 | | Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks. | Windows 7 - Trojan.VB.VZO
|
07-23-2009
|
#1 | | |
Trojan.VB.VZO Anybody know anything about Trojan.VB.VZO? Couldn't get anything useful from Bing or Google other than a couple of "i seen it"s. It's suddenly now being flagged in an installation Zip archive for Next Up!'s Natural Voices' Audrey (yes, my car's MP3 player is a gorgeous British Lass, so sue me!). Thing is, Ive installed this from Winzip several times over many years. Only now I got a hit on a scan.
What is the potential damage? I guess I'm about to reload everything over again (except this!)  . | My System Specs | | System Manufacturer/Model Number Custom workstation /// Lenovo X61t tablet notebook OS Windows 7 RTM x64 CPU Core i7 980X @ 4.04GHz OC /// Core Duo L7500 @ 1.6GHz Motherboard Asus P6T6 WS Revolution /// Memory 12GB G. Skill @ DDR-1600 OC /// 4GB Graphics Card Saphire HD4870 Toxic 1GB /// Intel Mobile GMA X3100 Monitor(s) Displays Dual Eizo 24" SX2461W /// 12" Screen Resolution 1920x1200 /// 1400x1050 Keyboard Logitech Edge /// Mouse Logitech Wireless Optical Trackball PSU Tagan ITZ 1100 Case GHS-1500 /// Cooling Thermalright IFX-14 + a slew of stealth fans /// Hard Drives Workstation:
5x 750GB Barracuda-11 on Areca ARC-1220;
4x 1.5TB Barracuda-11 on Intel ICH10R;
Volumes:
300GB RAID 0, 2.7TB RAID 10 on Intel;
100GB RAID 0, 1.4TB RAID 10 on Areca ///
Notebook: G.Skill Titan 256GB SSD Internet Speed 5Mbps down / 820Kbps up Other Info Main use: photography;
DVD Drive: L.G GGW-H20L Blu-Ray / DVD;
OC: QPI/DRAM @ 1.33v, CPU @ 1.293v, DRAM Bus @ 1.65v, CPU PLL @ 1.88v, CPU mult = 25x, BCLK = 160, DDR3-1604 @ 7-8-7-24 |
07-23-2009
|
#2 | | |
On the case with no solution yet. But I did find this one and thought it was "cute".
Trojan.VB.Zu blocks access to pornographic web pages based on the sites keywords. Upon visiting one of these sites, Internet Explorer is minimized and a message from the Koran is displayed. | My System Specs | | |
07-23-2009
|
#3 | | |
And, duh. If your scanner got a hit, your AV provider has a definition at their site. | My System Specs | | |
07-23-2009
|
#4 | | |
hopefully a false positive as it comes from a commercial software company?
have you tried submitting zip file to any online scanners?
(sorry if i'm stating the obvious...) | My System Specs | | System Manufacturer/Model Number mickey megabyte 1234 OS ultimate 64 sp1 CPU i5 2500K 3.3@4.2GHz Motherboard MSI P67A-GD53 Memory 8 gigs GSkill Ripjaws 1600 Graphics Card amd hd6950 Sound Card creative x-fi gamer Monitor(s) Displays samsung 24" Screen Resolution 1920x1080 Keyboard saitek eclipse ii Mouse logitech g3 PSU antec 550 Case antec three hundred Cooling i'm a cooling fan Hard Drives ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext Internet Speed about 4 Mbps Other Info i love win7 |
07-23-2009
|
#5 | | |

Quote: Originally Posted by Antman And, duh. If your scanner got a hit, your AV provider has a definition at their site. And zero info other than "it's a trojan!" Gee, thanks! I did Bing & Google - got a hit for Trojan condoms!
Oh no! My porno life is ruined! OK, let me test that one out, see if it's a pseudonym.
Typically, while I understand the backdoor paradigm, how do they normally get activated and used? Is it mostly annoyanceware? I haven't had any unusual behavior, other than some BSODs attributable to shifting OC parameters in the hardware.
The firewall hasn't reported anything like "Trojan.VB.VZO is asking to trash your C: drive [DENY] [ALLOW]".
I always set my FW to no auto rules and no auto training. I get prompted 1st time for everything and it creates the rule based on my response.
I started to upload but it's a 654MB Zip archive, and I have 800Kbs upstream - would take forever ... I'm waiting to get a little more info if possible. | My System Specs | | System Manufacturer/Model Number Custom workstation /// Lenovo X61t tablet notebook OS Windows 7 RTM x64 CPU Core i7 980X @ 4.04GHz OC /// Core Duo L7500 @ 1.6GHz Motherboard Asus P6T6 WS Revolution /// Memory 12GB G. Skill @ DDR-1600 OC /// 4GB Graphics Card Saphire HD4870 Toxic 1GB /// Intel Mobile GMA X3100 Monitor(s) Displays Dual Eizo 24" SX2461W /// 12" Screen Resolution 1920x1200 /// 1400x1050 Keyboard Logitech Edge /// Mouse Logitech Wireless Optical Trackball PSU Tagan ITZ 1100 Case GHS-1500 /// Cooling Thermalright IFX-14 + a slew of stealth fans /// Hard Drives Workstation:
5x 750GB Barracuda-11 on Areca ARC-1220;
4x 1.5TB Barracuda-11 on Intel ICH10R;
Volumes:
300GB RAID 0, 2.7TB RAID 10 on Intel;
100GB RAID 0, 1.4TB RAID 10 on Areca ///
Notebook: G.Skill Titan 256GB SSD Internet Speed 5Mbps down / 820Kbps up Other Info Main use: photography;
DVD Drive: L.G GGW-H20L Blu-Ray / DVD;
OC: QPI/DRAM @ 1.33v, CPU @ 1.293v, DRAM Bus @ 1.65v, CPU PLL @ 1.88v, CPU mult = 25x, BCLK = 160, DDR3-1604 @ 7-8-7-24 |
07-23-2009
|
#6 | | |

Quote: Originally Posted by DJG I did Bing & Google... I would not do that without a Trojan. 
Quote: Originally Posted by DJG But I DO have one! HE-LLOOO! Read the title! You are free to Bing & Google your brains out. | My System Specs | | |
07-23-2009
|
#7 | | |
But I DO have one! HE-LLOOO! Read the title! | My System Specs | | System Manufacturer/Model Number Custom workstation /// Lenovo X61t tablet notebook OS Windows 7 RTM x64 CPU Core i7 980X @ 4.04GHz OC /// Core Duo L7500 @ 1.6GHz Motherboard Asus P6T6 WS Revolution /// Memory 12GB G. Skill @ DDR-1600 OC /// 4GB Graphics Card Saphire HD4870 Toxic 1GB /// Intel Mobile GMA X3100 Monitor(s) Displays Dual Eizo 24" SX2461W /// 12" Screen Resolution 1920x1200 /// 1400x1050 Keyboard Logitech Edge /// Mouse Logitech Wireless Optical Trackball PSU Tagan ITZ 1100 Case GHS-1500 /// Cooling Thermalright IFX-14 + a slew of stealth fans /// Hard Drives Workstation:
5x 750GB Barracuda-11 on Areca ARC-1220;
4x 1.5TB Barracuda-11 on Intel ICH10R;
Volumes:
300GB RAID 0, 2.7TB RAID 10 on Intel;
100GB RAID 0, 1.4TB RAID 10 on Areca ///
Notebook: G.Skill Titan 256GB SSD Internet Speed 5Mbps down / 820Kbps up Other Info Main use: photography;
DVD Drive: L.G GGW-H20L Blu-Ray / DVD;
OC: QPI/DRAM @ 1.33v, CPU @ 1.293v, DRAM Bus @ 1.65v, CPU PLL @ 1.88v, CPU mult = 25x, BCLK = 160, DDR3-1604 @ 7-8-7-24 |
07-23-2009
|
#8 | | |
OK, I just rebooted from my 7232 install, which hasn't been up in a few days. Also I have an earlier beta of OSS. I immediately scanned the file and - no hit. So it's either new heuristics in the released version, or new def. I run the update cycle & re-scan- Bingo! Trojan hit.
I'm scratching my head. If it's a new ware, what's it doing in an old file? Maybe injected recently? It's a huge zip file, so probably tempting place to hide crappola in. I suppose they can do it without altering size & dates. The file is originally from 2005. I extracted from an image backup from 6/22 and it's there too.
Or maybe it's a false positive? I have installed this thing many times, several in the past three months  . If it is indeed infected, wonder what it's doing? I hope they get really bored, fall asleep on the keyboard, hit the DEL key and delete their main data bank ...
OMG! Antman used a wormhole post! | My System Specs | | System Manufacturer/Model Number Custom workstation /// Lenovo X61t tablet notebook OS Windows 7 RTM x64 CPU Core i7 980X @ 4.04GHz OC /// Core Duo L7500 @ 1.6GHz Motherboard Asus P6T6 WS Revolution /// Memory 12GB G. Skill @ DDR-1600 OC /// 4GB Graphics Card Saphire HD4870 Toxic 1GB /// Intel Mobile GMA X3100 Monitor(s) Displays Dual Eizo 24" SX2461W /// 12" Screen Resolution 1920x1200 /// 1400x1050 Keyboard Logitech Edge /// Mouse Logitech Wireless Optical Trackball PSU Tagan ITZ 1100 Case GHS-1500 /// Cooling Thermalright IFX-14 + a slew of stealth fans /// Hard Drives Workstation:
5x 750GB Barracuda-11 on Areca ARC-1220;
4x 1.5TB Barracuda-11 on Intel ICH10R;
Volumes:
300GB RAID 0, 2.7TB RAID 10 on Intel;
100GB RAID 0, 1.4TB RAID 10 on Areca ///
Notebook: G.Skill Titan 256GB SSD Internet Speed 5Mbps down / 820Kbps up Other Info Main use: photography;
DVD Drive: L.G GGW-H20L Blu-Ray / DVD;
OC: QPI/DRAM @ 1.33v, CPU @ 1.293v, DRAM Bus @ 1.65v, CPU PLL @ 1.88v, CPU mult = 25x, BCLK = 160, DDR3-1604 @ 7-8-7-24 |
07-23-2009
|
#9 | | |

Quote: Originally Posted by DJG ...OMG! Antman used a wormhole post! I can find ref's to Trojan.Downloader.VB.VZO, circa 2005-2006. No good def's though.
At a minimum, write protect your compressed files. I find it odd that someting would inject a payload into a single archive. Transient malware. Hit one file and leave before detection, with the payload undetected? That is one clever worm.
Speaking of clever worms, I have a court date at 10 a.m. | My System Specs | | |
07-24-2009
|
#10 | | |
Well, I'm on a new fairly bare clean install. I think it may be a false positive. When I have time I'll ship it upstream to Agnitum and let them check it out. Now I'm re-installing and putting things back in order, again, minus the one. Sigh ...
OTOH, that install was an upgrade, so I don't feel as bad  .
Thanks for the scouting. Have a fine day in court ... | My System Specs | | System Manufacturer/Model Number Custom workstation /// Lenovo X61t tablet notebook OS Windows 7 RTM x64 CPU Core i7 980X @ 4.04GHz OC /// Core Duo L7500 @ 1.6GHz Motherboard Asus P6T6 WS Revolution /// Memory 12GB G. Skill @ DDR-1600 OC /// 4GB Graphics Card Saphire HD4870 Toxic 1GB /// Intel Mobile GMA X3100 Monitor(s) Displays Dual Eizo 24" SX2461W /// 12" Screen Resolution 1920x1200 /// 1400x1050 Keyboard Logitech Edge /// Mouse Logitech Wireless Optical Trackball PSU Tagan ITZ 1100 Case GHS-1500 /// Cooling Thermalright IFX-14 + a slew of stealth fans /// Hard Drives Workstation:
5x 750GB Barracuda-11 on Areca ARC-1220;
4x 1.5TB Barracuda-11 on Intel ICH10R;
Volumes:
300GB RAID 0, 2.7TB RAID 10 on Intel;
100GB RAID 0, 1.4TB RAID 10 on Areca ///
Notebook: G.Skill Titan 256GB SSD Internet Speed 5Mbps down / 820Kbps up Other Info Main use: photography;
DVD Drive: L.G GGW-H20L Blu-Ray / DVD;
OC: QPI/DRAM @ 1.33v, CPU @ 1.293v, DRAM Bus @ 1.65v, CPU PLL @ 1.88v, CPU mult = 25x, BCLK = 160, DDR3-1604 @ 7-8-7-24 All times are GMT -5. The time now is 07:09 PM. |  |