Haven't seen a Zlob link for a few weeks

Haven't seen a Zlob link for a few weeks

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Haven't seen a Zlob link for a few weeks Duh_OZ 01-19-2007
Posted by David H. Lipman on January 20, 2007, 10:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| "David H. Lipman" wrote:
|
>> packers: UPX, BINARYRES, BINARYRES
|
| What is this BINARYRES packer? I can't find any description of it --
| the only hits are from Virustotal scans.
|
| Perhaps it's not an exe packer, but just indicates unusual resource
| blocks in the file.
|

Good question. I'll ask around.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by David H. Lipman on January 21, 2007, 7:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| "David H. Lipman" wrote:

>> packers: UPX, BINARYRES, BINARYRES

| What is this BINARYRES packer? I can't find any description of it --
| the only hits are from Virustotal scans.

| Perhaps it's not an exe packer, but just indicates unusual resource
| blocks in the file.


This is what I got back...

"Usually binaryes means it contains embedded file(s)"

and...

"DrWeb is using the term BINARYRES ...for Embeded files... in general, for every
exe or
dll that contains other files."

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Ant on January 21, 2007, 11:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
"David H. Lipman" wrote:

>| What is this BINARYRES packer? I can't find any description of it --
>| the only hits are from Virustotal scans.

> This is what I got back...
>
> "Usually binaryes means it contains embedded file(s)"
>
> and...
>
> "DrWeb is using the term BINARYRES ...for Embeded files... in general,
> for every exe or dll that contains other files."

Thanks. I suspected it wasn't the name of a particular packer.



Posted by Gabriele Neukam on January 20, 2007, 10:21 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On this special day, Duh_OZ wrote :

> Until tonight anyway.

> hxxp://xxx.activexmediasource.com/download/setupmedia.1645.exe

I don't know, if they are from the same source, but there is some
similar spam targeting German recipients, too.

http://www.heise.de/bilder/84000/0/1

If you click on one of the XXX-rated pictures on the page, in order to
see the video, a popup asks you to install a DivX plugin and a Flash
plugin, both of which are not recognized by most AV scanners.

http://www.heise.de/bilder/84000/1/1
http://www.heise.de/bilder/84000/2/1


Gabriele Neukam

Gabriele.Spamfighter.Neukam@t-online.de

--
Antenagenes, average skellimancer, lvl91 SP Patriarch, wearing a SOJ!



Posted by Duh_OZ on January 20, 2007, 11:15 am
If you were  Registered and logged in, you could reply and use other advanced thread options

Gabriele Neukam wrote:
>
> I don't know, if they are from the same source, but there is some
> similar spam targeting German recipients, too.
>
> http://www.heise.de/bilder/84000/0/1
>
> If you click on one of the XXX-rated pictures on the page, in order to
> see the video, a popup asks you to install a DivX plugin and a Flash
> plugin, both of which are not recognized by most AV scanners.
>
> http://www.heise.de/bilder/84000/1/1
> http://www.heise.de/bilder/84000/2/1
>
Got the link off rec.gambling.poker and see the one you mention was out
there also (posted yesterday). Tried the three (the two DivX and the
one flash) files and just VBA "flagged it".


Similar ThreadsPosted
Sorry Just get link June 6, 2006, 3:30 am
Link August 22, 2006, 6:04 am
Virus "link" in e-mail? April 24, 2006, 5:12 pm
Kaspersky AVP- request for update file download link ... October 29, 2005, 10:40 pm
Nice Microsoft link to sysinternals tools and more (no signin req) March 23, 2007, 8:58 am
Venak and Avenak Trial Version Link (MPS Edition) January 10, 2008, 3:15 am
IDNSERROR.COM and Troj/Zlob-QK November 10, 2006, 6:49 pm
Zlob Trojan - Newbie on group - Help please! April 13, 2006, 11:55 am
Troj/Zlob-ZG reported on my machine..... February 22, 2007, 5:59 pm
difference vundo, zlob, renos May 6, 2008, 9:20 am

The site map in XML format XML site map

Contact Us | Privacy Policy