Hacking Trojan.Downloader with ModMii?

JoostinOnline

Certified Crash Test Dummy
Member
Joined
Apr 2, 2011
Messages
11,005
Trophies
1
Location
The Twilight Zone
Website
www.hacksden.com
XP
4,339
Country
United States
shortz1994 said:
@ PsyBlade, even "suggesting" some one might lie, you are calling them a lier. as far as trusting xflak because he is "canadian" lol.. i trust him because he hasn't given me a reason NOT to trust him. i trust them(canadians) more the our own citizens here in the US.
Lol, I wrote that for XFlak's benefit. I'm always teasing him about being Canadian. Maybe I shouldn't though, I can't imagine how awful it must be growing up and knowing that you are from CANADA!
ohnoes.png
 
D

Deleted_171835

Guest
JoostinOnline said:
PsyBlade said:
Has anyone of the people who say its a false positive actually analysed it?
It wouldn't be the first tool infected with malware without its author knowing (or simply lying about it).
And no checking the source does not cut it unless you can compile it to exactly the same binary.
Even if you assume that its the real code it could be infected after or during compilation.
You aren't suggesting XFlak is lying about it, are you? He may be Canadian, but I trust him.
What's wrong with Canadians? >:

Also,
security%20essentials%20modmii.PNG
 

JoostinOnline

Certified Crash Test Dummy
Member
Joined
Apr 2, 2011
Messages
11,005
Trophies
1
Location
The Twilight Zone
Website
www.hacksden.com
XP
4,339
Country
United States
SoulSnatcher said:
JoostinOnline said:
PsyBlade said:
Has anyone of the people who say its a false positive actually analysed it?
It wouldn't be the first tool infected with malware without its author knowing (or simply lying about it).
And no checking the source does not cut it unless you can compile it to exactly the same binary.
Even if you assume that its the real code it could be infected after or during compilation.
You aren't suggesting XFlak is lying about it, are you? He may be Canadian, but I trust him.
What's wrong with Canadians? >:

Also,
security%20essentials%20modmii.PNG
Nothing, see my above post, lol.

Btw, I don't get any issues with MSE either.
 

shortz1994

Well-Known Member
Member
Joined
Jan 21, 2011
Messages
1,340
Trophies
0
XP
369
Country
United States
JoostinOnline said:
SoulSnatcher said:
JoostinOnline said:
PsyBlade said:
Has anyone of the people who say its a false positive actually analysed it?
It wouldn't be the first tool infected with malware without its author knowing (or simply lying about it).
And no checking the source does not cut it unless you can compile it to exactly the same binary.
Even if you assume that its the real code it could be infected after or during compilation.
You aren't suggesting XFlak is lying about it, are you? He may be Canadian, but I trust him.
What's wrong with Canadians? >:

Also,
security%20essentials%20modmii.PNG
Nothing, see my above post, lol.

Btw, I don't get any issues with MSE either.
Same here, An i run Norton on one laptop, an i have CA, on the second laptop. an neither of them don't say anything.
 

Wiimm

Developer
Member
Joined
Aug 11, 2009
Messages
2,292
Trophies
1
Location
Germany
Website
wiimmfi.de
XP
1,519
Country
Germany
It can also be possible, that Xflak PC is infected (or any other computer on the ModMii route) and that the malware infect others tools including ModMii and that ModMii contains really a Trojan. There are many ways to infect an exe.

Has anyone made a fine analysis which file after extraction triggers the alarm? Is the alarm also triggered for old ModMii?
 

techboy

Well-Known Member
Member
Joined
Mar 15, 2009
Messages
1,720
Trophies
0
Age
31
Location
Pennsylvania
Website
Visit site
XP
306
Country
United States
Wiimm said:
It can also be possible, that Xflak PC is infected (or any other computer on the ModMii route) and that the malware infect others tools including ModMii and that ModMii contains really a Trojan. There are many ways to infect an exe.

Has anyone made a fine analysis which file after extraction triggers the alarm? Is the alarm also triggered for old ModMii?
My AVG just got an update...now it's flagging the program as well
mad.gif
Since I now get the alerts:

PatchIOS.exe is Trojan.Dropper.Generic4.KMX
libWiiSharp.dll is Trojan.Downloader.Generic11.BGOK

Both are generic heuristic detections. Also of note: libwiisharp.dll is used by patchIOS.exe

ModMii 4.5.7 and 4.6.1 are equally affected. I don't have anything older to check.
 

Wiimm

Developer
Member
Joined
Aug 11, 2009
Messages
2,292
Trophies
1
Location
Germany
Website
wiimmfi.de
XP
1,519
Country
Germany
techboy said:
PatchIOS.exe is Trojan.Dropper.Generic4.KMX
libWiiSharp.dll is Trojan.Downloader.Generic11.BGOK

Both are generic heuristic detections. Also of note: libwiisharp.dll is used by patchIOS.exe
"generic heuristic detections" result often in false positive. It means also that nobody has reported ModMIi as malware.

And one last note: There are many anti virus tools, but only a few engines. Some tools uses a combination of engines and the engine developers exchange there knowledge frequently. That's the reason, that many tools made ModMii as trojan at nearly same time.
 

PsyBlade

Snake Charmer
Member
Joined
Jul 30, 2009
Messages
2,204
Trophies
0
Location
Sol III
XP
458
Country
Gambia, The
Well if you want to believe that XFlak is to dumb to lie
and that it is impossible that modmii was infected without his knowledge,
I can't stop you.
But I think its stupid to assume either.
 

XFlak

Wiitired but still kicking
Member
Joined
Sep 12, 2009
Messages
13,811
Trophies
3
Age
38
Location
Cyprus, originally from Toronto
Website
modmii.github.io
XP
9,801
Country
Cyprus
Hey guys, I won't have internet up set up at my house until Friday, so until then I'll only be able to spare a couple minutes @ work to check up on things. And even then I am going to be really busy over the next few weeks, so even though it may take some time rest assured that "XFlak" is on the case.

I wanted to note a couple things... firstly, my PC is virus free, so I doubt ModMii was accidentally infected. Also, I don't think a .bat file can get infected (at least not without getting corrupted)... it's just text. That and the underlying supporting apps have not changed, if they were altered by a virus without my knowledge that can be checked by hashing the supporting apps from newer versions against older versions (I've personally checked this for libwiisharp, and it has not been altered).

Secondly, I'd never do anything malicious with ModMii, NEVER, not even if I was paid to do it. If you don't believe me, go read through my 5000+ posts and judge for yourself what kind of person I am.

Someone mentioned the problem was with ModMii's modified version of libwiisharp, this was modded so it doesn't timestamp wads (therefor enabling consistent hash signatures), and the mod was done by either cwstjdenobs or Leathl (first post of the ModMii thread would have the correct information). Anyways, that same person mentioned that the version of libwiisharp available on its google code page isn't showing up as a virus. As such, I decided to recompile the exe for ModMii v4.6.1 using the older libwiisharp and upload it here:
http://www.mediafire.com/?kk9nksa179u2bqw

Can someone please scan it and report whether it's being detected as a virus or not? If so, the false-positive problem is likely due to libwiisharp, if not, the problem is elsewhere. Also, can someone run the official ModMii v4.6.1 (not the above test version), go to the options page, type "decompiler", save the source, and scan the source folder and report the results? Additionally, can someone confirm that the ModMii Installer is being reported as virus-free. Thanks!

Lastly, I'm certain this is a fale-positive, but obviously everyone is entitled to their opinion. If there really was a virus in ModMii, one of the MANY people using ModMii would have come forward by now reporting symptons (and I don't mean a 'bogus' virus scanner report). So if we can't get this fixed, just white list it as others have recommended.

On a side note, I'm getting close to finalizing another awesome ModMii update, but by the time I finish it though 2 new things would have been released by other devs (*spoiler*) and I'll have to update ModMii again shortly afterwards... so depending on the timing I might end up waiting to put out the ModMii update for these 2 new things to be released... hopefully I can also have this figured out for the next update.
 

ChrisLuther

Active Member
Newcomer
Joined
Sep 28, 2010
Messages
40
Trophies
1
Age
44
Location
Bracknell,UK
XP
227
Country
Hi XFlak

I have run a scan using NIS on the source code of the official 4.6.1 and no issues have been reported.

Downloaded the file from the link and IE9 warned that it is not commonly downloaded and NIS auto deleted with a WS.Reputation.1 error. Redownloaded to a non autoprotect location and ran it and copied the files to an another folder to scan them. No issues were reported on the old file(s)

I've been using ModMiii since it was NUS Auto Downloader and never had any problems with it .. It is an excellent program.

Regards

Chris
 

shortz1994

Well-Known Member
Member
Joined
Jan 21, 2011
Messages
1,340
Trophies
0
XP
369
Country
United States
CA- security suites. no threat detected.( set to the most aggressive setting it has.)
NORTON- no threat detected.(also set to be aggressive.).. hit dolphin though.
laugh.gif
 

qwertymodo

Well-Known Member
Member
Joined
Feb 1, 2010
Messages
827
Trophies
0
Age
34
Website
qwertymodo.com
XP
520
Country
United States
UPX is used to compress the .exe's and .dll's. It has a history of generating false positives on virus scanners. This isn't a virus, it's just a side effect of the whole grab-bag frontend pack and play nature of this program.
 

techboy

Well-Known Member
Member
Joined
Mar 15, 2009
Messages
1,720
Trophies
0
Age
31
Location
Pennsylvania
Website
Visit site
XP
306
Country
United States
WiiBricker said:
I have an old ModMii 4.6.1 downloaded from google code right before the takedown. It has unlike the new ModMii 4.6.1 no viruses or trojans alarms at all: http://bit.ly/p9IPSX
That zip is still on Google Code as ModMii4.6.1.zip dated Jun 22. (The MD5s match.)

Also, this is the version I've been testing with. The Modmii.exe in that zip tests clean, but my AV complains as soon as I run it. The installer version from 5 days ago does the same thing after you install it.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Julie_Pilgrim @ Julie_Pilgrim:
    the internet
  • Julie_Pilgrim @ Julie_Pilgrim:
    @Psionic Roshambo i have 16 gb in my pc and i run into issues with ram more than i'd like to admit
  • HiradeGirl @ HiradeGirl:
    I got only 8GB of RAM. But I want 32GB.
  • Sonic Angel Knight @ Sonic Angel Knight:
    Time to just download more ram
  • K3Nv2 @ K3Nv2:
    Yeah search Google
  • Sonic Angel Knight @ Sonic Angel Knight:
    Or, I also heard that if you use flash memory, it can act as more "RAM" at least windows tell me when I stick a flash drive into it.
  • Veho @ Veho:
    It can act as a swap drive but that isn't more RAM, it's slooow.
  • K3Nv2 @ K3Nv2:
    I wish we could have 1Gbps external storage by now
  • K3Nv2 @ K3Nv2:
    Like for micro
  • Veho @ Veho:
    New Myoo.
  • SylverReZ @ SylverReZ:
    @Veho, Yooo noice
  • SylverReZ @ SylverReZ:
    Looks like a Famicom handheld
  • Veho @ Veho:
    Yeah, they were going for that.
  • Veho @ Veho:
    It's not very good though.
  • Veho @ Veho:
    I'm watching the review, the emulators it uses suck bawls.
  • Veho @ Veho:
    Software update might improve it.
  • Psionic Roshambo @ Psionic Roshambo:
    Or maybe someone will make like Emulation Station for it or something?
  • Veho @ Veho:
    That counts as a software update :tpi:
    +1
  • OctoAori20 @ OctoAori20:
    Ello
  • K3Nv2 @ K3Nv2:
    I can think of the design teams process another joystick and no audio or a joystick and mono audio
  • Veho @ Veho:
    "You think we can just put the speakers at the top
    ?" "NO!"
    +1
  • K3Nv2 @ K3Nv2:
    Pft stereo speakers you're fired
    +1
    K3Nv2 @ K3Nv2: Pft stereo speakers you're fired +1