wrt_vx_imgtool.exe flagged by Norton to contain a trojan

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
routermodder805
DD-WRT Novice


Joined: 13 Aug 2017
Posts: 1

PostPosted: Sun Aug 13, 2017 21:44    Post subject: wrt_vx_imgtool.exe flagged by Norton to contain a trojan Reply with quote
I went through the instructions on the wiki (see https://wikidevi.com/wiki/Linksys_WRT54G_v5) and in the instructions it has me download a few tools to image the router. One of them has the link http://www.dd-wrt.com/phpBB2/download.php?id=11090.

I ran a scan last night and Norton flagged the following trojan in the tool wrt_vx_imgtool.exe:

https://us.norton.com/online-threats/backdoor.graybird-2003-040217-2506-99-writeup.html

Not sure who maintains these servers but they appear to be compromised.



scan_dd-wrt_flag.png
 Description:
 Filesize:  24.92 KB
 Viewed:  6152 Time(s)

scan_dd-wrt_flag.png


Sponsor
mrjcd
DD-WRT Guru


Joined: 31 Jan 2015
Posts: 6291
Location: Texas

PostPosted: Sun Aug 13, 2017 22:01    Post subject: Reply with quote
Gv5Flash.zip cotains Gv5Flash:
dd-wrt.v24-12548_NEWD_micro.bin
tftp.exe
vxworks_prep_v03.bin
vximgtoolgui.zip >>> which contains:
wrt_vx_imgtool.exe
cfe.bin
common.dll
vximgtoolgui.exe

They are harmless and the same olderthandirt stuff I have 'HERE'
--
I just checked both --> 'wrt_vx_imgtool.exe' has same ol August 3, 2006 1:46 time stamp
Alozaros
DD-WRT Guru


Joined: 16 Nov 2015
Posts: 6445
Location: UK, London, just across the river..

PostPosted: Mon Aug 14, 2017 10:19    Post subject: Re: wrt_vx_imgtool.exe flagged by Norton to contain a trojan Reply with quote
routermodder805 wrote:
I went through the instructions on the wiki (see https://wikidevi.com/wiki/Linksys_WRT54G_v5) and in the instructions it has me download a few tools to image the router. One of them has the link http://www.dd-wrt.com/phpBB2/download.php?id=11090.

I ran a scan last night and Norton flagged the following trojan in the tool wrt_vx_imgtool.exe:

https://us.norton.com/online-threats/backdoor.graybird-2003-040217-2506-99-writeup.html

Not sure who maintains these servers but they appear to be compromised.


As mrjcd said there is nothing to be worried about,
the this is Norton is the same crap as AVG or Kasperski or any modern AV protection they are just bloatware that takes your resources and mark most of the useful stuff like harmful just because they do no like something that works like hack or crack, the other thing is all those AV keep open ports and they are easy to hack and serve to someone else i ve been without AV more that 15 years and never had anything to be worried about but i do have some kind of internet hygiene and know where to click and what to avoid....it's not an easy job ....

_________________
Atheros
TP-Link WR740Nv1 ---DD-WRT 55630 WAP
TP-Link WR1043NDv2 -DD-WRT 55723 Gateway/DoT,Forced DNS,Ad-Block,Firewall,x4VLAN,VPN
TP-Link WR1043NDv2 -Gargoyle OS 1.15.x AP,DNS,QoS,Quotas
Qualcomm-Atheros
Netgear XR500 --DD-WRT 55779 Gateway/DoH,Forced DNS,AP Isolation,4VLAN,Ad-Block,Firewall,Vanilla
Netgear R7800 --DD-WRT 55819 Gateway/DoT,AD-Block,Forced DNS,AP&Net Isolation,x3VLAN,Firewall,Vanilla
Netgear R9000 --DD-WRT 55779 Gateway/DoT,AD-Block,AP Isolation,Firewall,Forced DNS,x2VLAN,Vanilla
Broadcom
Netgear R7000 --DD-WRT 55460 Gateway/SmartDNS/DoH,AD-Block,Firewall,Forced DNS,x3VLAN,VPN
NOT USING 5Ghz ANYWHERE
------------------------------------------------------
Stubby DNS over TLS I DNSCrypt v2 by mac913
pld
DD-WRT Novice


Joined: 04 Jul 2020
Posts: 2

PostPosted: Sat Jul 04, 2020 16:46    Post subject: Reply with quote
I ran into the same issue when unzipping the Gv5Flash.zip.

The wiki doesn't specifically point to running the "wrt_vx_imgtool.exe" executable. Instead, it references running the "VXImgToolGui.exe" executable, which is also contained in the same *.zip file.

Can someone actually provide a legitimate reason that this would be flagged as a virus if it actually isn't?

And if it's not a virus, why would an extra executable be included in the zip file that has an eerily similar filename as to what is actually supposed to be executed? Do the two programs have different functionality?
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14242
Location: Texas, USA

PostPosted: Sat Jul 04, 2020 21:06    Post subject: Reply with quote
On what version of Windows, with what, if any 3rd party Anti-virus software? Not sure if the GUI exe uses the other exe to do the work or what. Sometimes, there is one executable that uses another executable to function. VxWorksKiller is probably something I wouldn't run on an Internet-aware device just in case, but that's just me. Also, thanks for this wonderful necro-jack Razz
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
pld
DD-WRT Novice


Joined: 04 Jul 2020
Posts: 2

PostPosted: Sat Jul 04, 2020 23:37    Post subject: Reply with quote
Yes, the necro jack (first time I've heard the term, but I like it)... I debated creating a new thread but not knowing the community, I was afraid that I would get flamed for not searching before posting:)

I downloaded the file on a Windows 10 Professional 64-bit machine running Symantec Endpoint Protection V14.2 RU2. Being new to the custom firmware world, of course I'm now hesitant to go forward with the installation. I was debating between dd-wrt and OpenWrt, but dd-wrt was the only firmware that supported WRT54GS V6.0. OpenWrt only supported up to V3.0 from what I recall.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14242
Location: Texas, USA

PostPosted: Sun Jul 05, 2020 0:25    Post subject: Reply with quote
If it's not part of the internal Windows firewall, anti-virus, malware suite, it should be removed. I have not run a 3rd-party anything since XP, and with smart screen and secure boot, all you are doing is spending money and wasting cpu cycles and clobbering the sh*t out of the kernel stack unnecessarily.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum