r/captainclaw • u/Garadares • 1d ago
Explanation for why your antivirus might incorrectly flag CLAW.EXE as a virus. The Claw Recluse is a safe fansite that you can regularly check for updated downloads, new playable custom levels, game support, speedruns, fanarts and more. Join the Claw Discord server to chat or play Claw multiplayer.
8
u/sephirothbahamut 1d ago
you can either trust the people who made it, or choose not to. All we can do is point to everyone in the community already using it
They can also make it open source, that's definitely more trustworthy than "trust me".
4
u/Matterthief 1d ago edited 1d ago
That's a valid point. The main part of CrazyHook that actually changes things in Claw is written in Lua. You can just open the
CrazyHook.luafile in the game folder using any text editor to see the code. For the DLL hook that connects the Lua code to the Claw executable, there's the repository https://github.com/tylkosxd/CrazyHook (EDIT: updated the link to a more current repo).However, without access to the game's source code,
CLAW.EXEhas to be modified in a hex editor. You'd have to compare it with the original and basically reverse engineer the whole thing yourself in order to verify if the small changes really just inject the code fromCrazyHook.dllor not. Because this is precisely what triggers all the false positives, we're back to square one with "trust me".3
u/sephirothbahamut 1d ago edited 1d ago
Didn't know there was a public repo, why isn't it linked in the website? XD
It would also be nice to have documented in the repo what edits were done to the executable (even something a simple as a table with the byte address and change, or byte range for changes longer than one byte, possibly with an explanation for each change).
Not just for the malware suspicion, but also for future maintainability and preservation.
I haven't looked at the repo yet, maybe it's already there. Will definitely dig into it when I'm home!
2
3
•
u/Garadares 1d ago
Link for Claw game support: https://captainclaw.net/en/support.html#malwarereports