Trojan Zlob

Discussion in 'NOD32 version 2 Forum' started by ugly, May 27, 2006.

Thread Status:
Not open for further replies.
  1. Brian N

    Brian N Registered Member

    Joined:
    Jul 7, 2005
    Posts:
    2,174
    Location:
    Denmark
    I do hope it's not 100% automated.. Never trust those machines! ..:rolleyes:
     
  2. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Don't know what file(s) you submitted, but all these Zlobs are actually malicious.
     
  3. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    I know, but it appears to be difficult to convince the guys at Fortinet.

    Maybe you could have a go at it? http://www.spywareinfoforum.com/html/emoticons/weee.gif
     
  4. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    so this last Zlobs are detected after extraction?
     
  5. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Yes, they are and the archives will be as of the next update.
     
  6. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    thx for the info. ;)
     
  7. colt45allstar

    colt45allstar Registered Member

    Joined:
    Jun 9, 2006
    Posts:
    65
    Very informative stuff here guys and I appreciate those of you who send the samples not only to eset, but to the other vendors as well.

    I think all internet users should be protected.. regardless of what antivirus software they use.

    This seems like an ever evolving threat....

    I will say... those of you who willingly download these samples, just to report them and make the internet world a safer place... are much braver than I.

    I would be afraid I would download something that can't be reversed.
     
  8. hin123

    hin123 Registered Member

    Joined:
    Mar 24, 2005
    Posts:
    12
    good job:thumb:

    AntiVir 6.35.0.10 06.12.2006 no virus found
    Authentium 4.93.8 06.09.2006 no virus found
    Avast 4.7.844.0 06.11.2006 no virus found
    AVG 386 06.11.2006 no virus found
    BitDefender 7.2 06.12.2006 no virus found
    CAT-QuickHeal 8.00 06.10.2006 (Suspicious) - DNAScan
    ClamAV devel-20060426 06.12.2006 no virus found
    DrWeb 4.33 06.11.2006 no virus found
    eTrust-InoculateIT 23.72.34 06.11.2006 no virus found
    eTrust-Vet 12.6.2250 06.09.2006 no virus found
    Ewido 3.5 06.11.2006 no virus found
    Fortinet 2.77.0.0 06.12.2006 suspicious
    F-Prot 3.16f 06.09.2006 no virus found
    Ikarus 0.2.65.0 06.09.2006 no virus found
    Kaspersky 4.0.2.24 06.12.2006 no virus found
    McAfee 4781 06.09.2006 no virus found
    Microsoft 1.1441 06.12.2006 no virus found
    NOD32v2 1.1593 06.12.2006 Win32/TrojanDownloader.Zlob.RJ
    Norman 5.90.21 06.09.2006 no virus found
    Panda 9.0.0.4 06.11.2006 Suspicious file
    Sophos 4.06.0 06.12.2006 no virus found
    Symantec 8.0 06.12.2006 no virus found
    TheHacker 5.9.8.158 06.12.2006 no virus found
    UNA 1.83 06.09.2006 no virus found
    VBA32 3.11.0 06.11.2006 no virus found

    Additional Information
    File size: 88425 bytes
    MD5: 2e9afafd821fd5182d6df3d7767e32b2
    SHA1: d38d4f8382e171e6f7eff7192f5cb28516ff56bc
     
  9. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    Scanning the latest - very nice! :)
     

    Attached Files:

    • NOD.gif
      NOD.gif
      File size:
      33.4 KB
      Views:
      422
  10. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    indeed, Tony! Nice job now! :thumb:
     

    Attached Files:

  11. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    Yup, another one here; only Nod32 achieves positive detection ;) :

    *****codec.net/v4/mediacodec-v4.207.exe

    Complete scanning result of "mediacodec-v4.207.exe", received in VirusTotal at 06.12.2006, 15:32:34 (CET).

    CAT-QuickHeal 8.00 06.12.2006 (Suspicious) - DNAScan
    Fortinet 2.77.0.0 06.12.2006 suspicious
    NOD32v2 1.1594 06.12.2006 Win32/TrojanDownloader.Zlob.RM
    Panda 9.0.0.4 06.12.2006 Suspicious file
     
    Last edited: Jun 12, 2006
  12. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    I'm doubtful whether these links comply with TOS. I for one think ...v4/mediacodec-v4.207.exe would be enough.
     
  13. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
  14. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    *.exe would be enough. Just joking. :D
     
  15. TNT

    TNT Registered Member

    Joined:
    Sep 4, 2005
    Posts:
    948
    Time for a new one, guys (mediacodec.net). :)
     

    Attached Files:

  16. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    Three latest variants, this time only identified by their MD5 hash.

    More work to do, it would seem, files submitted...

    1st file:
     

    Attached Files:

  17. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    Second file:
     

    Attached Files:

  18. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,361
    Location:
    The Netherlands
    3d one:
     

    Attached Files:

  19. TNT

    TNT Registered Member

    Joined:
    Sep 4, 2005
    Posts:
    948
  20. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    the new one is detected. :) ...and also those posted by Tony. ;)
     

    Attached Files:

  21. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    and this one ....
     

    Attached Files:

  22. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    This was the result from 11.20, almost 1,5 hour ago:

    AntiVir 6.35.0.10 06.13.2006 no virus found
    Authentium 4.93.8 06.12.2006 no virus found
    Avast 4.7.844.0 06.11.2006 no virus found
    AVG 386 06.12.2006 no virus found
    BitDefender 7.2 06.13.2006 no virus found
    CAT-QuickHeal 8.00 06.12.2006 (Suspicious) - DNAScan
    ClamAV devel-20060426 06.12.2006 no virus found
    DrWeb 4.33 06.13.2006 no virus found
    eTrust-InoculateIT 23.72.35 06.13.2006 no virus found
    eTrust-Vet 12.6.2253 06.13.2006 no virus found
    Ewido 3.5 06.13.2006 no virus found
    Fortinet 2.77.0.0 06.13.2006 suspicious
    F-Prot 3.16f 06.12.2006 no virus found
    Ikarus 0.2.65.0 06.12.2006 no virus found
    Kaspersky 4.0.2.24 06.13.2006 no virus found
    McAfee 4782 06.12.2006 no virus found
    Microsoft 1.1441 06.13.2006 no virus found
    NOD32v2 1.1596 06.13.2006 Win32/TrojanDownloader.Zlob.RR
    Norman 5.90.21 06.12.2006 no virus found
    Panda 9.0.0.4 06.12.2006 Suspicious file
    Sophos 4.06.0 06.13.2006 no virus found
    Symantec 8.0 06.13.2006 no virus found
    TheHacker 5.9.8.158 06.12.2006 no virus found
    UNA 1.83 06.09.2006 no virus found
    VBA32 3.11.0 06.12.2006 no virus found
     
  23. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    Everyone talking how better is NOD32 with its AH and it's reaction times than KAV... But has anyone actually tried these against PDM ? I think not...
     
  24. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    you could try them if you like. :D :D
    I can give you my collection of Zlob variants (about 46) and you may test it. I currently don't have KAV installed on my computer. :)
     
  25. .....

    ..... Registered Member

    Joined:
    Jan 14, 2005
    Posts:
    312
    I don't think KAV's PDM detects Zlob variants (atleast with the sample a tried - mediacodec-v4.107.exe). Only PDM was active (no other modules)(everything except ACI). I receieved no promts from KAV, but the threat was already detected by the realtime scanner.

    I'm willing to try with more samples.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.