Antivir: Nothing found ArcaVir: Nothing found Avast: Nothing found AVG: Nothing found BitDefender: Nothing found ClamAV: Nothing found F-Prot: Nothing found Norman: Nothing found Rising: Nothing found VirusBlokAda32: Nothing found VirusBuster: Nothing found
I really don't get those stupid virus scan posts, its false reassurance for all the noobs.Anyone can just fake a virus report, therefore none of those reports mean a thing, you have to scan the file yourself.
No such thing as a multi client +9 exists either. From what i know, the "+" system is used for game trainers, showing how many functions a trainer has. I don't see why you would embed 9 extra functions into a multi-client when its better practice to just make 9 separate standalone programs, since its a mmo.
In my humble opinion, I'd say its some form of malware .
Additional information
File size: 1548288 bytes
MD5: b16c0ed9d6496dfe7893b8dc6a20a3f5
SHA1: 90f586202746538d1db8ab3ce44cbeb1aafe8e6d
packers: Themida
Prevx info:
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.
Here's a Spanish translation of what MemScanBackdoor.VB.EV is>>>
Quote:
> INFORMATION
This one troyano does not propagate by itself. It can arrive at the computer via manual copy in the system, or at the unloaded being intentionally or by means of deceits of some malicious site, or networks of interchange of archives P2P, disguised generally like an application.
> CHARACTERISTIC
A malintencionado user, also could massively send the troyano to his victim in an individual electronic message or by means of Spam to other users.
When executing itself he opens a back door that allows a remote user to take the total control from the infected equipment.
He uses ports TCP/1040, 1041 and 1043 by defect, but he can form itself to use others.
He can create several archives in the folder of the system of Windows, some with attributes of single reading (+R), system (+S) and hidden (+H). Some examples:
It creates some of the following entrances in the registry to autoejecutar itself in each resumption of Windows:
HKCU Software Microsoft Windows CurrentVersion Run
[name] = [name and way of feasible]
HKCU Software Microsoft Windows NT CurrentVersion Windows
run = [name and way of feasible]
HKLM SOFTWARE Microsoft Windows CurrentVersion Run
[name] = [name and way of feasible]
HKLM SOFTWARE Microsoft Windows CurrentVersion RunServices
[name] = [name and way of feasible]
Where [name] can be a value of the following ones (among others):
ravmond
svchost
system
winlogon
[name of feasible]
The troyano allows the following actions, among others:
To accede to the archives of the infected equipment.
It activates and it deactivates the equipment, it suspends it or it extinguishes.
Flock archives and formatea the hard disk.
Capture information of the configuration of the servant and the workstations.
Capture keys digitadas by the user.
To also capture screens and video (if webcam exists one).
Control of Remote Access of the archives and programs of the attacked systems.
It controls peripheral like mouse, CD/DVD drivers, monitor, etc.
To quiet unload, to install and to execute other programs.
It sends mail messages from the equipment infected through bookstores MAPI.
To listen by the microphone of the system.
To modify the configurations by defect of the Internet Explorer.
It can send commandos through Chat.
It robs keys of access and numbers of credit cards.
> INSTRUCTIONS TO ELIMINATE IT
1. Deactivate the automatic restoration in Windows XP/ME.
2. Reinitiate on approval in Way of failures.
3. Execute an updated antivirus and you take note from the archives infected before eliminating them.
4. Eliminate under the column “Name”, (s) the entrance (s) which they make reference to of the names written down in step 3, in the following keys of the registry:
HKCU Software Microsoft
Windows CurrentVersion
Run
Now I also find it funny that the person (alaa_a, 0 posts) giving the thanks is a new member, singed up the same day as drbetamax. Also the only other post made by (drbetamax, 2 posts) had the same scan as this one did. That thread was closed too. Now if you looked at his profile you would find that there was posted another program in his siggy that comes up even dirtier then the two programs in two threads.
conquer online multi client 10/18/2009 - CO2 Exploits, Hacks & Tools - 10 Replies Ok guys this is my first ever multi client it has a bug the fps is Iaeps.Well guys have fun this is for all my friends on conquer online....have fun