MATRIXSYNTH: Trojan Viruses in VSTi's?


Wednesday, January 05, 2011

Trojan Viruses in VSTi's?

See the comments in this post. Anyone experience one in a VSTi? I've been on the fence posting lesser known software based synths. On the one hand I want to promote people new and experimenting, on the other, bad seeds are always a risk. Feel free to comment.

Update via X-Dark in the comments: "Please read this as well : http://www.kvraudio.com/forum/viewtopic.php?t=286095&start=0"

Update via Mr. Soza in the comments: "ZoneAlarm False Positive.

The main DLL file actually appears to be clean.
I checked it out myself.
(FYI - I used to write AV signatures & am a malware/security engineer by day).

Infected VSTi's are not new, this primarily affects "cracked" software and stuff you grab from P2P networks.
Though its always possible even for legit sites / apps to be compromised by bad guys so you do have to be somewhat cautious on the internet in general.

My advice to all is be suspicious of anything you download.
Especially when it comes from P2P, blogs or file share sites like RapidShare, MegaUpload, etc...

When in doubt, submit the file(s) to Virustotal for a scan against all the major AV vendors.
Go to www.virustotal.com and upload the files (unzip them first).

To see the results for this VSTi in question, go here

As you can see 0/43 AV products marked this VSTi as an infected file.
So either it's clean or these guys are among the best virus writers on the planet to evade AV detection like that.

Hope that helps my fellow music heads & props to Matrix Synth !!!"

5 comments:

  1. I don't know about this specific synth but false positive happens often.

    ReplyDelete
  2. Please read this as well : http://www.kvraudio.com/forum/viewtopic.php?t=286095&start=0

    ReplyDelete
  3. ZoneAlarm False Positive.

    The main DLL file actually appears to be clean.
    I checked it out myself.
    (FYI - I used to write AV signatures & am a malware/security engineer by day).

    Infected VSTi's are not new, this primarily affects "cracked" software and stuff you grab from P2P networks.
    Though its always possible even for legit sites / apps to be compromised by bad guys so you do have to be somewhat cautious on the internet in general.

    My advice to all is be suspicious of anything you download.
    Especially when it comes from P2P, blogs or file share sites like RapidShare, MegaUpload, etc...

    When in doubt, submit the file(s) to Virustotal for a scan against all the major AV vendors.
    Go to www.virustotal.com and upload the files (unzip them first).

    To see the results for this VSTi in question, go here:

    http://www.virustotal.com/file-scan/report.html?id=d259ebad889ecedd3b7363fb86d7c0ed608133db8b0e5e0e811dd3b255d516a3-1294251889

    As you can see 0/43 AV products marked this VSTi as an infected file.
    So either it's clean or these guys are among the best virus writers on the planet to evade AV detection like that.

    Hope that helps my fellow music heads & props to Matrix Synth !!!

    ReplyDelete
  4. My advice: Buy the software you use!

    ReplyDelete
  5. got this on the xenharmonic vsti; mostly didn't trust the download path...

    after checking with the dev, I'm using it & having fun, bypassed zonealarm.

    zonealarms support seemed somewhat aware of the issues and promised they were working on it. relatively clueless tech when it came to a step by step to allow the vst to function with the za software.

    ReplyDelete

To reduce spam, comments for posts older than one week are not displayed until approved, usually same day. Do not insult people. For items for sale, do not ask if it is still available. Check the auction link and search for the item. Auctions are from various sellers and expire over time. Posts remain for the pics and historical purposes. This site is meant to be a daily snapshot of some of what was out there in the world of synths.

PREVIOUS PAGE NEXT PAGE HOME


Patch n Tweak
Switched On Make Synthesizer Evolution Vintage Synthesizers Creating Sound Fundlementals of Synthesizer Programming Kraftwerk

© Matrixsynth - All posts are presented here for informative, historical and educative purposes as applicable within fair use.
MATRIXSYNTH is supported by affiliate links that use cookies to track clickthroughs and sales. See the privacy policy for details.
MATRIXSYNTH - EVERYTHING SYNTH