The Biggest Threat This Year!

The Biggest threat this year turns out to be Portable Applications and the programs used to make them!


Modified copies of THINSTALL are being downloaded from all the Torrent portals and NO MAJOR Antivirus Publisher is paying attention!


Bitdefender does not see a threat with modified copies of THINSTALL and Kaspersky simply removed my posts and banned me from reporting the threat!


Modified copies of THINSTALL can disable your firewall, freeze your computer untill its damage is done and pretends to be "ANY" of your trusted applications accessing the Internet!


Your firewall might ask you if you wish your trusted program to access the Internet again, but by checking where your trusted application is going, you can see that its really the modified copy of THINSTALL that is accessing the Network!


If you doubt me that this is the biggest threat of the year and is about to go SuperNova, then research Thinstall and/or the portable applications made with it...


If you still dont see a problem, then YOU are the Problem!!!

Comments

  • alexcrist
    alexcrist
    edited December 2007

    Chill out, Corrupted. You want to report the, and I quote, Biggest threat this year, but you didn't even give a link to that application...


    If you want to make a correct report, please put the file(s) that you suspect in a ZIP file, protected by the password infected, and attach the ZIP to your next post. Otherwise...as least post a link where the BD Virus Analysts can take a sample. Nobody can do anything without a sample. :)


    ----------------------------------------------------------------------------------------------------


    Because you made me curious about this, I searched it on Google. As it appears, it's a legit application (but I'm not a Virus Analyst...if there's something wrong with it, only the Virus Analysts can tell).


    As I said, it looks like a legit application, and you seem to agree with me (I quote: "Modified copies of THINSTALL can disable your firewall, ..."). From the previous quote, I understand that you agree that only modified versions of Thinstall could be threats and NOT the actual Thinstall.


    This situation is extremely similar with the packers' situation: packers are very useful tools, when you (as a developer) want your application to be smaller, and to be protected by viruses. But nobody stops the virus-creators to use packers to crypt the virus code. And so, many people started to think that packers are actually viruses (because packed viruses are harder to detect).


    In other words: if you want BD to detect modified versions of Thinstall, you have to provide such a modified version, so it can be analyzed.


    Cris.


    P.S.: I'll mode this topic to a more appropriate section.

  • Corrupted user
    edited December 2007

    if there's something wrong with it, only the Virus Analysts can tell


    Yeah Right


    Apparently they cant...


    Oh by the way, its obviously not a "Legit" application if Thinstall.com only sells it to Corporations for $5000 a pop!


    And which suspected application is it when you do a Torrent search with BTJunkie or any other search Engine?


    Looks Like the Vast Majority of them to me so take your pick!!!

  • alexcrist
    alexcrist
    edited December 2007

    Look, you say that Kaspersky deleted your posts and banned you from their forums. I don't think anyone here will do he same, but with your attitude... I really can't say I blame anyone who does.


    Apparently they cant...


    What makes you say this? Just because it's not already detected, doesn't mean that Virus Analysts didn't find something wrong with it. It means that they didn't know about it, they didn't study the file(s) and, therefore, if it not detected. It's as simple as that!


    Oh by the way, its obviously not a "Legit" application if Thinstall.com only sells it to Corporations for $5000 a pop!


    And what exactly seems suspicious to you in this situation? As far as I know...it's their choice to who and at what price they sell their own work. Just make your own application and sell it for three times the price ($15000)...would that mean that your application is a virus? Just because you cannot afford it, it means that it's a virus??


    Last time I checked, you didn't have to pay for malware applications... who would pay $5000 for a malware?? :D


    I'm sorry, but I really cannot see your point. Just please calm down! for God's sake! And explain clearly what you mean.


    And which suspected application is it when you do a Torrent search with BTJunkie or any other search Engine?


    Looks Like the Vast Majority of them to me so take your pick!!!


    I'm not gonna take my pick. And also I don't think anyone will just start downloading something from somewhere, just hoping they'll find a particular file. If you are willing to post such a sample, do it, and I guarantee to you that it WILL be analyzed and, IF it is necessary, detection will be added.


    On the other hand...if you really don't want to post a sample...fine. But in this case, stop complaining that BD doesn't detect it. BD Virus Analysts have too much work to do and they do not have time to waste looking on torrents for some...file, that seems suspicious to you.


    Cris.

  • Where can you get this Alleged Malware?


    Try Thinstall Version 3.207 which can be found from BTJunkie!


    The REAL Problem is not one specific version of Thinstall however! The REAL problem is Thinstalls Popularity and using ANY Bugged version of Thinstall to create a Portable Application which is ALSO Bugged!


    Now do you get it?


    This thing will be everywhere!

    /applications/core/interface/file/attachment.php?id=1087" data-fileid="1087" rel="">Virus_Photos.zip

  • No, YOU have a bad attitude!

  • alexcrist
    alexcrist
    edited December 2007

    You attached a file on your prevoius post. I have no idea what it is, because on this section, only Virus Analysts have access to attachments. But I really find it hard to believe that a $5000 application (or so you say...) has only ~300K. So I assume you didn't attach a sample. If I'm wrong, I appologize (and I thank you for the sample...it will be analyzed as soon as possible).


    Where can you get this Alleged Malware?


    Try Thinstall Version 3.207 which can be found from BTJunkie!


    The REAL Problem is not one specific version of Thinstall however! The REAL problem is Thinstalls Popularity and using ANY Bugged version of Thinstall to create a Portable Application which is ALSO Bugged!


    Now do you get it?


    This thing will be everywhere!


    You are really getting paranoid...sorry for saying this.


    And...I'm saying this AGAIN!... BD Virus Analysts will NOT stay and search on torrents any files! If you already know about such files, do as all a good, download it, put it in a ZIP file (with the password infected) and attach it to a post. Since your first post, I believe you would have downloaded more then just one such samples...and you would have saved as both from this long and useless argument.


    No, YOU have a bad attitude!


    Excuse me?!?! I have a bad attitude? Oh, please...


    I'm on your side, Corrupted! I'm trying to help you! I told you what to do, so that the files that you suspect are analyzed by professionals. What more do you want from me?? :blink:


    If you really continue like this, I don't know if I'm going to respond anymore...because I have better things to do then wasting my time arguing with you. I HATE arguing...


    I'm going to contact a Virus Analyst to take a look at the file you attached. If that is not a sample, I ask you PLEASE just attach a sample and let's get this over with.


    Cris.

  • AndreiASM
    edited December 2007

    Dear Corrupted, having this kind of attitude on this forum won't solve anything. If you have samples of "bugged" programs, you are welcomed to upload them here, in an archive with the password `infected' You really should calm down, with this kind of attitude, no wonder you were banned on KAV official forum! Still, it's a wonder that your warn level is still null.


    The real problem is that there are tons of this kind of modified programs on the internet (maybe they are cracked, patched etc.). But, trust me, it isn't easy to modify a program "on fly", to add this kind of routines in it, capable of "freezing your computer". It is not only difficult to keep track of all "modified programs wich can cause damage", wich pretend to be legit, it's just imposible (think about all the keygens/cracks wich also pretend to be "legit"...). A vr will take a look at the file you sent, and will add detection if needed.

  • Cris,


    How come you havent been banned from this group?


    Your asking me to commit a Federal crime by downloading and sharing an illegal program over the internet?


    Seriously, what kind of nuttcase are you?


    You know where the file is, you know how to get it and the photo's I sent show what it can do!


    You need to be banned from Internet access completely and for Life!


    See kids, this is why your parents need to protect you from these nutts!


    Corrupted

  • You must be feeling better now with warn level increased. What do you really want? To receive a bann on this forum too?? You can get it for free, if you keep having this kind of attiutude. I have adjusted your warn level, (not for warez as I mentioned in warn log <_< ) for having this kind of attiutude.

  • How come you havent been banned from this group?


    Well...if someone (one of the SuperModerators) finds a reson to BAN me, I believe they will, because I'm not the boss around here.


    Your asking me to commit a Federal crime by downloading and sharing an illegal program over the internet?


    A Federal crime...hmmm... Do you mean using illegal, cracked applications?


    Well...if you download it is it really necessary to use them?!?! Again, I have large difficulties understanding your point... :wacko:


    So...let me get this strait (please, correct me if I'm wrong...and I mean it. Maybe I'm too hard-headed to understand you): you don't want to attach a sample, because that would mean downloading it. And downloading it, in your opinion, is a Federal crime. Right? Well, let's say you're right. So, in this case, what makes you believe that me or the BD Virus Analysts want to commit a Federal Crime and download the application? Really...maybe my brain stopped, but I can't understand your point. Please, if anyone else here understood what Corrupted wanted to say, please, PLEASE explain it to me.


    Seriously, what kind of nuttcase are you?


    Nuttcase...hmmm...very hard word. And because you know such hard words, let me give you a prize: a warning increase. For what? Umm...let's make it for Personal insults. Please, DO continue like this, because I have many more prizes for you. <img class=" />


    Why can't you just understand I'm trying to help you? I'm open to discussion, but I really can't do anything to help you, unless you post a sample. I'm not a virus analyst, so I can't just go and search for it.


    You know where the file is, you know how to get it and the photo's I sent show what it can do!


    Exactly! You know where it is. Just download it, put it in a ZIP file, attach it to a post here, and erase it from your HardDrive. It's simple.


    About the photo...as I already told you (but you seem not to be able to understand)...I don't have access to it. On this section (Malware Talk), only virus analysts have access to attachments. I'm not a Virus Analyst, I'm just a Moderator.


    You need to be banned from Internet access completely and for Life!


    Yeah... NO COMMENT! <_<


    See kids, this is why your parents need to protect you from these nutts!


    Yeah...you already said this a few rows before -_-


    Cris.

  • There is only one point I need to clear up here and that is>


    Oh by the way, its obviously not a "Legit" application if Thinstall.com only sells it to Corporations for $5000 a pop!


    -----------------


    I meant that ALL of the Copies floating around the torrent scene are Not Legit!


    Obviously Thinstall can sell to Corporations only if they like and for $5000 a pop!


    All other "Moderated" chitchat in these posts is pointless and no further comments are needed!


    Corrupted

  • There is only one point I need to clear up here and that is>


    Oh by the way, its obviously not a "Legit" application if Thinstall.com only sells it to Corporations for $5000 a pop!


    -----------------


    I meant that ALL of the Copies floating around the torrent scene are Not Legit!


    Obviously Thinstall can sell to Corporations only if they like and for $5000 a pop!


    All other "Moderated" chitchat in these posts is pointless and no further comments are needed!


    Corrupted


    Ok...I finally understood something. And that's a good thing, because we're starting to communicate. :)


    So: everything that is made with Thinstall that's on the torrents is... at least suspicious. Ok, but again, I have to insist, just download a copy of it and post it. But I guess you won't even read this sentence...again.


    So let me tell you what we'll do. As I told you twice untill now, I don't have access to what you attached earlier. Because you really don't want to download something like this (and only God knows why), could you please send me all details about it (in a PM)? I mean, where can I get it from...exactly the address.


    Keep in mind that I am willing to make this for you: download the application myself and submit it for analisys.


    But I will NOT stay and search for it. So if you want to give me the exact address of one (or multiple) such samples, I will get them. Otherwise...no.


    Cris.

  • P.S.


    Cris,


    Get a Life!

  • Corrupted,


    This is an official forum, I have to remind it to you again. Messing with a moderator is not a way to solve your problems. First of all, Cris`s knowledge in computers is far greater than yours. Secondly, I am really really sorry to tell you, but if you keep insulting other memebers, we will offere you a free vacation! Here, you say your problem, we try to solve it. We are humans, we can't solve all problems in a blink of an eye. But, if we give us time and if you have patience, everything will be all right. Instead, you come here and argue with a moderator, and expect a faster solution. This is not the way to do it! -_-

  • alexcrist
    alexcrist
    edited December 2007

    Don't mind me asking, but... WHAT IS WRONG WITH YOU, Corrupted?!?!


    Let me refresh your memory of what happened: you came here, desperate (I must say) that none of the major AV companies deals, in any way, with, and I quote, The Biggest Threat This Year. In that moment I thought: Well, this is a user who cares about security. Maybe, with his help, BitDefender will become better (maybe even detect something that other AVs don't).


    Also, you were very upset that you already posted on KAV's forums, but not only that they didn't help you, but they banned you.


    I tried my best to help you: I told you what to do, so the BD Virus Analysts can analyze a sample of this malware. I tried everything to convince you to submit at least a sample. You really didn't want to (again, only God knows why).


    I even offered to personally download the sample(s), and I only asked for a link to them.


    But no matter what I try, you attack me! What is WRONG with you? I'm starting to think that actually, there's nothing wrong with Thinstall. I'm starting to think that you have a personal thing with this product/company, and you just want to affect it in some way.


    I'm wrong when I'm saying this? Ok...Prove it! Just send me a PM with a link...something that I can use to get such a sample. This is my last request. If you don't want to, fine. But I repeat: there's nothing BD can do, if you don't supply a sample (or at least a link to it).


    Remember that, at the beginning of this thread, I told you that nobody will ban you from here? Well...I'm sorry to tell you, but your situation is not looking very well. I'm not talking about myself, because I don't have the power to ban users. But tomorrow, when one of the SuperModerators logs in and sees this, frankly, I have doubts about your faith on this forum.


    Cris.


    P.S.: Until now, on my previous posts, I tried to joke a little (because that's my nature). But in this post, I'm talking as serious as I can. You are trying everybody's patience here...


  • This is an official forum, I have to remind it to you again. Messing with a moderator is not a way to solve your problems.


    ---------------------


    Excuse me?


    You people are ******!


    I never had a problem!


    I did not come here because of any problem!


    I came here to inform you of a threat!


    I handled the threat quite nicely without any help from you or Bitdefender!


    I am informing you that bitdefender does not see the threat!


    You have the problem!


    Corrupted

  • Corrupted user
    edited December 2007

    Here is the URL you requested!


    You may now Download it yourself


    Thinstall Version 3.207 is the Exact File I referred to


    ~Link removed~


    Oh, And your an Idiot so Ban me Now Please!


    Corrupted

  • If you still dont see a problem, then YOU are the Problem!!!


    Or, maybe you are the problem since you don't remeber what you've posted in an earlier post. And, secondly, if you would have known the board rules, you wouldn't have posted a direct link to a possible infected and dangerous file. So, please, chill down, and wait for an official response from a virus researcher, OK? Everything will be fine. Here, we don't want to bann users, it's not our job, and that's not why we're here. We're here to help people and to listen to them, thanks for the sample, btw, but, you really should behave from now on, or else, you will probably get a ban here too!


    Thank you for the sample and your interest in BitDefender. We are looking forward to hearing from you next time. ;)

    /applications/core/interface/file/attachment.php?id=1095" data-fileid="1095" rel="">link.txt

  • Wow, all I can say is: I truly respect you both, Cris and Andrei. :)


    I can never be THAT patient :P

  • Wow, all I can say is: I truly respect you both, Cris and Andrei. :)


    I can never be THAT patient :P


    I agree with dat.


    By accident saw this thread, if you have a lot of spare time it may be even amusing.


    Let not be that patient and advise Corrupted to stop acting-out and let others help people who need extra help besides their AV.


    It seems to me very obvious that corrupted needs another kind of help.


    By the way if this forum doesn't have the policy to ban somebody who goes way out of line, I suggest it (the ban policy) should be made.


    I expect I am the next in the line to receive some warm words from Corrupted, I would be amused to read that, but would not respond to that.

  • bluesprite
    edited December 2007
    Here is the URL you requested!


    You may now Download it yourself


    Thinstall Version 3.207 is the Exact File I referred to


    ~Link removed~


    Oh, And your an Idiot so Ban me Now Please!


    Corrupted


    You're just making a fool of yourself, talking like that to mods who by the way react so politely to your insulting childish outbursts. You're wasting their time, which they could have used to help other users who actually need help. And just want to remind you that not all countries are under your Federal law, so something which is a Federal crime there, might not be in other countries.

  • Chesda
    edited December 2007

    Funny Topic <img class=" />

  • well...that kid need an intense attitude lesson, certainly no one would care if he "warn"/"remind" people with that attitude.


    Maybe after he'd banned from all community on the net a.k.a rejected everywhere from the net, he would realize something, or wouldn't he? ^_^ haahhaha


    nice handle by mods, u got my salutation ^_^

  • It seems to me that Corrupted is the biggest threat this year. And it seems bitdefender had finally added detection. Cheers! I salute the mods for their utmost patience.

This discussion has been closed.