V
Virus Guy
Got an e-mail tonight with an attachment that VirusTotal identifies
as various versions of Bagle, such as DM/FB/GT/BT/CW/DL, but some
ID it as DX (CAT, Ikarus, Kaspersky, TheHacker, VBA32).
This is probably what it is:
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=47438
Anyways, it says it's FSG packed. I looked for some FSG unpackers,
but many seem to have been written by hackers (cOmPleTe wItH FrEekY
..rEAdmE Filz tHaT m8ke me wOndeR iF i wAnT 2 tRy ThEm). Submitting
these unpackers to Virus Total usually come back with all but 2 or 3
AV progs finding nothing.
For example, this FSG unpacker:
http://protools.reverse-engineering.net/files/unpackers/fsg133unpazker.zip
has this in the file "usage.txt":
----------
hEllo there..
tHiz iz my first pub_prog_unpukzer.
ATTANSION!!!!!!!!!!!
tHiz prog is intended for use by TerriBBle iLLegalz ONLEY!!!
All other are restricted & will be prosecuted with
sincerely tsehpis,
my jE!
------------
Now maybe I just don't get east-european humor, but the text of that
message is just totally nutz.
What is a "TerriBBle iLLegalz" ???
What is the point of that warning? Or am I simply not hip enough to
understand it?
What is "HDD-MBR law" ???
Do I want to mess with software that is making a vague or disturbing
reference to the MBR of my hard drive?
as various versions of Bagle, such as DM/FB/GT/BT/CW/DL, but some
ID it as DX (CAT, Ikarus, Kaspersky, TheHacker, VBA32).
This is probably what it is:
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=47438
Anyways, it says it's FSG packed. I looked for some FSG unpackers,
but many seem to have been written by hackers (cOmPleTe wItH FrEekY
..rEAdmE Filz tHaT m8ke me wOndeR iF i wAnT 2 tRy ThEm). Submitting
these unpackers to Virus Total usually come back with all but 2 or 3
AV progs finding nothing.
For example, this FSG unpacker:
http://protools.reverse-engineering.net/files/unpackers/fsg133unpazker.zip
has this in the file "usage.txt":
----------
hEllo there..
tHiz iz my first pub_prog_unpukzer.
ATTANSION!!!!!!!!!!!
tHiz prog is intended for use by TerriBBle iLLegalz ONLEY!!!
All other are restricted & will be prosecuted with
sincerely tsehpis,
my jE!
------------
Now maybe I just don't get east-european humor, but the text of that
message is just totally nutz.
What is a "TerriBBle iLLegalz" ???
What is the point of that warning? Or am I simply not hip enough to
understand it?
What is "HDD-MBR law" ???
Do I want to mess with software that is making a vague or disturbing
reference to the MBR of my hard drive?