Log in

View Full Version : Windows 7 Containing Botnet



CleanFilm
15-05-2009, 06:04 PM
Just read this, reports saying Windows 7 from torrents are containing botnets within the setup.exe file.


Researchers at security firm Damballa said that an infected, pirated version of Windows 7 Release Candidate created a botnot spanning around 27,000 controlled bots.

Sources:
http://www.tomshardware.com/news/Pirated-Windows-7-Botnet,7810.html
http://www.eweek.com/c/a/Security/Pirated-Windows-7-Builds-a-Botnet-With-Trojan-456054/
http://www.itworld.com/security/67803/pirated-windows-7-software-part-criminal-botnet

To prevent yourself from getting this botnet within your installation of Windows 7 First - Hash check it!

Build 7100 Hashes are as followed:
x64 (64bit Build)
Build String: 7100.0.winmain_win7rc.090421-1700
File Name: 7100.0.090421-1700_x64fre_client_en-us_Retail_Ultimate-GRC1CULFRER_EN_DVD.iso
Size: 3.04GB
MD5 Hash: 98341AF35655137966E382C4FEAA282D
CRC32: 58FB2BE0
SHA-1: FC867FE1AB2E0A9796F9E4D155B44EA6998F4874

x86/x32 (32bit Build)
Build String: 7100.0.winmain_win7rc.090421-1700
File Name: 7100.0.090421-1700_x86fre_client_en-us_Retail_Ultimate-GRC1CULFRER_EN_DVD.iso
Size: 2.35GB
MD5 Hash: 8867C13330F56A93944BCD46DCD73590 (x86 only)
CRC32: E8A1C394
SHA-1: 7D1F486CA569EFFFFB719CFB48355BB7BF499712

Hashes for 7127 are as follows:
x32
0xF691687F 7127.0.090507-1820_x86fre_client_en-us_Retail_Ultimate-GRMCULFRER_EN_DVD.iso

MD5 Hash : 4045CB2A8E50B65ED9E1C2B8D6026B2F
SHA1 Hash : F2D615E674B64053D299CFA5E80B777269F0DFF2
CRC-32 : F691687F


X64
0×460FAD4E 7127.0.090507-1820_x64fre_client_en-us_Retail_Ultimate-GRMCULXFRER_EN_DVD.iso

MD5 Hash : F805A6595DDC6D12956588BB0F1B9B83
SHA1 Hash : 9BEB69BE3C2D113ECEB944145951A2123FBBBBF8
CRC-32 : 460FAD4E

Looks like the botnet is actually embedded into the setup.exe file
http://img411.imageshack.us/img411/5778/win7virus.jpg

Well just to say to be careful from downloading from torrents any Windows 7 Builds.
Even though you should be careful with torrents anyways.

Stephen!
15-05-2009, 06:28 PM
Glad i got mine from MSDN.

Recursion
15-05-2009, 06:37 PM
Glad i got mine from MSDN.

How did YOU get access to MSDN? :|

Stephen!
15-05-2009, 06:45 PM
technet :P samething.

Recursion
15-05-2009, 06:49 PM
Psshttt! Useless i tellz ya!

DaveTaylor
15-05-2009, 07:11 PM
This is why me and SoLoR when we leak the builds get them from torrents.ru

Pyroka
21-05-2009, 09:16 AM
Sorry to come in and brag, but the University I'm going to apparently gives out free MSDN access to Computing students. ;D

Oh here it is: http://msdn60.e-academy.com/elms/Storefront/ViewProductDetails.aspx?campus=msdnaa_mh8500&np1=112&p=1657

WINRAR LOL.

Joe!
21-05-2009, 02:49 PM
I get that as well Pyroka! With my college though :] Microsoft Academic Alliance or something ;)

Pyroka
21-05-2009, 02:52 PM
Yeah Microsoft Academic Alliance, it looks proper fit. We don't have it in our college however this University does. My mates like "Free copy of Windows 7 please, yoink" xD

DaveTaylor
21-05-2009, 03:02 PM
Yeah Microsoft Academic Alliance, it looks proper fit. We don't have it in our college however this University does. My mates like "Free copy of Windows 7 please, yoink" xD

I get free MSDN/Technet at RGU aswell, same as Developer Access to Apple.

Pyroka
21-05-2009, 03:05 PM
I get free MSDN/Technet at RGU aswell, same as Developer Access to Apple.

http://i2.photobucket.com/albums/y37/tr4c3/Futurama_Fry_Looking_Squint2.jpg

DaveTaylor
21-05-2009, 03:08 PM
http://i2.photobucket.com/albums/y37/tr4c3/Futurama_Fry_Looking_Squint2.jpg

LOL!, you might get Apple Access aswell at your uni, just ask them. I had to ask before they mentioned it, they mentioned MSDN as it's microsoft, but most Computing Uni's in the UK have Apple Access aswell.

Verrou
26-05-2009, 06:44 PM
Yeah Microsoft Academic Alliance, it looks proper fit. We don't have it in our college however this University does. My mates like "Free copy of Windows 7 please, yoink" xD
Username and password plox ;D

Want to hide these adverts? Register an account for free!