Trojan in JauntePE?!

Discuss anything related to JauntePE, the utlimate utility to help you tame non-portable applications. Share your experience about the apps that work with JauntePE, and the apps that don't.
Post Reply
Message
Author
castman
Posts: 179
Joined: Sat Jun 28, 2008 5:41 am
Location: Brazil, Sao Paulo
Contact:

Trojan in JauntePE?!

#1 Post by castman »

People here must know that Avast and GData started detecting all versions of JauntePE as a Trojan

The problem is that I use Avast :P

Win32:Bifrose-DJV [Trj] - People can see it at VirusTotal site

User avatar
Firewrath
Posts: 321
Joined: Mon Aug 28, 2006 2:36 pm

#2 Post by Firewrath »

yeah, AVG did this a while back, see these thread for info:

http://portablefreeware.com/forums/viewtopic.php?t=1934

http://portablefreeware.com/forums/viewtopic.php?t=2491

AVG called it "Backdoor.Bifrost"
but i think it was submitted as a false positive by some users here and AVG doesnt flag it anymore,


either way, its a false alert,

User avatar
Kranor
Posts: 120
Joined: Sun Jan 14, 2007 7:15 am
Location: uk

#3 Post by Kranor »

The madchook dll has been used in the past by virus and trojan writers to exploit machines. it is because of this that it flags up in many antivirus and antispyware products. Just so you know madchook was not written to create viruses it just happens that is what some people have used it for. This is one of the reasons that madashi asked redllar to remove madchook from his builds.

castman
Posts: 179
Joined: Sat Jun 28, 2008 5:41 am
Location: Brazil, Sao Paulo
Contact:

However

#4 Post by castman »

However, where is the source code of JauntePE (not madCHook) ??
I only have the original JauntePE015 from the broken links and the JauntePE020 :P
It's some kind of mistery!!

User avatar
Kranor
Posts: 120
Joined: Sun Jan 14, 2007 7:15 am
Location: uk

#5 Post by Kranor »

???????
Please explain what you mean??????

As far as I know version 0.1.5 is the only one out in the wild. Version 0.2.0 was being worked on by redllar but has not been re3leased to joe public.

JauntePE or madChook do not trigger any antivirus on their own. But any apps that you have made portable will trigger AV due to the api calls and dll hooking which is symptomatic of trojan behaviour

castman
Posts: 179
Joined: Sat Jun 28, 2008 5:41 am
Location: Brazil, Sao Paulo
Contact:

#6 Post by castman »

I mean to be informed about sources =P ??

I also thought it was PortableFreeware effort...

And explaining JauntePE020, I got it from the web and only used it to Discovery Registry Usage.

User avatar
Queue
Posts: 197
Joined: Mon Oct 08, 2007 2:41 am
Contact:

#7 Post by Queue »

I don't believe JauntePE source code was ever available. It was and is Redllar's project.

Queue

castman
Posts: 179
Joined: Sat Jun 28, 2008 5:41 am
Location: Brazil, Sao Paulo
Contact:

Sorry

#8 Post by castman »

Sorry, I'm a noobie =P

I understand now who built JauntePE. I think it was only the way Kranor explained me that confused me.

Don't bother yourselfs about me. I visit this site (portablefreeware.com) more than Google 8)

castman
Posts: 179
Joined: Sat Jun 28, 2008 5:41 am
Location: Brazil, Sao Paulo
Contact:

#9 Post by castman »

Kranor wrote:As far as I know version 0.1.5 is the only one out in the wild. Version 0.2.0 was being worked on by redllar but has not been re3leased to joe public.
This JauntePE020 package I downloaded from the web has 2 extra DLLs (jpeCrypto 0.1.0 and jpeShade 0.1.0)

I thought it was a new package but the JauntePE.dll says its version 0.1.1.

It has extra files. In addition of extra folders: Filesystems and Plugins.

Edit: Oh wait! You missed the new package!!

http://portablefreeware.com/forums/viewtopic.php?t=1849

But Someone can explain me why its written version 0.1.1??

I can't forget, Thanks Redllar for his great work :)

User avatar
Kranor
Posts: 120
Joined: Sun Jan 14, 2007 7:15 am
Location: uk

#10 Post by Kranor »

Ahh now you have posted that link we know what you are talking about!!

that 020 version is just an experimanetal plugin that redllar released. It is to do with fake drives and drive encyrption. It does not have the ability to make stand alone portable software but will work as a launchpad. this was released back in the early days of JauntePE. We are currently in limbo as far as jauntePE is concerned the latest news we had was that 030 was on its way. But like i say that was a fair while back.

Post Reply