Trojan Zlob

Discussion in 'NOD32 version 2 Forum' started by ugly, May 27, 2006.

Thread Status:
Not open for further replies.
  1. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Please take this to Private Messages or eMails.

    Cheers

    Blackspear.
     
  2. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    ok.. I understand. ;)
     
  3. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,154
    Location:
    Texas
  4. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    new ZLOB !!! Detected only by ArcaVir heuristically! :(
     

    Attached Files:

  5. ugly

    ugly Registered Member

    Joined:
    Mar 21, 2005
    Posts:
    276
    Location:
    Romania
    Show must go on ...


    NZL.JPG


    Sent it.
     
  6. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    NOD added the def again among the first. :thumb:
     

    Attached Files:

  7. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    new one...not detected again...I think I'll not post here anymore except this and the next one. AV companies know where to get them from.
     

    Attached Files:

  8. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    and this is the last one...samples sent
     

    Attached Files:

  9. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    This one's corrupted, don't expect it to be detected. But the other one already is ;)
     

    Attached Files:

    • zlob.png
      zlob.png
      File size:
      12.4 KB
      Views:
      419
    Last edited: Jun 14, 2006
  10. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    thanks for the answer... ;)
    Btw, here's another good point for NOD32 :thumb:
     

    Attached Files:

  11. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Don't put all eggs into one basket by relying on results from Jotti's scanner. It often happens that NOD32 doesn't detect submitted files there as it even doesn't get to scanning due to techical difficulties at their part. Likewise other scanners may not always show valid results.
     
  12. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    I've scanned the file on Virustotal.com and here's the result. Virustotal was very busy that time that's why I"ve used jotti's
     

    Attached Files:

  13. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    Since the PDM is a behaviour blocker and relies on the file being executed. Here in your case the On-Access scanner blocked the execution of the file so PDM wasn't called into action.
     
  14. TNT

    TNT Registered Member

    Joined:
    Sep 4, 2005
    Posts:
    948
    Latest "pornmagpass"... :doubt:
     

    Attached Files:

  15. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    it has been added. ;)
     
  16. ugly

    ugly Registered Member

    Joined:
    Mar 21, 2005
    Posts:
    276
    Location:
    Romania
    Morning news.

    new.JPG
     
  17. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    added as Win32/TrojanDownloader.SA
     
  18. pc-support

    pc-support Registered Member

    Joined:
    Mar 10, 2005
    Posts:
    285
    Location:
    Edinburgh, UK
    10 pages all about 1 virus. I don't believe it!
     
  19. NOD32 user

    NOD32 user Registered Member

    Joined:
    Jan 23, 2005
    Posts:
    1,766
    Location:
    Australia
    Yeah it's nuts especially when you consider a user must first download and then install it....
     
  20. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    The problem is there are SOOOOO many variants, eventually heuristics need to be able to capture this and that will be the end of it ;) :D

    Cheers :D
     
  21. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    Symantec Corporate editions's heuristics catch them without updates. ;)
    Hope NOD32 will develop an heuristic engine soon, as these Zlobs never end... :(
     
  22. NOD32 user

    NOD32 user Registered Member

    Joined:
    Jan 23, 2005
    Posts:
    1,766
    Location:
    Australia
    I think I'd be unhappy if NOD32's heuristics were configured that loose, but it will be nice when they are tuned into catching all zlobs :)
     
  23. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    new one....
     

    Attached Files:

  24. steve1955

    steve1955 Registered Member

    Joined:
    Feb 7, 2004
    Posts:
    1,384
    Location:
    Sunny(in my dreams)Manchester,England
    I think one thing that can be deduced from this is that Nod doesn't seem to detect this very well using heuristics(advanced or otherwise)and seems to be more reliant on sigs than we'd like to think
     
  25. NOD32 user

    NOD32 user Registered Member

    Joined:
    Jan 23, 2005
    Posts:
    1,766
    Location:
    Australia
    Actually that will always be the case when the virus author deliberately makes changes to avoid further detection by AH... That's one of the reasons these are considered nasty, because the writer is acting with deliberate intent to avoid detection - deliberately modifying the code in such a way that the AV vendors must respond for further detections...
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.