CleanFilm
15-05-2009, 06:04 PM
Just read this, reports saying Windows 7 from torrents are containing botnets within the setup.exe file.
Researchers at security firm Damballa said that an infected, pirated version of Windows 7 Release Candidate created a botnot spanning around 27,000 controlled bots.
Sources:
http://www.tomshardware.com/news/Pirated-Windows-7-Botnet,7810.html
http://www.eweek.com/c/a/Security/Pirated-Windows-7-Builds-a-Botnet-With-Trojan-456054/
http://www.itworld.com/security/67803/pirated-windows-7-software-part-criminal-botnet
To prevent yourself from getting this botnet within your installation of Windows 7 First - Hash check it!
Build 7100 Hashes are as followed:
x64 (64bit Build)
Build String: 7100.0.winmain_win7rc.090421-1700
File Name: 7100.0.090421-1700_x64fre_client_en-us_Retail_Ultimate-GRC1CULFRER_EN_DVD.iso
Size: 3.04GB
MD5 Hash: 98341AF35655137966E382C4FEAA282D
CRC32: 58FB2BE0
SHA-1: FC867FE1AB2E0A9796F9E4D155B44EA6998F4874
x86/x32 (32bit Build)
Build String: 7100.0.winmain_win7rc.090421-1700
File Name: 7100.0.090421-1700_x86fre_client_en-us_Retail_Ultimate-GRC1CULFRER_EN_DVD.iso
Size: 2.35GB
MD5 Hash: 8867C13330F56A93944BCD46DCD73590 (x86 only)
CRC32: E8A1C394
SHA-1: 7D1F486CA569EFFFFB719CFB48355BB7BF499712
Hashes for 7127 are as follows:
x32
0xF691687F 7127.0.090507-1820_x86fre_client_en-us_Retail_Ultimate-GRMCULFRER_EN_DVD.iso
MD5 Hash : 4045CB2A8E50B65ED9E1C2B8D6026B2F
SHA1 Hash : F2D615E674B64053D299CFA5E80B777269F0DFF2
CRC-32 : F691687F
X64
0×460FAD4E 7127.0.090507-1820_x64fre_client_en-us_Retail_Ultimate-GRMCULXFRER_EN_DVD.iso
MD5 Hash : F805A6595DDC6D12956588BB0F1B9B83
SHA1 Hash : 9BEB69BE3C2D113ECEB944145951A2123FBBBBF8
CRC-32 : 460FAD4E
Looks like the botnet is actually embedded into the setup.exe file
http://img411.imageshack.us/img411/5778/win7virus.jpg
Well just to say to be careful from downloading from torrents any Windows 7 Builds.
Even though you should be careful with torrents anyways.
Researchers at security firm Damballa said that an infected, pirated version of Windows 7 Release Candidate created a botnot spanning around 27,000 controlled bots.
Sources:
http://www.tomshardware.com/news/Pirated-Windows-7-Botnet,7810.html
http://www.eweek.com/c/a/Security/Pirated-Windows-7-Builds-a-Botnet-With-Trojan-456054/
http://www.itworld.com/security/67803/pirated-windows-7-software-part-criminal-botnet
To prevent yourself from getting this botnet within your installation of Windows 7 First - Hash check it!
Build 7100 Hashes are as followed:
x64 (64bit Build)
Build String: 7100.0.winmain_win7rc.090421-1700
File Name: 7100.0.090421-1700_x64fre_client_en-us_Retail_Ultimate-GRC1CULFRER_EN_DVD.iso
Size: 3.04GB
MD5 Hash: 98341AF35655137966E382C4FEAA282D
CRC32: 58FB2BE0
SHA-1: FC867FE1AB2E0A9796F9E4D155B44EA6998F4874
x86/x32 (32bit Build)
Build String: 7100.0.winmain_win7rc.090421-1700
File Name: 7100.0.090421-1700_x86fre_client_en-us_Retail_Ultimate-GRC1CULFRER_EN_DVD.iso
Size: 2.35GB
MD5 Hash: 8867C13330F56A93944BCD46DCD73590 (x86 only)
CRC32: E8A1C394
SHA-1: 7D1F486CA569EFFFFB719CFB48355BB7BF499712
Hashes for 7127 are as follows:
x32
0xF691687F 7127.0.090507-1820_x86fre_client_en-us_Retail_Ultimate-GRMCULFRER_EN_DVD.iso
MD5 Hash : 4045CB2A8E50B65ED9E1C2B8D6026B2F
SHA1 Hash : F2D615E674B64053D299CFA5E80B777269F0DFF2
CRC-32 : F691687F
X64
0×460FAD4E 7127.0.090507-1820_x64fre_client_en-us_Retail_Ultimate-GRMCULXFRER_EN_DVD.iso
MD5 Hash : F805A6595DDC6D12956588BB0F1B9B83
SHA1 Hash : 9BEB69BE3C2D113ECEB944145951A2123FBBBBF8
CRC-32 : 460FAD4E
Looks like the botnet is actually embedded into the setup.exe file
http://img411.imageshack.us/img411/5778/win7virus.jpg
Well just to say to be careful from downloading from torrents any Windows 7 Builds.
Even though you should be careful with torrents anyways.