Ok, first off the download the project64.exe file from this site
http://pj64.emulation64.com/iedefault.htm
and this is the file which it detected a virus in http://pj64.emulation64.com/files/pj64_1_5.exe
and it says that it Contains code of the Windows virus W32/CTX
know for question what is a W32/CTX virus anyway? that things does one of these virus do anyway?
because when using either 1964 and project 64 and using jabo video plugin either jabo (directx version 7 and directx version 6 ) I have too of those plugins still and was this weird little icon in the upper left side of the screen, I was playing a game on my dad's laptop computer and I notice this icon that I don't ever remember seeing in this plugin before, also the virus is not detected in the new file named pj64_1_5_SP1 just only detected in the old file pj64_1_5.exe from this site http://pj64.emulation64.com and yes and download it again from the same site and the virus detecting program called AntiVir Personal Edition still detectes this program that is has a W32/CTX virus stored in it and also when uncompress it detects the virus in the orginal project64.exe file it reads it having a W32/CTX Virus but the patch update seems to be clean of a virus but even with the SP1 patch installed afterwords it still detects this virus type.
so my next question is project64 clean of a virus and is this detecting a virus a real one or is it really a fake virus that is being detected in both the compress file and uncompress one?
the freeware program called AntiVir Personal Edition can be found at http://www.hbedv.com/
next I will paste the log scan of the project64.exe file from the virus scaning program under this
AntiVir®/XP (2000 + NT) Personal Edition v6.20.14.31 of 02.06.2003
VDF file v6.20.0.32 (0) of 07.07.2003
This program is for PERSONAL USE only.
Any other use is PROHIBITED.
Informations regarding commercial versions of AntiVir may be obtained from:
www.hbedv.com.
Scanning for 74557 virus strains and unwanted programs.
Licensed for: AntiVir Personal Edition
Serial number: 0000149996-ADJIE-0001
FUSE: Basic license
Please enter the workstation and
contact name with phone number in this form:
Company ___________________________________________
Department ___________________________________________
Name ___________________________________________
Street ___________________________________________
Town ___________________________________________
Phone/Fax ___________________________________________
EMail ___________________________________________
Platform: Windows NT Workstation
Windows version: 5.1 Build 2600 (Service Pack 1)
Username: Robert
Processor: Pentium
Working memory: 523764 KB free
Version information:
AVEWIN32.DLL : v6.20.0.1 266240 17.06.2003 14:51:30
AVGNT.EXE : v6.20.01.02 118824 22.05.2003 12:04:40
AVGUARD.EXE : v6.20.00.04 180264 16.05.2003 14:20:46
GUARDMSG.DLL : v6.20.00.04 90152 16.05.2003 14:20:46
AVGCMSG.DLL : v6.19.05.04 241704 22.05.2003 12:04:38
AVGNTDD.SYS : v6.20.03.00 39320 15.05.2003 08:45:50
AVPACK32.DLL : v6.20.00.04 409640 08.05.2003 08:41:34
AVGETVER.DLL : v6.15.00.00 73728 31.10.2002 16:18:56
AVWIN.DLL : v6.20.00.03 553000 20.05.2003 10:36:38
AVSHLEXT.DLL : v6.15.00.00 57344 20.08.2002 11:50:04
AVSched32.EXE : v6.15.00.00 106536 19.08.2002 11:58:20
AVSched32.DLL : v6.15.00.00 122880 19.08.2002 11:58:20
AVREG.DLL : v6.19.00.00 41000 21.03.2003 15:10:52
AVRep.DLL : v6.20.00.14 245800 03.07.2003 11:25:48
CTL3D32.DLL : v2.31.000 27136 23.08.2001 12:00:00
MFC42.DLL : v6.00.8665.0 995383 23.08.2001 12:00:00
MSVCRT.DLL : v7.0.2600.1106 (xpsp1.020828-1920
MSVCRT.DLL : v7.0.2600.1106 323072 29.08.2002 03:41:08
CTL3DV2.DLL : No information
Configuration file:
Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI
Name of report file: C:\Program Files\AVPersonal\AVWIN.LOG
Start path: C:\Program Files\AVPersonal
Command line: /S*H*L="C:\Documents and Settings\Robert\Desktop\pj64_1_5.exe"
Start mode: Shell extension
Mode of report file:
[ ] Do not create report
[X] Overwrite report
[ ] Append new report
Data in report file:
[X] Infected files
[ ] Infected files with paths
[ ] All scanned files
[ ] Full information
Abridge report file:
[ ] Abridge report file
Warnings in report:
[X] Access denied/file locked
[X] Wrong file size in directory
[X] Wrong creation time in directory
[ ] COM file is too large
[X] Invalid start address
[X] Invalid EXE header
[X] Possibly damaged
Summary report:
[X] Create summary report
Output file: AVWIN.ACT
Maximum number of entries: 100
Where to search:
[X] Memory
[X] Boot record of selected drives
[ ] Report unknown boot sectors
[ ] All files
[X] Program files
Extensions: .386 .ACM .ADE .ADP .APP .ASP .AWX .AX .BAT .BIN .CDF .CHM .CLASS .CMD .CNV .COM .CPL .CSH .DLL .DLO .DO? .DRV .EML .EXE .FLT .FOT .HLP .HT* .INF .INI .INS .ISP .JS .JSE .LNK .MD? .MDB .MOD .MS? .NWS .OBJ .OCX .OLB .OSD .OV? .PDR .PGM .PIF .PKG .POT .PPS .PPT .PRG .RPL .RTF .SCR .SCRIPT .SCT .SH .SHA .SHB .SHS .SHTM* .SPL .SWF .SYS .TLB .TSP .TTF .VB? .VLM .VXD .VXO .WIZ .WLL .WPC .WSC .WSF .WSH .WWK .XL? .XML
Response in case of a detection:
[X] Repair with prompt
[ ] Repair without prompt
[ ] Delete with prompt
[ ] Delete without prompt
[ ] Write in report file only
[X] Acoustic alarm
Response in case of destroyed files:
[X] Delete with prompt
[ ] Delete without prompt
[ ] Ignore
Response in case of destroyed files:
[X] No change
[ ] Current system time
[ ] Correct date
Suspicious macros:
[ ] Delete all suspicious macros
[ ] Delete all macros if one is suspicious
[X] Confirm action
Convert template:
[ ] Never
[ ] Only .DOC files
[X] Always
[ ] Confirm
[X] Compress format table
Drag&drop settings:
[X] Scan subdirectories
Profile settings:
[X] Scan subdirectories
Archive options
[X] Search archive
[X] All archive types
Miscellaneous options:
Temporary path: %TEMP% -> C:\DOCUME~1\Robert\LOCALS~1\Temp
[X] Overwrite infected files
[ ] Detect idle time
[X] Allow interruptions of scan
[X] Load AVWin®/NT Guard on System start
General settings:
[X] Save options on exiting AntiVir
Priority: medium
Start of scan: 09.07.2003 01:04
Memory test OK
Master boot record of hard disk HD0 OK
Master boot record of hard disk HD1 OK
Boot record of drive C: OK
Boot record of drive C: OK
C:\DOCUMENTS AND SETTINGS\ROBERT\DESKTOP
PJ64_1_5.EXE
ArchiveType: RAR SFX (self extracting)
--> Project64.exe
Contains code of the Windows virus W32/CTX
End of scan: 09.07.2003 01:04
Time taken: 00:01 min
0 directories were scanned
15 files were scanned
0 warning messages were issued
0 files were deleted
0 files were repaired
1 detection
and just to yet you know I have the virus scaning program updated to the newest version that their currently is.
http://pj64.emulation64.com/iedefault.htm
and this is the file which it detected a virus in http://pj64.emulation64.com/files/pj64_1_5.exe
and it says that it Contains code of the Windows virus W32/CTX
know for question what is a W32/CTX virus anyway? that things does one of these virus do anyway?
because when using either 1964 and project 64 and using jabo video plugin either jabo (directx version 7 and directx version 6 ) I have too of those plugins still and was this weird little icon in the upper left side of the screen, I was playing a game on my dad's laptop computer and I notice this icon that I don't ever remember seeing in this plugin before, also the virus is not detected in the new file named pj64_1_5_SP1 just only detected in the old file pj64_1_5.exe from this site http://pj64.emulation64.com and yes and download it again from the same site and the virus detecting program called AntiVir Personal Edition still detectes this program that is has a W32/CTX virus stored in it and also when uncompress it detects the virus in the orginal project64.exe file it reads it having a W32/CTX Virus but the patch update seems to be clean of a virus but even with the SP1 patch installed afterwords it still detects this virus type.
so my next question is project64 clean of a virus and is this detecting a virus a real one or is it really a fake virus that is being detected in both the compress file and uncompress one?
the freeware program called AntiVir Personal Edition can be found at http://www.hbedv.com/
next I will paste the log scan of the project64.exe file from the virus scaning program under this
AntiVir®/XP (2000 + NT) Personal Edition v6.20.14.31 of 02.06.2003
VDF file v6.20.0.32 (0) of 07.07.2003
This program is for PERSONAL USE only.
Any other use is PROHIBITED.
Informations regarding commercial versions of AntiVir may be obtained from:
www.hbedv.com.
Scanning for 74557 virus strains and unwanted programs.
Licensed for: AntiVir Personal Edition
Serial number: 0000149996-ADJIE-0001
FUSE: Basic license
Please enter the workstation and
contact name with phone number in this form:
Company ___________________________________________
Department ___________________________________________
Name ___________________________________________
Street ___________________________________________
Town ___________________________________________
Phone/Fax ___________________________________________
EMail ___________________________________________
Platform: Windows NT Workstation
Windows version: 5.1 Build 2600 (Service Pack 1)
Username: Robert
Processor: Pentium
Working memory: 523764 KB free
Version information:
AVEWIN32.DLL : v6.20.0.1 266240 17.06.2003 14:51:30
AVGNT.EXE : v6.20.01.02 118824 22.05.2003 12:04:40
AVGUARD.EXE : v6.20.00.04 180264 16.05.2003 14:20:46
GUARDMSG.DLL : v6.20.00.04 90152 16.05.2003 14:20:46
AVGCMSG.DLL : v6.19.05.04 241704 22.05.2003 12:04:38
AVGNTDD.SYS : v6.20.03.00 39320 15.05.2003 08:45:50
AVPACK32.DLL : v6.20.00.04 409640 08.05.2003 08:41:34
AVGETVER.DLL : v6.15.00.00 73728 31.10.2002 16:18:56
AVWIN.DLL : v6.20.00.03 553000 20.05.2003 10:36:38
AVSHLEXT.DLL : v6.15.00.00 57344 20.08.2002 11:50:04
AVSched32.EXE : v6.15.00.00 106536 19.08.2002 11:58:20
AVSched32.DLL : v6.15.00.00 122880 19.08.2002 11:58:20
AVREG.DLL : v6.19.00.00 41000 21.03.2003 15:10:52
AVRep.DLL : v6.20.00.14 245800 03.07.2003 11:25:48
CTL3D32.DLL : v2.31.000 27136 23.08.2001 12:00:00
MFC42.DLL : v6.00.8665.0 995383 23.08.2001 12:00:00
MSVCRT.DLL : v7.0.2600.1106 (xpsp1.020828-1920
MSVCRT.DLL : v7.0.2600.1106 323072 29.08.2002 03:41:08
CTL3DV2.DLL : No information
Configuration file:
Name of configuration file: C:\Program Files\AVPersonal\AVWIN.INI
Name of report file: C:\Program Files\AVPersonal\AVWIN.LOG
Start path: C:\Program Files\AVPersonal
Command line: /S*H*L="C:\Documents and Settings\Robert\Desktop\pj64_1_5.exe"
Start mode: Shell extension
Mode of report file:
[ ] Do not create report
[X] Overwrite report
[ ] Append new report
Data in report file:
[X] Infected files
[ ] Infected files with paths
[ ] All scanned files
[ ] Full information
Abridge report file:
[ ] Abridge report file
Warnings in report:
[X] Access denied/file locked
[X] Wrong file size in directory
[X] Wrong creation time in directory
[ ] COM file is too large
[X] Invalid start address
[X] Invalid EXE header
[X] Possibly damaged
Summary report:
[X] Create summary report
Output file: AVWIN.ACT
Maximum number of entries: 100
Where to search:
[X] Memory
[X] Boot record of selected drives
[ ] Report unknown boot sectors
[ ] All files
[X] Program files
Extensions: .386 .ACM .ADE .ADP .APP .ASP .AWX .AX .BAT .BIN .CDF .CHM .CLASS .CMD .CNV .COM .CPL .CSH .DLL .DLO .DO? .DRV .EML .EXE .FLT .FOT .HLP .HT* .INF .INI .INS .ISP .JS .JSE .LNK .MD? .MDB .MOD .MS? .NWS .OBJ .OCX .OLB .OSD .OV? .PDR .PGM .PIF .PKG .POT .PPS .PPT .PRG .RPL .RTF .SCR .SCRIPT .SCT .SH .SHA .SHB .SHS .SHTM* .SPL .SWF .SYS .TLB .TSP .TTF .VB? .VLM .VXD .VXO .WIZ .WLL .WPC .WSC .WSF .WSH .WWK .XL? .XML
Response in case of a detection:
[X] Repair with prompt
[ ] Repair without prompt
[ ] Delete with prompt
[ ] Delete without prompt
[ ] Write in report file only
[X] Acoustic alarm
Response in case of destroyed files:
[X] Delete with prompt
[ ] Delete without prompt
[ ] Ignore
Response in case of destroyed files:
[X] No change
[ ] Current system time
[ ] Correct date
Suspicious macros:
[ ] Delete all suspicious macros
[ ] Delete all macros if one is suspicious
[X] Confirm action
Convert template:
[ ] Never
[ ] Only .DOC files
[X] Always
[ ] Confirm
[X] Compress format table
Drag&drop settings:
[X] Scan subdirectories
Profile settings:
[X] Scan subdirectories
Archive options
[X] Search archive
[X] All archive types
Miscellaneous options:
Temporary path: %TEMP% -> C:\DOCUME~1\Robert\LOCALS~1\Temp
[X] Overwrite infected files
[ ] Detect idle time
[X] Allow interruptions of scan
[X] Load AVWin®/NT Guard on System start
General settings:
[X] Save options on exiting AntiVir
Priority: medium
Start of scan: 09.07.2003 01:04
Memory test OK
Master boot record of hard disk HD0 OK
Master boot record of hard disk HD1 OK
Boot record of drive C: OK
Boot record of drive C: OK
C:\DOCUMENTS AND SETTINGS\ROBERT\DESKTOP
PJ64_1_5.EXE
ArchiveType: RAR SFX (self extracting)
--> Project64.exe
Contains code of the Windows virus W32/CTX
End of scan: 09.07.2003 01:04
Time taken: 00:01 min
0 directories were scanned
15 files were scanned
0 warning messages were issued
0 files were deleted
0 files were repaired
1 detection
and just to yet you know I have the virus scaning program updated to the newest version that their currently is.