto virus before it infects the system (such as finding programs that use LoadLibrary and FreeLibrary hooks). It is not fool-proof detection.
However, if you don't trust these files, then you don't have to use them. I've looked through almost every part of the code, and I didn't see anything that resembles a virus, and there isn't really anything I can do to, at the moment, that can make these files seem safe or unsuspicious, but as I said, if you don't trust it, then I suggest not using it.