Log in

View Full Version : FSG v2.0 executable packer


bart
May 24th, 2004, 10:16
http://www.woodmann.net/bart/download.php?id=xt_fsg20.zip
or
http://tinyurl.com/37eqh

dELTA
May 24th, 2004, 11:49
What?

bart
May 24th, 2004, 11:51
what what , isnt it TOT forum?

dELTA
May 24th, 2004, 11:55
Yeah, I just guess a small description would be in its place when posting a link to a file of warez release format which is also distributed from our own server, like e.g. "here is a packer I have created, and not really cracked and warezed, like the friggin nfo file in it says"...

Gustav
May 24th, 2004, 12:45
Norton AV says:Bloodhound.W32.EF

bart
May 24th, 2004, 13:11
and you trust it, shame on you

klier
May 25th, 2004, 13:39
Quote:
[Originally Posted by Gustav]Norton AV says:Bloodhound.W32.EF


is because of low entrypoint?

bart
May 25th, 2004, 13:58
i think becouse its shitty, and cant even emulate fsg's code (if executable != msvc or delphi then virus)

Kayaker
May 27th, 2004, 02:58
Interesting, I was cleaning up a W32/Spybot.worm.gen worm I just got, damned if I know how though since I never click on anything that might get me infected. I had to turn off my firewall though for access to a site, might have happened then.

Luckily I turned the firewall back on when I next logged on (dialup) and caught the worm in action, filenamed 'intersvc.exe' (UPX 0,1,2 packed). Started doing a bit of research after cleaning up, there are now >1000 variants of this worm, and found this entry about the worm:

"Some are encoded using FSG packer for PE executables".

http://hq.mcafeeasap.com/dispVirus.asp?virus_k=100282


'tis a shame your nice packer is used for this shite...
Ah well, such is the pitfalls of net travel.

K.

evaluator
May 27th, 2004, 08:54
Kayaker, RTM?????????

Kayaker
May 27th, 2004, 20:36
Hmmm, you mean this...?

features:
+ designed for asm executable files (kg, cracks, trojans


Ya, I guess you're right

...still shite though

evaluator
May 30th, 2004, 12:33
forgot to write one curious situation.

1. If this packer made for viri-trojs,
then Anti-Virs are doing good job, when FALSE-ALARMing!

2. But then, this packer will not be used by Viri-authors.

3. So then Anti-Virs will do bad job,
when FALSE-ALARMing & thay will remove FALSE-ALARM.

4. But then Viri-authors will think about using this packer..

5. GoTo 1.