|
You last visited: Today at 04:39
Advertisement
Script Vessel Final Analysis
Discussion on Script Vessel Final Analysis within the CO2 Bots & Macros forum part of the Conquer Online 2 category.
01/07/2007, 18:34
|
#1
|
elite*gold: 0
Join Date: Jun 2005
Posts: 291
Received Thanks: 160
|
This is for Mr.Rattlz Cracked Script Vessel Release.
File Scan.
File: ScriptVessel.zip
Status:
POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.)
MD5 f7c228717c06c8c5195cab5c10fad94d
Packers detected: PE_PATCH.UPX, UPX, ASPROTECT
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found Win32:Crypto
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found Possibly a new variant of W32/Internet-Trojan-patched-based!Maximus
F-Secure Anti-Virus
Found nothing
Fortinet
Found PossibleThreat!019139
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
Virus Information
Win32.Crypto
This text was written with the help of Adrian Marinescu, GeCAD Software.
This is a very dangerous memory resident parasitic polymorphic Win32 virus about 20K in length. It infects KERNEL32.DLL and PE EXE files: it writes its code to the end of the file and modifies necessary fields in the PE header to gain control when an infected file is run. The virus also adds its "droppers" to archives of different types (ACE, RAR, ZIP, CAB, ARJ) and to some types of self-extracting packages (SFX ACE and RAR files).
The virus uses a polymorphic engine while infecting PE EXE files and archives only, and leaves the virus image non-encrypted in the KERNEL32.DLL file.
The virus uses anti-debugging tricks, disables anti-virus on-access scanners (Avast, AVP, AVG and Amon), deletes anti-virus data files (AVP.CRC, IVP.NTZ, ANTI-VIR.DAT, CHKLIST.MS, CHKLIST.CPS, SMARTCHK.MS, SMARTCHK.CPS, AGUARD.DAT, AVGQT.DAT), patches the LGUARD.VPS file (anti-virus database?), and avoids infection of many anti-virus programs: TB, F-, AW, AV, NAV, PAV, RAV, NVC, FPR, DSS, IBM, INOC, ANTI, SCN, VSAF, VSWP, PANDA, DRWEB, FSAV, SPIDER, ADINF, SONIQUE, SQSTART.
One of the most important virus features is the fact that it encrypts/decrypts "on-the-fly" Windows libraries (DLL files) when they are loaded - upon loading a library, the virus decrypts it, an upon unloading, the virus encrypts the file body. To encrypt DLL files, the virus uses strong cryptographic algorithms (provided by Crypt API included in Windows). As a result, once infected system keeps working only in the case the virus code is present in the memory and realizes this encryption/decryption. In case the system is disinfected, the DLL libraries stay encrypted, and the system cannot load them. The first virus to use such technology was Onehalf multipartite virus that was "well known" in the second half of the 1990s.
The virus is incompatible with several Win32 versions, such as Win95 and Win98 standard editions. Under these conditions, the virus does not install itself into the system (does not infect KERNEL32.DLL) and/or does not PE EXE infect files.
Possible Keylogger in countrymakeinUS.dll
A scan from  shows a possible keylogger in countrymakeinUS.dll
However, I dont believe there is any risk with this as it probably the feature used to get item and monster names from conquer.
Final Report
So far I have had no problems with this software, And the 'Viruses' don't seem to be much of a problem. My theory is that Win32:Crypto is used to encrypt countrymakeinUS.dll to protect the program from being cracked. (Need verification).
All-in-all its up to you to decide what you wish to do if you acquire this program.
Any more information will be amended. Beyond this point with the date and time. If you have any information to add PM me.
Quote:
|
The "viruses" are part of ASProtect, used for anti-debugging(says in Crypto desc.)
|
|
|
|
01/07/2007, 18:40
|
#2
|
elite*gold: 0
Join Date: Jan 2006
Posts: 15
Received Thanks: 0
|
0___0 is this REALL? if it is then o wells i never got a copy of it
|
|
|
01/07/2007, 19:21
|
#3
|
elite*gold: 0
Join Date: Jan 2007
Posts: 30
Received Thanks: 0
|
wow, i guess it will be just a matter of time until pple starts losing items
|
|
|
01/07/2007, 20:18
|
#4
|
elite*gold: 0
Join Date: Jul 2005
Posts: 426
Received Thanks: 15
|
well guess what noone will lose items cuz i scaned the older SV before the patch it showed the same **** as now, and still noone lost theyre acc, so you nubs can stop eorrying and trying to be smart <comment excludes lupurus and other programmers....the only ones who lost theyre acnts were Rtards who cant read or scan and got keyloggers from newb posters.
|
|
|
01/07/2007, 20:39
|
#5
|
elite*gold: 0
Join Date: Jul 2006
Posts: 36
Received Thanks: 0
|
Quote:
Originally posted by ftho@Jan 7 2007, 20:18
well guess what noone will lose items cuz i scaned the older SV before the patch it showed the same **** as now, and still noone lost theyre acc, so you nubs can stop eorrying and trying to be smart <comment excludes lupurus and other programmers....the only ones who lost theyre acnts were Rtards who cant read or scan and got keyloggers from newb posters.
|
Lol, you can tell them 2,000,000,000,000,000,000 ****** times, and yet they still will cry about it ^^
|
|
|
01/07/2007, 21:02
|
#6
|
elite*gold: 0
Join Date: Dec 2006
Posts: 181
Received Thanks: 21
|
why dont u trust dm and rattlz???? why would dm corrupt her own forums???, if u can't trust dm and mr.rattlz, then u should'nt be on this forum........ i trust them and i'll keep using sv, and if u can't trust them??? then who can u trust?................ thats all i got to say
|
|
|
01/07/2007, 21:13
|
#7
|
elite*gold: 0
Join Date: Jul 2006
Posts: 25
Received Thanks: 0
|
Can I see the file?
|
|
|
01/07/2007, 21:24
|
#8
|
elite*gold: 0
Join Date: Dec 2006
Posts: 181
Received Thanks: 21
|
why would u want to see the file just so u coudl download it?
|
|
|
01/07/2007, 21:25
|
#9
|
elite*gold: 0
Join Date: Jan 2006
Posts: 189
Received Thanks: 6
|
Quote:
Originally posted by GreenPencil@Jan 7 2007, 21:02
why dont u trust dm and rattlz???? why would dm corrupt her own forums???, if u can't trust dm and mr.rattlz, then u should'nt be on this forum........ i trust them and i'll keep using sv, and if u can't trust them??? then who can u trust?................ thats all i got to say
|
Agree with u, they won`t be hacking accs. I`ll keep on useing sv too. And these peoples who dont trust admins i think will never get cracked version
|
|
|
01/07/2007, 21:25
|
#10
|
elite*gold: 20
Join Date: Apr 2006
Posts: 1,341
Received Thanks: 886
|
Quote:
Originally posted by lupurus@Jan 7 2007, 18:34
So far I have had no problems with this software, And the 'Viruses' don't seem to be much of a problem. My theory is that Win32:Crypto is used to encrypt countrymakeinUS.dll to protect the program from being cracked. (Need verification).
|
The "viruses" are part of ASProtect, used for anti-debugging(says in Crypto desc.).
|
|
|
01/07/2007, 21:28
|
#11
|
elite*gold: 0
Join Date: Jun 2005
Posts: 291
Received Thanks: 160
|
Quote:
Originally posted by GreenPencil@Jan 7 2007, 21:02
why dont u trust dm and rattlz???? why would dm corrupt her own forums???, if u can't trust dm and mr.rattlz, then u should'nt be on this forum........ i trust them and i'll keep using sv, and if u can't trust them??? then who can u trust?................ thats all i got to say
|
Maybe you havent perfected the skill of reading. So I will do it for you.
1. The program has viruses.
I told which viruses.
2. People want to know why there are viruses.
I told them why.
3. People want to know if the viruses are harmful.
I showed them that they arent.
So where in my post about backing up rattlz and dm2000 did I call them untrustworthy?
Perhaps if you read the full post you would have seen the part where I wrote what the 'viruses' do and how the dont affect you.
And to make sure this dosent happen again
|
|
|
01/07/2007, 21:29
|
#12
|
elite*gold: 0
Join Date: Jun 2005
Posts: 291
Received Thanks: 160
|
Quote:
Originally posted by andyd123+Jan 7 2007, 21:25--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (andyd123 @ Jan 7 2007, 21:25)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin--lupurus@Jan 7 2007, 18:34
So far I have had no problems with this software, And the 'Viruses' don't seem to be much of a problem. My theory is that Win32:Crypto is used to encrypt countrymakeinUS.dll to protect the program from being cracked. (Need verification).
|
The "viruses" are part of ASProtect, used for anti-debugging(says in Crypto desc.). [/b][/quote]
Thanks +k to you
|
|
|
01/07/2007, 21:30
|
#13
|
elite*gold: 0
Join Date: Apr 2006
Posts: 317
Received Thanks: 10
|
Lol why would they **** over the senior members of EPVP, this is fake.
|
|
|
01/07/2007, 21:32
|
#14
|
elite*gold: 0
Join Date: Jun 2005
Posts: 291
Received Thanks: 160
|
How is it fake? When scanned the file is shown as infected. Ive proved that it is safe. How is that 'fake'?
|
|
|
01/07/2007, 21:37
|
#15
|
elite*gold: 0
Join Date: May 2005
Posts: 476
Received Thanks: 1
|
The version I have (not rattlz's crack) comes up clean (both files). I very highly doubt that rattlz would try to pull anything though...being lvl 3, I don't think he would throw all that away for something as monotonous as CO..
|
|
|
Similar Threads
|
Script Vessel
07/22/2008 - Conquer Online 2 - 5 Replies
I was searching for prices, or at least the official site, but when I got there...
http://img232.imageshack.us/img232/3710/svgreenpj 1.jpg
What's wrong?
|
Script vessel
12/20/2007 - Conquer Online 2 - 1 Replies
Does anyone have a cracked sv for the 5006 patch?
|
Script Vessel
07/08/2007 - Conquer Online 2 - 5 Replies
can someone tell me if theres a new Script Vessel that works for the latest patch 4351?
|
All times are GMT +1. The time now is 04:40.
|
|