Noport; that could easily be faked and also if I were to hijack a known dll to insert a virus, I'd change as little as possible.
http://www.telerik.com/products/decompiler.aspx would actually show the code that would be run. .Net binaries are very very easily decompiled, even when run through an obfuscator.
But the point is, the current version only links to these compiled binaries:
https://github.com/EQEmu/EQExtractor/tree/master/lib
The dll's mentioned are well known and used binaries by name, but it doesn't mean the actual versions he downloaded arent compromised.
To state;
there is no currently working version of EQExtractor available,the latest version is 4 months worth of patches out of date.
Sony were patching and changing the structs at least once a week and so by the time I got it working again, they broke it., so I never bothered releasing binaries. I never did (re-)crack the merchant lists so I don't think anyone was particularly interested in using it.