Trojan Found in Setup.exe on Build 16385 x86 ISO Image!

rck01

Curmudgeon
Well, maybe that LeBlanc fellow had a point about bogus ISO images. I just fired up setup.exe from an image of the x86 Build 7600.16385 leak under my current build 7264 installation and look what Microsoft Security Essentials found (see attached image).

Note: The ISO in question has the following Filename and Hash Info:

7600.16385.090713-1255_x86fre_client_en-us_Retail_Ultimate-GRMCULFRER_EN_DVD.iso
SHA1: 2ebdb1f65fbf5aaf38d4fb39ea4e658389a25ea3
MD5: b49d1c065de9be078abe5bbafc5a304d
CRC32: 65b9f574

So, I guess we all still need to be careful after all. Needless to say, stay FAR AWAY from this image.

RCK
 

Attachments

  • trojan.png
    trojan.png
    69.5 KB · Views: 145

My Computer

Computer Manufacturer/Model Number
HP Mini 2140
OS
Peanut Butter & Jelly.
CPU
Propeller Hat (with chin strap upgrade).
Motherboard
She keeps calling me!
Memory
Not what it used to be.
Graphics Card(s)
Hey! Let's not get too personal!
Sound Card
What?
Monitor(s) Displays
They're watching me right now!
Screen Resolution
Hasn't been resolved yet.
Hard Drives
Only when I take this little blue pill.
PSU
Twice yearly.
Case
On file with the DA's office.
Cooling
The Colin Fletcher approach to wilderness walking.
Keyboard
How quaint!
Mouse
Trap!
Internet Speed
None, I'm broke
Other Info
Redacted at the request of the Department of Homeland Security.
Well, maybe that LeBlanc fellow had a point about bogus ISO images. I just fired up setup.exe from an image of the x86 Build 7600.16385 leak under my current build 7264 installation and look what Microsoft Security Essentials found (see attached image).

Note: The ISO in question has the following Filename and Hash Info:

7600.16385.090713-1255_x86fre_client_en-us_Retail_Ultimate-GRMCULFRER_EN_DVD.iso
SHA1: 2ebdb1f65fbf5aaf38d4fb39ea4e658389a25ea3
MD5: b49d1c065de9be078abe5bbafc5a304d
CRC32: 65b9f574

So, I guess we all still need to be careful after all. Needless to say, stay FAR AWAY from this image.

RCK

Did you check that the hash values match what was quoted....do those hash values match others that are easilly found out there?

The good thing is that Microsoft Security Essentials found it I guess.
As with all the leaks up till now....it is always best to check them thoroughly before installing...as you have found.
 

My Computer

Computer Manufacturer/Model Number
Home Build
OS
Windows 7 RTM Ultimate - Activated (Technet)
CPU
Athlon 4800+
Motherboard
Gigabyte M56S-S3
Memory
2 gig
Graphics Card(s)
ATI Radeon 2400+
Sound Card
On board
Monitor(s) Displays
Samsung 22" LCD
Screen Resolution
1680 x 1050
Hard Drives
WD 250 gig Sata
PSU
550 w
Case
Antec LS100
Keyboard
Logitech MX5000 BT
Mouse
Logitech MX 5000 BT
Internet Speed
ADSL 2+
This is strange...When I thorughly tested this build MSE popped up with nothing...where did you get the build from...there are alot of fakes flying around...
 

My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
I'm normally pretty careful...

...about this sort of thing. In fact, I checked the hash values for the x64 build I installed on my Lenovo W700ds and they matched up fine. I guess I just got lazy with this build - the x86 version was so hard to find, and there were so many different permutations (assembled from either the Chinese dude or Wzor), that when I finally did get a working torrent I assumed any hash mismatches were the result of too many copies from too many sources. That, and it runs just fine under VMware Workstation - version stamps on explorer.exe and others looked good (7600.16385). No real reason to doubt it was a working build...until now!

Oh well, lesson learned! :o

RCK
 

My Computer

Computer Manufacturer/Model Number
HP Mini 2140
OS
Peanut Butter & Jelly.
CPU
Propeller Hat (with chin strap upgrade).
Motherboard
She keeps calling me!
Memory
Not what it used to be.
Graphics Card(s)
Hey! Let's not get too personal!
Sound Card
What?
Monitor(s) Displays
They're watching me right now!
Screen Resolution
Hasn't been resolved yet.
Hard Drives
Only when I take this little blue pill.
PSU
Twice yearly.
Case
On file with the DA's office.
Cooling
The Colin Fletcher approach to wilderness walking.
Keyboard
How quaint!
Mouse
Trap!
Internet Speed
None, I'm broke
Other Info
Redacted at the request of the Department of Homeland Security.
...about this sort of thing. In fact, I checked the hash values for the x64 build I installed on my Lenovo W700ds and they matched up fine. I guess I just got lazy with this build - the x86 version was so hard to find, and there were so many different permutations (assembled from either the Chinese dude or Wzor), that when I finally did get a working torrent I assumed any hash mismatches were the result of too many copies from too many sources. That, and it runs just fine under VMware Workstation - version stamps on explorer.exe and others looked good (7600.16385). No real reason to doubt it was a working build...until now!

Oh well, lesson learned! :o

RCK
Hey no big deal...The fact you posted your results and you tried to warn people overshadows the mistake...well done for spending the time to post
 

My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
The main issue is that because there was never an actual ISO released the hash values can change all over the gaff so tracing it is like trying to find a needle in a hay stack (so to say).

Unfortunately, as you say
lesson learned! :o
 

My Computer

Computer Manufacturer/Model Number
Compaq Desktop
OS
Windows 7 Ultimate x64
CPU
AMD Sempron Dual Core
Memory
3GB
Graphics Card(s)
NVIDIA GeForce 6150SE nForce 430
Screen Resolution
1024x768
Hard Drives
150GB Sata
I guess the moral of the story is ..... The price of freedom is vigilance...
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
Very weird!

@Zidane24,

Well, I just re-scanned setup.exe directly on my x64 system and, again, it got a hit on the Trojan. You're saying you've used this same build without incident? Very odd, indeed! I'm going to fire-up that VM I tested it in originally (prior to launching it directly on its intended upgrade target, my HP Mini 2140) and see if installed MSE into the "infected" VM triggers another hit.

RCK
 

My Computer

Computer Manufacturer/Model Number
HP Mini 2140
OS
Peanut Butter & Jelly.
CPU
Propeller Hat (with chin strap upgrade).
Motherboard
She keeps calling me!
Memory
Not what it used to be.
Graphics Card(s)
Hey! Let's not get too personal!
Sound Card
What?
Monitor(s) Displays
They're watching me right now!
Screen Resolution
Hasn't been resolved yet.
Hard Drives
Only when I take this little blue pill.
PSU
Twice yearly.
Case
On file with the DA's office.
Cooling
The Colin Fletcher approach to wilderness walking.
Keyboard
How quaint!
Mouse
Trap!
Internet Speed
None, I'm broke
Other Info
Redacted at the request of the Department of Homeland Security.
People need to be careful and get there builds from a reputable source. If you just grab any old iso from the internet with a build number your gonna get grief.
 

My Computer

Computer Manufacturer/Model Number
Custom Assembled
OS
Windows 7 Build 7600.16385 (Clean Install)
CPU
AMD Black Edition AMD Phenom X3 8750 / 2.4 GHz processor
Motherboard
Gigabyte GA-MA78GM-S2H 780G Socket AM2+ onboard VGA 8 channe
Memory
Kingston 4GB (4x1GB) DDR2 1066MHz/PC2-8500 Hyperx Memory
Graphics Card(s)
Intergrated ATI HD3200
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Acer 19"
Screen Resolution
1280 x 1024
Hard Drives
2 x Maxtor STM3250310AS 250GB SATAII 7200rpm 8MB Cache

3 x 500gb Seagate External HDD
PSU
CM eXtreme Power 460W PSU
Case
Coolermaster Elite 330 Black Case
Keyboard
Zippy Multimedia
Mouse
Logitech MX™518 Gaming-Grade Optical Mouse
Internet Speed
8Mbps down / 1Mbps up
Other Info
I haz floppyz
Does not look like a good hash.
According to our russian friends this is the good hash:

SIZE: 2,501,892,096 byte
SHA1: 4fb88ed0e763a0cd82d388e7fdaabd10fc0846d1
MD5: c7102805815abb3b6b4796a8cc3fb008
 

My Computer

Computer Manufacturer/Model Number
MasterB/Custom
OS
Windows 7 Professional x64
CPU
QuadCore AMD Phenom II X4 Black Edition 955 3.2 GHz
Motherboard
Asus M4A785TD-V Evo
Memory
8 GB Crucial DDR3
Graphics Card(s)
SAPPHIRE Radeon HD 4890 1GB HDMI New Edition
Sound Card
VIA VT1708S HD Audio 7.1 onboard/ ATI HDMI video card
Monitor(s) Displays
Acer H233H 23'' LCD HDMI
Screen Resolution
1920x1080
Hard Drives
1x 500GB and 1x 1TB 7200RPM 32MB Cache WD Caviar Black
PSU
CORSAIR CMPSU-620HX 620W
Case
COOLER MASTER Storm Scout SGC-2000
Cooling
2x 140mm and 1x 120mm case fans, Stock CPU fan
Keyboard
Logitech MX 3200
Mouse
Logitech MX 3200
Internet Speed
15 Mbps
Other Info
My first build!
these are mine from wzor can anyone confirm these are good ?SHA1: 29d32ad89b7eb05033974c99f8fc41d06f36a58c
MD5: 4171999e05724d309a62104d83485d69
 

My Computer

OS
windows 7 RTM
CPU
Q6600 @ 3.9
Motherboard
IP 35-E
Memory
8GB GEIL BLACK DRAGON
Graphics Card(s)
GTX 260-216
Monitor(s) Displays
SAMSUNG T240
Screen Resolution
1920X1200
Hard Drives
2X 500GB
PSU
COOLERMASTER 750 WATT
Case
HAF 932
Cooling
SYTHE MINE
Keyboard
TRUST WIRELESS KEYBOARD
Internet Speed
8 MEG
If someone knows if this is clean I'll appreciate it
CRC32: 61AD5BB2
MD5: 351712FB063012113D86AB061DCA1E5B
SHA-1: 32DA9836D1C2BD48553AADCDBD4CD4EB19AC860B

Edit:Just Scanned them this one is clean.
 

My Computer

OS
Windows 7
these are mine from wzor can anyone confirm these are good ?SHA1: 29d32ad89b7eb05033974c99f8fc41d06f36a58c
MD5: 4171999e05724d309a62104d83485d69

Dan lol yours are good but for x64! :)

He is talking about x86!
 

My Computer

Computer Manufacturer/Model Number
MasterB/Custom
OS
Windows 7 Professional x64
CPU
QuadCore AMD Phenom II X4 Black Edition 955 3.2 GHz
Motherboard
Asus M4A785TD-V Evo
Memory
8 GB Crucial DDR3
Graphics Card(s)
SAPPHIRE Radeon HD 4890 1GB HDMI New Edition
Sound Card
VIA VT1708S HD Audio 7.1 onboard/ ATI HDMI video card
Monitor(s) Displays
Acer H233H 23'' LCD HDMI
Screen Resolution
1920x1080
Hard Drives
1x 500GB and 1x 1TB 7200RPM 32MB Cache WD Caviar Black
PSU
CORSAIR CMPSU-620HX 620W
Case
COOLER MASTER Storm Scout SGC-2000
Cooling
2x 140mm and 1x 120mm case fans, Stock CPU fan
Keyboard
Logitech MX 3200
Mouse
Logitech MX 3200
Internet Speed
15 Mbps
Other Info
My first build!
Hm...well this might not matter much anymore...Windows 7 has been Officially announced RTM
 

My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)

My Computer

Computer Manufacturer/Model Number
MasterB/Custom
OS
Windows 7 Professional x64
CPU
QuadCore AMD Phenom II X4 Black Edition 955 3.2 GHz
Motherboard
Asus M4A785TD-V Evo
Memory
8 GB Crucial DDR3
Graphics Card(s)
SAPPHIRE Radeon HD 4890 1GB HDMI New Edition
Sound Card
VIA VT1708S HD Audio 7.1 onboard/ ATI HDMI video card
Monitor(s) Displays
Acer H233H 23'' LCD HDMI
Screen Resolution
1920x1080
Hard Drives
1x 500GB and 1x 1TB 7200RPM 32MB Cache WD Caviar Black
PSU
CORSAIR CMPSU-620HX 620W
Case
COOLER MASTER Storm Scout SGC-2000
Cooling
2x 140mm and 1x 120mm case fans, Stock CPU fan
Keyboard
Logitech MX 3200
Mouse
Logitech MX 3200
Internet Speed
15 Mbps
Other Info
My first build!

My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
Curiouser and Curiouser

Well, now when I run MSE from within a VM that was installed via this ISO I get no hits - unless I scan the ISO itself, in which case setup.exe is again flagged. Looks like whatever payload it carries, it doesn't impact the ultimate contents of the main WIM file. However, it could infect any system attempting to run it directly as part of an attempted upgrade, etc.

Regardless, I'm nuking this contaminated version and grabbing the real deal as soon as the just announced RTM images leak...

RCK
 

My Computer

Computer Manufacturer/Model Number
HP Mini 2140
OS
Peanut Butter & Jelly.
CPU
Propeller Hat (with chin strap upgrade).
Motherboard
She keeps calling me!
Memory
Not what it used to be.
Graphics Card(s)
Hey! Let's not get too personal!
Sound Card
What?
Monitor(s) Displays
They're watching me right now!
Screen Resolution
Hasn't been resolved yet.
Hard Drives
Only when I take this little blue pill.
PSU
Twice yearly.
Case
On file with the DA's office.
Cooling
The Colin Fletcher approach to wilderness walking.
Keyboard
How quaint!
Mouse
Trap!
Internet Speed
None, I'm broke
Other Info
Redacted at the request of the Department of Homeland Security.
Well, thanks for posting this. I have been concerned about this type of thing since day 1 and I always catch grief from people saying this sort of stuff doesn't happen and that I have bought into the MS FUD.....well it does happen.....even to the good people who take the necessary steps, precautions and "usually" get their stuff from a reputable source.
 

My Computer

Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Back
Top