Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 3rd, 2002, 04:06 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default New trojans detected

There has been 2 big releases in the last 24 hours:
RAT.Optix Pro 1.0
RAT.Bionet 4.0.1

We've just finished adding comprehensive detection for both, and a preliminary update is available from this single update server at this time:
http://www.diamondcslabs.com/radius.td3

For TDS v3.2.1 the built-in updater will automatically use this server first. All update servers will be refreshed tonight (in approx. 3 hours from the time of this post) with the latest update along with detection of several more trojans.

I also currently have Advanced generic Bionet and Optix Pro detection in the works, this should be built into tonights final update.
  #2  
Old April 3rd, 2002, 05:06 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: New trojans detected

Hi Gavin,

Nice work! Bionet v4.0.1 has been released just yesterday - and you guys are on top of it already.

I'll copy and paste your post to the TDS forum as well, since your additional info surely belongs over there as well.

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #3  
Old April 3rd, 2002, 05:14 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re: New trojans detected

Hi Paul,

Especially happy with the upcoming Bionet generics, Bionet 3.x detection was similar, and TDS in all honesty is a fortress against and completely stops Bionet 3.x

Bionet 4 has nothing on 3.x ! in fact it should be called 3.20 - I don't know what happened there, this is no major update as users were expecting (and us, in preparation of its release)
  #4  
Old April 3rd, 2002, 05:23 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: New trojans detected

Hi Gavin,

You should be happy indeed with the upcoming BN generics - I am.

As for Bionet v4.0.1, I guess you are right. The coder does not regard this version as a stable one - could well be a new version will be coming up soon (you know how he has been pushed and pushed again to come up with a new version - had to come up with something in the end I suppose..).

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #5  
Old April 30th, 2002, 11:17 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re: New trojans detected

Hi everyone, just an update on this..

Since the recent releases of Bionet 4.00.02/4.00.03 and Optix Pro 1.1 as updates to these trojans, we have found that before analysis, the packed variants of these trojans were detected perfectly by the Advanced Scanning component in TDS. Even without a database update, users were protected from these heavily used trojans, in many packed variants - from just FILE scanning. We are proud of the detection abilities and will continue to work on such good detection of heavily used trojans

On another bright note, we quickly broke the current encryption schemes of BOTH trojans, and can give users the configuration from the servers if this information is requested. This involved some tricky cryptanalysis, however we believe it was worth the effort
  #6  
Old May 2nd, 2002, 10:11 PM
Mr.Blaze's Avatar
Mr.Blaze Mr.Blaze is offline
The Newbie Welcome Wagon
 
Join Date: Feb 2003
Location: on the sofa
Posts: 2,842
Default Re: New trojans detected

you guys are so lucky i dont know code lol of course id never make anything evill just funny stuff lol.

where when you move your mouse to click on an icon to start a program the icon gets up and runs alway from the mouse pointer lol

if you guys ever see anything that funny i sugest you worry cause i just learnd code
__________________
i am blazes rageing fur ball of fury dont let the small paws fool you my claws retract like wolverin, err when I'm not babysitting Jooskes mouse
  #7  
Old May 3rd, 2002, 10:26 AM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,139
Default Re: New trojans detected

Are you suggesting MRBLAZE, that you are a virus writer of W32.Magistr.24876@mm ?

Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #8  
Old May 4th, 2002, 02:19 AM
Mr.Blaze's Avatar
Mr.Blaze Mr.Blaze is offline
The Newbie Welcome Wagon
 
Join Date: Feb 2003
Location: on the sofa
Posts: 2,842
Default Re: New trojans detected

NO I DONT KNOW CODE WHATS THAT THING YOU SAID DOES IT DO WHAT I SAID LOL NO WAY THATS TO FUNNY

__________________
i am blazes rageing fur ball of fury dont let the small paws fool you my claws retract like wolverin, err when I'm not babysitting Jooskes mouse
  #9  
Old May 4th, 2002, 02:23 AM
Mr.Blaze's Avatar
Mr.Blaze Mr.Blaze is offline
The Newbie Welcome Wagon
 
Join Date: Feb 2003
Location: on the sofa
Posts: 2,842
Default Re: New trojans detected

http://www.symantec.com/avcenter/venc/data/w32.magistr.24876@mm.html SOME ONE BEAT ME TO IT

THAT OK *MINE WILL GROW LEGS AND RUN AROUND THE SCREEN DODGEING AND DIVEING ALWAY FROM THE CURSEOR LOL
__________________
i am blazes rageing fur ball of fury dont let the small paws fool you my claws retract like wolverin, err when I'm not babysitting Jooskes mouse
  #10  
Old May 4th, 2002, 02:26 AM
Mr.Blaze's Avatar
Mr.Blaze Mr.Blaze is offline
The Newbie Welcome Wagon
 
Join Date: Feb 2003
Location: on the sofa
Posts: 2,842
Default Re: New trojans detected

LIKE I SAID IT BE A FUNY THING SO AFTER REBOOT IT REMOVES ITSELF LOL I NEVER MAKE ANYTHING HARMFUL THATS NOT FUN AND WHATS THE POINT LOL
__________________
i am blazes rageing fur ball of fury dont let the small paws fool you my claws retract like wolverin, err when I'm not babysitting Jooskes mouse
  #11  
Old May 4th, 2002, 03:22 PM
Technodrome's Avatar
Technodrome Technodrome is offline
Global Moderator
 
Join Date: Feb 2002
Location: New York
Posts: 2,139
Default Re: New trojans detected

MRBLAZE Troublemaker....I mean FUNMAKER !!! *

Technodrome
__________________
Classic Trance Hit: PPK - Resurrection
  #12  
Old May 4th, 2002, 04:56 PM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: New trojans detected

Maybe you can show us some, maybe in SS3 script in SS3 but please in the private forum. I mean no viruses, of course, but some funny effects, movements, just happy harmless little things.
What you just described might need JS, not sure about that, but SS3 reads that as well. You might like to run after your MrBlze script to press a button for other scripts to play, etc. with the agents it might be lots less difficult, not sure.....
__________________
Jooske
"o_o"
  #13  
Old May 25th, 2002, 09:05 PM
s13az3
 
Posts: n/a
Default Re: New trojans detected





  #14  
Old May 25th, 2002, 09:27 PM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: New trojans detected

Quote:

* *
*
* *
__________________
Jooske
"o_o"
  #15  
Old May 27th, 2002, 10:55 AM
s13az3
 
Posts: n/a
Default Re: New trojans detected

hahahahahaha just a friendly note to say i like your forum alot!....it contributes alot to my programs. So thankyou very much!
  #16  
Old May 27th, 2002, 11:23 AM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,227
Default Re: New trojans detected

Quote:
it contributes alot to my programs.


(And hello.)
__________________
My Novel
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 09:42 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums