This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#1 2010-10-29 20:34:34

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

My program detected as Trojan

How funny. I made a program to test in VM, I didn't give it to anyone except a person who tests viruses on purpose on YouTube. It deletes hal.dll, constantly terminates and opens explorer.exe, and kills some processes such as taskmgr.exe. I was testing my skills in a Virtual Machine, not to make harm to real computers.

I left it somewhere by accident where Malwarebytes' got a copy of it and marked it as Trojan.Downloader. I notice one flaw in it: It does not download anyyyyything.
http://dl.dropbox.com/u/11485779/Pictures/mbamamf.pngClick to get a closer look

The first thing that made me realize Malwarebytes' flagged it is when the protection module (I bought MBAM) said a malicious file was about to execute. I don't know what tried to execute that file. I clicked quarantine. Just to save my computer incase it ran and destroyed my computer.

No, I will not send it to Malwarebytes' to make it a false positive, and no, you can't have a copy. It deletes hal.dll!


~ihaveamac - visit ihaveamac.net

Offline

 

#2 2010-10-29 20:38:33

littletonkslover
Scratcher
Registered: 2008-12-12
Posts: 1000+

Re: My program detected as Trojan

lolwut?


http://www.coxlab.org/images/rat_banner.jpg
That's the dark nature of capitalism. ~ Wonder Showzen

Offline

 

#3 2010-10-29 20:40:42

PW132
Scratcher
Registered: 2009-05-16
Posts: 1000+

Re: My program detected as Trojan

You made. A virus.


SCRATCH 2.0 OHHHHH MANNNNNNN
http://i18.photobucket.com/albums/b107/PsychicDeath/universe.gif

Offline

 

#4 2010-10-29 20:41:57

Scratchthatguys
Scratcher
Registered: 2010-07-16
Posts: 1000+

Re: My program detected as Trojan

Yes. I only made a happy virus (It makes a billion windows open up, and freezes the computer.), and it's easy to stop.

Offline

 

#5 2010-10-29 20:55:42

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

PW132 wrote:

You made. A virus.

You didn't read enough.


~ihaveamac - visit ihaveamac.net

Offline

 

#6 2010-10-29 20:58:04

Jonathanpb
Scratcher
Registered: 2008-07-25
Posts: 1000+

Re: My program detected as Trojan

lol  LOL!!!  yikes


"Human beings... must have action; and they will make it if they cannot find it.
-Charlotte Brontë

Offline

 

#7 2010-10-29 21:05:30

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

Jonathanpb wrote:

lol  LOL!!!  yikes

ikr


~ihaveamac - visit ihaveamac.net

Offline

 

#8 2010-10-29 21:34:19

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

Bump

This is an epic thread.


~ihaveamac - visit ihaveamac.net

Offline

 

#9 2010-10-29 21:36:37

recycle49
Scratcher
Registered: 2009-12-21
Posts: 1000+

Re: My program detected as Trojan

Wow, nice going... LOL  lol  I cant make fake files, i can open them with winrar and do that stuffs, but not do that, lol i would have cried laughing if your computer tried forever to execute it  lol


"Every challenge must be met, every battle must be won, and every story will end." -Me
Recycle49 December 09 - November 11 Goodbye

Offline

 

#10 2010-10-29 21:43:04

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

recycle49 wrote:

Wow, nice going... LOL  lol  I cant make fake files, i can open them with winrar and do that stuffs, but not do that, lol i would have cried laughing if your computer tried forever to execute it  lol

I made mine in CMD, and got a batch converter and made an exe where it runs the batch file without a cmd window.


~ihaveamac - visit ihaveamac.net

Offline

 

#11 2010-10-29 22:12:34

Blade-Edge
Scratcher
Registered: 2009-06-13
Posts: 1000+

Re: My program detected as Trojan

ihaveamac wrote:

PW132 wrote:

You made. A virus.

You didn't read enough.

You expected him to? Lol


http://img29.imageshack.us/img29/5145/scratchycat.gif CLASSY

Offline

 

#12 2010-10-30 01:06:31

throughthefire
Scratcher
Registered: 2009-07-09
Posts: 1000+

Re: My program detected as Trojan

WOW 0_0
Malwarebytes is good anti-malware, so I wouldn't expect this!


Back. For now. Maybe.

Offline

 

#13 2010-10-30 01:13:54

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

throughthefire wrote:

WOW 0_0
Malwarebytes is good anti-malware, so I wouldn't expect this!

I guess
  1) Malwarebytes found it
  2) Someone reported it
  3) When it was scanned it looked suspicious

Last edited by ihaveamac (2010-10-30 01:20:47)


~ihaveamac - visit ihaveamac.net

Offline

 

#14 2010-10-30 04:51:03

what-the
Scratcher
Registered: 2009-10-04
Posts: 1000+

Re: My program detected as Trojan

Why make a virus. That's weak and pathetic. I could program one with my eyes closed, literally. Also your program failed it shouldn't be detected. Only once has any of my programs been detected by a anti virus and that was because I self signed a digital certificate and put it on the program.


http://imageshack.us/m/64/9034/ddfss.pngMy site
Find someone post count. Click posts under username. Find number of pages. Times that by 40 for min and 60 for max and you have a rough estimate of post count.

Offline

 

#15 2010-10-30 08:14:46

fire219
Scratcher
Registered: 2008-02-07
Posts: 1000+

Re: My program detected as Trojan

lol   Sounds like how your Norton hates SIMPL-DOS! Except, in this case, MBAM did what it is supposed to do.


http://bluetetrarpg.x10.mx/usercard/img.php?name=fire219

Offline

 

#16 2010-10-30 08:57:05

recycle49
Scratcher
Registered: 2009-12-21
Posts: 1000+

Re: My program detected as Trojan

ihaveamac wrote:

recycle49 wrote:

Wow, nice going... LOL  lol  I cant make fake files, i can open them with winrar and do that stuffs, but not do that, lol i would have cried laughing if your computer tried forever to execute it  lol

I made mine in CMD, and got a batch converter and made an exe where it runs the batch file without a cmd window.

XD! Malwear cought it though lol


"Every challenge must be met, every battle must be won, and every story will end." -Me
Recycle49 December 09 - November 11 Goodbye

Offline

 

#17 2010-10-30 11:55:17

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

what-the wrote:

Why make a virus. That's weak and pathetic. I could program one with my eyes closed, literally. Also your program failed it shouldn't be detected. Only once has any of my programs been detected by a anti virus and that was because I self signed a digital certificate and put it on the program.

Read the most some more. It says why I made one.


~ihaveamac - visit ihaveamac.net

Offline

 

#18 2010-10-30 12:05:27

Scratchthatguys
Scratcher
Registered: 2010-07-16
Posts: 1000+

Re: My program detected as Trojan

Make it run in the background. Oh yeah, and doesn't the /b switch make it run in background?

Offline

 

#19 2010-10-30 12:44:48

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

Scratchthatguys wrote:

Make it run in the background. Oh yeah, and doesn't the /b switch make it run in background?

I made it EXE and not .BAT/.CMD extension. The virus tester doesn't take bat/cmd files with those extensions.


~ihaveamac - visit ihaveamac.net

Offline

 

#20 2010-10-30 12:45:35

Scratchthatguys
Scratcher
Registered: 2010-07-16
Posts: 1000+

Re: My program detected as Trojan

Oh.

Offline

 

#21 2010-10-30 16:10:25

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

bump


~ihaveamac - visit ihaveamac.net

Offline

 

#22 2010-10-30 16:46:54

WindozeNT
Scratcher
Registered: 2010-06-05
Posts: 1000+

Re: My program detected as Trojan

ihaveamac wrote:

No, I will not send it to Malwarebytes' to make it a false positive, and no, you can't have a copy. It deletes hal.dll!

I could make the exact same thing, if not worse, in Microsoft Visual Basic 6! I'm a professional in that language.

EDIT: I have this one virtual  machine. It runs a modded Windows XP that looks, acts and feels like Win2K Pro. I hacked everything down to the last system DLL. It calles itself Windows 2000 Professional instead of Windows XP Professional because of a registry hack. Of course, my Win XP file hacking lead to a few OS bugs (I can't access Control Panel and Shell32 acts wierd in some areas). The bootscreen was changed and every other aspect of the XP OS was changed and hacked with Windows 2000 aspects, so you can't even identify it as Windows XP without reverse engeneering the NTOSKRNL.EXE file.
One time, I was bored, so I decided to see if the BSOD lookedn like 2K's as it should to fit the Windows 2000 environment, so I deleted the registry. On next boot, I got a DOS messsage saying Windows 2000 (even the bootloader thinks it's 2K!) couldn't boot because the registry went boom and files it required had vanished in thin air. Windows paniced about it and refused to boot. I exited the VM and told MS Virtual PC 2007 to delete the undo disk changes.
On the next VM start, the homemade Win2K booted up and greeted me with the startup sound. Epic.
WindozeNT

Last edited by WindozeNT (2010-10-30 17:13:48)


http://i48.tinypic.com/rlyo80.png
Ever since Misc was killed, I've pretty much stopped going to Scratch Forums...

Offline

 

#23 2010-10-30 18:19:01

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

Nice.
And I have a real computer installed with Windows 7 Ultimate.


~ihaveamac - visit ihaveamac.net

Offline

 

#24 2010-10-30 19:03:16

WindozeNT
Scratcher
Registered: 2010-06-05
Posts: 1000+

Re: My program detected as Trojan

ihaveamac wrote:

Nice.
And I have a real computer installed with Windows 7 Ultimate.

In addition, you have a Mac, too.  tongue


http://i48.tinypic.com/rlyo80.png
Ever since Misc was killed, I've pretty much stopped going to Scratch Forums...

Offline

 

#25 2010-10-31 14:05:23

ihaveamac
Scratcher
Registered: 2007-09-22
Posts: 1000+

Re: My program detected as Trojan

Code:

BUMP
rpmo
i ys
n  t
g

~ihaveamac - visit ihaveamac.net

Offline

 

Board footer