Trojan Found in Setup.exe on Build 16385 x86 ISO Image!

Page 1 of 2 12 LastLast

  1. Posts : 21
    Peanut Butter & Jelly.
       #1

    Trojan Found in Setup.exe on Build 16385 x86 ISO Image!


    Well, maybe that LeBlanc fellow had a point about bogus ISO images. I just fired up setup.exe from an image of the x86 Build 7600.16385 leak under my current build 7264 installation and look what Microsoft Security Essentials found (see attached image).

    Note: The ISO in question has the following Filename and Hash Info:

    7600.16385.090713-1255_x86fre_client_en-us_Retail_Ultimate-GRMCULFRER_EN_DVD.iso
    SHA1: 2ebdb1f65fbf5aaf38d4fb39ea4e658389a25ea3
    MD5: b49d1c065de9be078abe5bbafc5a304d
    CRC32: 65b9f574

    So, I guess we all still need to be careful after all. Needless to say, stay FAR AWAY from this image.

    RCK
    Attached Thumbnails Attached Thumbnails Trojan Found in Setup.exe on Build 16385 x86 ISO Image!-trojan.png  
      My Computer


  2. Posts : 449
    Windows 7 RTM Ultimate - Activated (Technet)
       #2

    rck01 said:
    Well, maybe that LeBlanc fellow had a point about bogus ISO images. I just fired up setup.exe from an image of the x86 Build 7600.16385 leak under my current build 7264 installation and look what Microsoft Security Essentials found (see attached image).

    Note: The ISO in question has the following Filename and Hash Info:

    7600.16385.090713-1255_x86fre_client_en-us_Retail_Ultimate-GRMCULFRER_EN_DVD.iso
    SHA1: 2ebdb1f65fbf5aaf38d4fb39ea4e658389a25ea3
    MD5: b49d1c065de9be078abe5bbafc5a304d
    CRC32: 65b9f574

    So, I guess we all still need to be careful after all. Needless to say, stay FAR AWAY from this image.

    RCK
    Did you check that the hash values match what was quoted....do those hash values match others that are easilly found out there?

    The good thing is that Microsoft Security Essentials found it I guess.
    As with all the leaks up till now....it is always best to check them thoroughly before installing...as you have found.
      My Computer


  3. Posts : 5,807
    Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
       #3

    This is strange...When I thorughly tested this build MSE popped up with nothing...where did you get the build from...there are alot of fakes flying around...
      My Computer


  4. Posts : 21
    Peanut Butter & Jelly.
    Thread Starter
       #4

    I'm normally pretty careful...


    ...about this sort of thing. In fact, I checked the hash values for the x64 build I installed on my Lenovo W700ds and they matched up fine. I guess I just got lazy with this build - the x86 version was so hard to find, and there were so many different permutations (assembled from either the Chinese dude or Wzor), that when I finally did get a working torrent I assumed any hash mismatches were the result of too many copies from too many sources. That, and it runs just fine under VMware Workstation - version stamps on explorer.exe and others looked good (7600.16385). No real reason to doubt it was a working build...until now!

    Oh well, lesson learned!

    RCK
      My Computer


  5. Posts : 5,807
    Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
       #5

    rck01 said:
    ...about this sort of thing. In fact, I checked the hash values for the x64 build I installed on my Lenovo W700ds and they matched up fine. I guess I just got lazy with this build - the x86 version was so hard to find, and there were so many different permutations (assembled from either the Chinese dude or Wzor), that when I finally did get a working torrent I assumed any hash mismatches were the result of too many copies from too many sources. That, and it runs just fine under VMware Workstation - version stamps on explorer.exe and others looked good (7600.16385). No real reason to doubt it was a working build...until now!

    Oh well, lesson learned!

    RCK
    Hey no big deal...The fact you posted your results and you tried to warn people overshadows the mistake...well done for spending the time to post
      My Computer


  6. Posts : 6,305
    Windows 7 Ultimate x64
       #6

    The main issue is that because there was never an actual ISO released the hash values can change all over the gaff so tracing it is like trying to find a needle in a hay stack (so to say).

    Unfortunately, as you say
    lesson learned!
      My Computer


  7. Posts : 11,840
    64-bit Windows 8.1 Pro
       #7

    I guess the moral of the story is ..... The price of freedom is vigilance...
      My Computer


  8. Posts : 21
    Peanut Butter & Jelly.
    Thread Starter
       #8

    Very weird!


    @Zidane24,

    Well, I just re-scanned setup.exe directly on my x64 system and, again, it got a hit on the Trojan. You're saying you've used this same build without incident? Very odd, indeed! I'm going to fire-up that VM I tested it in originally (prior to launching it directly on its intended upgrade target, my HP Mini 2140) and see if installed MSE into the "infected" VM triggers another hit.

    RCK
      My Computer


  9. Posts : 20
    Windows 7
       #9

    If I installed it, Will a antivirus search find it still?
      My Computer


  10. Posts : 168
    Windows 7 Build 7600.16385 (Clean Install)
       #10

    People need to be careful and get there builds from a reputable source. If you just grab any old iso from the internet with a build number your gonna get grief.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 02:25.
Find Us