forum.vdsworld.com Forum Index forum.vdsworld.com
Visit VDSWORLD.com
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Trojan Downloaders and VDS

 
Post new topic   Reply to topic    forum.vdsworld.com Forum Index -> Miscellaneous
View previous topic :: View next topic  
Author Message
vtol
Valued Contributor
Valued Contributor


Joined: 05 Feb 2004
Posts: 656
Location: Eastern Indiana

PostPosted: Sat Apr 08, 2006 12:22 am    Post subject: Trojan Downloaders and VDS Reply with quote

Hi
My Virus detection program just found that a DLL made by one of the people here is a Trojan Downloader Sad

I dont really know what to do about it as far as talking to any one.
May be a false reading, not sure about that either.

Thought someone might have had the same problem.

Rolling Eyes



trojanDLLvds.gif
 Description:
Posible Trojan Downloader
 Filesize:  10.38 KB
 Viewed:  31684 Time(s)

trojanDLLvds.gif


Back to top
View user's profile Send private message Visit poster's website
vtol
Valued Contributor
Valued Contributor


Joined: 05 Feb 2004
Posts: 656
Location: Eastern Indiana

PostPosted: Sat Apr 08, 2006 12:31 am    Post subject: Reply with quote

Maybe the Trojan attached itself to the DLL like a gay hitchiker Laughing
Back to top
View user's profile Send private message Visit poster's website
Serge
Professional Member
Professional Member


Joined: 04 Mar 2002
Posts: 1480
Location: Australia

PostPosted: Sat Apr 08, 2006 2:07 am    Post subject: Reply with quote

that is a definite concern that you should raise in this forum

i would expect the moderators of this forum to get in touch with you to find out details of this dll + to check whether it is a trojan downloader or not

if they do find that it is, i expect the author of the dll to be contacted for a 'please explain' and/or to be kicked out of this forum and the rogue dll removed from vdsworld

in the past, such measures have been taken

serge

_________________
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
PGWARE
Web Host


Joined: 29 Dec 2001
Posts: 1565

PostPosted: Sun Apr 09, 2006 5:35 pm    Post subject: Reply with quote

Please note that some dll's are compressed with programs like Petite, PeCompact, AsPack, and other type of PE compressors. A virus scanner may detect a false positive based on the heuristics of a similar program (which is the real virus/trojan) which uses that same pe compressor. The virus scanners cannot decompress the pe compressed file so it bases its heuristics on what it finds inside of the real trojan/virus which in some cases can lead to false positives for files which have similar characteristics within it.

I know a few of my dll's have actually reported as trojans when using the PeCompact compressor and one of the compression algorithms the program allows; changing the compression algorithm to another one fixed the issue with the scanner.

Then again there have been a few dll's posted here at vdsworld which were actual trojans and were meant to steal your vds.key file and other data from the registry. Most of these files have been talked about on the forums and have been removed from the site.

You should not feel compelled to hide the name of the dll's as its important for the community and for the author of the dll to find what may be causing this false positive or if indeed the author is putting out virus/trojans to the community.
Back to top
View user's profile Send private message
vtol
Valued Contributor
Valued Contributor


Joined: 05 Feb 2004
Posts: 656
Location: Eastern Indiana

PostPosted: Tue Apr 11, 2006 1:10 am    Post subject: Reply with quote

Heres what you wanted


trojanDLLvds2a2.bmp
 Description:
 Filesize:  54.7 KB
 Viewed:  31617 Time(s)

trojanDLLvds2a2.bmp


Back to top
View user's profile Send private message Visit poster's website
Serge
Professional Member
Professional Member


Joined: 04 Mar 2002
Posts: 1480
Location: Australia

PostPosted: Tue Apr 11, 2006 1:52 am    Post subject: Reply with quote

in that case, i would say that it is a case of false positive as i really can't see codescript including trojan code in his dll's, he has provided fantastic support to vds programmers over the years

can you test it using a different anti-virus program ... there a a few free online ones you can use

serge

_________________
Back to top
View user's profile Send private message Visit poster's website MSN Messenger
vtol
Valued Contributor
Valued Contributor


Joined: 05 Feb 2004
Posts: 656
Location: Eastern Indiana

PostPosted: Tue Apr 11, 2006 2:23 am    Post subject: Reply with quote

I know, thats why I didnt know what to do..

I try that
Back to top
View user's profile Send private message Visit poster's website
WidgetCoder
Contributor
Contributor


Joined: 28 May 2002
Posts: 126
Location: CO, USA

PostPosted: Tue Apr 11, 2006 3:46 am    Post subject: Reply with quote

I found nothing malicious in the files using Symantec AntiVirus (Eng. 61.1.0.11 Def. 4/10/2006 rev.7), I think you may have just received a false positive.

At any rate considering the file's source I’m certainly not concerned Smile
Back to top
View user's profile Send private message Send e-mail
vtol
Valued Contributor
Valued Contributor


Joined: 05 Feb 2004
Posts: 656
Location: Eastern Indiana

PostPosted: Tue Apr 11, 2006 3:49 am    Post subject: Reply with quote

I allready checked it with latest nortons too.
I sent the ZIP to the finder in case it is a trojan that clings to a file.
Just curious is all.
I never was real concerned either.
Back to top
View user's profile Send private message Visit poster's website
Dr. Dread
Professional Member
Professional Member


Joined: 03 Aug 2001
Posts: 1065
Location: Copenhagen, Denmark

PostPosted: Tue Apr 11, 2006 7:12 am    Post subject: Reply with quote

I've also had two different AV progs flagging that DLL as Trojan. Dunno if it's a false alarm.

Greetz
Dread

_________________
~~ Alcohol and calculus don't mix... Don't drink and derive! ~~

String.DLL * advanced string processing
Back to top
View user's profile Send private message
vtol
Valued Contributor
Valued Contributor


Joined: 05 Feb 2004
Posts: 656
Location: Eastern Indiana

PostPosted: Tue Apr 11, 2006 7:22 am    Post subject: Reply with quote

Ya

Thanks for your input, Dread.

APImath is used in security/ incryption/ program key math etc.. to protect people, is kinda scary, So I guess it dont hurt to be cautious considering how things are nowadays.

I got the ol:
Ticket Received
Thank-you for contacting.......

So I figure it will take a few weeks to get a answer from my AV support.
I'll post another POST when news comes back..
regards Cool
Back to top
View user's profile Send private message Visit poster's website
vdsalchemist
Admin Team


Joined: 23 Oct 2001
Posts: 1448
Location: Florida, USA

PostPosted: Wed Apr 12, 2006 2:46 pm    Post subject: Reply with quote

Hi All,
I scanned CodeScripts DLL with McAfee Virusscan Enterprise 8.x and is does NOT show any virus in the DLL.

_________________
Home of

Give VDS a new purpose!
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    forum.vdsworld.com Forum Index -> Miscellaneous All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum

Twitter@vdsworld       RSS

Powered by phpBB © 2001, 2005 phpBB Group