Trojan Zlob

Discussion in 'NOD32 version 2 Forum' started by ugly, May 27, 2006.

Thread Status:
Not open for further replies.
  1. TNT

    TNT Registered Member

    Joined:
    Sep 4, 2005
    Posts:
    948
    Thank you. :)

    After I asked the question I realized it was quite unlikely that Jotti used version 6, but didn't wanna delete the message. But it's good to hear, and it's good to see you're working on the other Vcodec nasties too. :D
     
  2. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Ladies and Gentlemen, please remember which forum we are in; that is the NOD32 SUPPORT Forum.

    Blackspear
     
  3. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    Mike - I thought you just get annoyed at tackling trivial static malware? You spend 20 mins adding generic for it now :doubt: Someone must have annoyed you to do it :thumb:
     
  4. proactivelover

    proactivelover Registered Member

    Joined:
    Apr 7, 2006
    Posts:
    840
    Location:
    Near Wilders Forums
    a new one not detect by nod32 and kaspersky
     

    Attached Files:

    • gg.jpg
      gg.jpg
      File size:
      50.8 KB
      Views:
      5
  5. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Another new one, detected by NOD32 without update:

    AntiVir 6.34.1.37 06.07.2006 no virus found
    Authentium 4.93.8 06.08.2006 no virus found
    Avast 4.7.844.0 06.06.2006 no virus found
    AVG 386 06.07.2006 no virus found
    BitDefender 7.2 06.08.2006 no virus found
    CAT-QuickHeal 8.00 06.07.2006 (Suspicious) - DNAScan
    ClamAV devel-20060426 06.07.2006 no virus found
    DrWeb 4.33 06.07.2006 no virus found
    eTrust-InoculateIT 23.72.31 06.07.2006 no virus found
    eTrust-Vet 12.6.2248 06.08.2006 no virus found
    Ewido 3.5 06.07.2006 no virus found
    Fortinet 2.77.0.0 06.08.2006 no virus found
    F-Prot 3.16f 06.07.2006 no virus found
    Ikarus n - no virus found
    Kaspersky 4.0.2.24 06.08.2006 Trojan-Downloader.Win32.Zlob.pm
    McAfee 4779 06.07.2006 no virus found
    Microsoft 1.1441 06.08.2006 no virus found
    NOD32v2 1.1585 06.07.2006 a variant of Win32/TrojanDownloader.Zlob
    Norman 5.90.17 06.07.2006 no virus found
    Panda 9.0.0.4 06.07.2006 Suspicious file
    Sophos 4.06.0 06.08.2006 no virus found
    Symantec 8.0 06.08.2006 no virus found
    TheHacker 5.9.8.156 06.08.2006 no virus found
    UNA 1.83 06.06.2006 no virus found
    VBA32 3.11.0 06.07.2006 no virus found
     
  6. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    U never dissapointed me IC. :D :D
     
  7. ASpace

    ASpace Guest


    which is excellent ;)


    Great job , ESET :thumb:
     
  8. izi

    izi Registered Member

    Joined:
    Jan 19, 2004
    Posts:
    354
    Location:
    Slovenia
  9. proactivelover

    proactivelover Registered Member

    Joined:
    Apr 7, 2006
    Posts:
    840
    Location:
    Near Wilders Forums
    nod32 and kasparsky detect it excellent
    nice work by ?
     
  10. rothko

    rothko Registered Member

    Joined:
    Jan 12, 2005
    Posts:
    579
    Location:
    UK
  11. TNT

    TNT Registered Member

    Joined:
    Sep 4, 2005
    Posts:
    948
    Newly found sites:
    mediacodec.info
    media-codec.net
    i.****jerks.com (not porn, just another "fake codec" site) :D
    xxxcodec.com (seems empty right now, but from Google searches, people have been infected before); the one above points to this one.
    pornmagpass.com

    All listing:
    codeccash.com
    codecmania.com
    digikeygen.com
    digipassword.com
    emcodec.com
    emediacodec.com
    getcodecs.com #expired
    i.****jerks.com
    imediacodec.com
    lastcodec.com
    media-codec.com
    media-codec.net
    mediacodec.info
    mediacodec.net
    modecodec.com
    my-codec.com
    my-homemade.com
    nvidcodec.com
    pornmagpass.com
    v-codec.com
    vcodec-download.com
    vcodec-get.com
    vcodec.com #expired
    vcodecdownload.com
    vcodecget.com
    vcodecget.net
    vcodecobtain.com
    vcodecpull.com
    vcodecreceive.com
    vicodec.com
    vidcodec.com
    videocodecupdate.com
    vidscodec.com
    xxxcodec.com
    your-codec.com
    zcodec.com


    As said above, more than a few porn sites point to these but they they are not listed, and they don't cointain the actual trojans files anyway.
     
  12. NAMOR

    NAMOR Registered Member

    Joined:
    May 19, 2004
    Posts:
    1,530
    Location:
    St. Louis, MO
    NOD32 doesn't see the one from pornmagpass.com but, BoClean does.
     
  13. ugly

    ugly Registered Member

    Joined:
    Mar 21, 2005
    Posts:
    276
    Location:
    Romania
    Look at this !:D

    prob.JPG

    Possibly & probably a new Zlob ...:eek:
    Well done.Congratulations.:-*
     
  14. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    nice ugly, but see this one. :( sample sent...
     

    Attached Files:

  15. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    We are familiar with it, it has already been added and the signature will go out with the upcoming update.
     
  16. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Results from scanning a new variant:

    AntiVir 6.35.0.10 06.09.2006 no virus found
    Authentium 4.93.8 06.08.2006 no virus found
    Avast 4.7.844.0 06.08.2006 no virus found
    AVG 386 06.08.2006 no virus found
    BitDefender 7.2 06.09.2006 no virus found
    CAT-QuickHeal 8.00 06.08.2006 (Suspicious) - DNAScan
    ClamAV devel-20060426 06.08.2006 no virus found
    DrWeb 4.33 06.08.2006 no virus found
    eTrust-InoculateIT 23.72.32 06.09.2006 no virus found
    eTrust-Vet 12.6.2248 06.08.2006 no virus found
    Ewido 3.5 06.08.2006 no virus found
    Fortinet 2.77.0.0 06.09.2006 suspicious
    F-Prot 3.16f 06.08.2006 no virus found
    Ikarus n - no virus found
    Kaspersky 4.0.2.24 06.09.2006 no virus found
    McAfee 4780 06.08.2006 no virus found
    Microsoft 1.1441 06.09.2006 no virus found
    NOD32v2 1.1587 06.08.2006 probably a variant of Win32/TrojanDownloader.Zlob.PW
    Norman 5.90.21 06.08.2006 no virus found
    Panda 9.0.0.4 06.08.2006 Suspicious file
    Sophos 4.06.0 06.08.2006 no virus found
    Symantec 8.0 06.09.2006 no virus found
    TheHacker 5.9.8.156 06.08.2006 no virus found
    UNA 1.83 06.08.2006 no virus found
    VBA32 3.11.0 06.08.2006 no virus found
     
  17. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    nice to hear that Marcos! ;)
    Now you definetly the best in zlob detection... :)
     
  18. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Another new one:

    AntiVir 6.35.0.10 06.09.2006 no virus found
    Authentium 4.93.8 06.08.2006 no virus found
    Avast 4.7.844.0 06.08.2006 no virus found
    AVG 386 06.08.2006 no virus found
    BitDefender 7.2 06.09.2006 no virus found
    CAT-QuickHeal 8.00 06.08.2006 no virus found
    ClamAV devel-20060426 06.09.2006 no virus found
    DrWeb 4.33 06.08.2006 no virus found
    eTrust-InoculateIT 23.72.32 06.09.2006 no virus found
    eTrust-Vet 12.6.2250 06.09.2006 no virus found
    Ewido 3.5 06.08.2006 no virus found
    Fortinet 2.77.0.0 06.09.2006 no virus found
    F-Prot 3.16f 06.08.2006 no virus found
    Ikarus n - no virus found
    Kaspersky 4.0.2.24 06.09.2006 no virus found
    McAfee 4780 06.08.2006 no virus found
    Microsoft 1.1441 06.09.2006 no virus found
    NOD32v2 1.1587 06.08.2006 a variant of Win32/TrojanDownloader.Zlob.PV
    Norman 5.90.21 06.08.2006 no virus found
    Panda 9.0.0.4 06.08.2006 Suspicious file
    Sophos 4.06.0 06.09.2006 no virus found
    Symantec 8.0 06.09.2006 no virus found
    TheHacker 5.9.8.156 06.08.2006 no virus found
    UNA 1.83 06.09.2006 no virus found
    VBA32 3.11.0 06.08.2006 no virus found
     
  19. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    Marcos, sorry to post another one not detected by NOD, but hope you'll add it fast. Sample sent to you. ;)
     

    Attached Files:

  20. i_kenefick

    i_kenefick Registered Member

    Joined:
    Nov 29, 2005
    Posts:
    135
    Location:
    Cork, Ireland.
    I'm sure Marcos doesn't need an apology. It's good for ESET to get these files from you. I don't think AV's are seeing this as a priority anyway. The only reason for the publicity is that people in forums like this know where the files are (and that they are updated so much) and are comparing AV detection using this stupid crap :D
     
  21. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    8,251
    Location:
    The land of no identity :D
    IMO, since the online scanner submits the files anyway, it means that all AV vendors will add signatures for these variants one day (most likely before the next AV-comparatives test:p). So its not much to worry, Eset already has most of the samples I think. ;)
     
    Last edited: Jun 9, 2006
  22. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    yeah...they are updated almost daily now. :D
     
  23. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    8,251
    Location:
    The land of no identity :D
    To be honest, I'm collecting such samples daily and sending them to all AV-companies. I've noticed that this Zlob trojan is really not a priority for most companies, since most of them take about 2-3 days to detect it (except McAfee, who took it very seriously and replied the next day with a notice saying signatures are added :eek:).

    Eset is also very fast in adding these Zlobs.
     
  24. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    Well, it's bad that some AV do this...adding defs just before the av-comparatives.org test. They should protect their users everytime not only before the test, and after that. :rolleyes: :(
     
  25. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    Dr.Web is very fast adding them, too. I've just received their answer to this new threat while replying to your post. :D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.