18 February 2008

AMD X2 DualCore with Intel P4 Core -:)

0 comments
CPU 1

CPU 2 -> Name string



Advanced Micro Devices - Other Hardware - AMD Processor MS update Pentium 4 MSR KB99894-v5.zip

playing with MSRs: AMD -> Pentium4 read more...

17 February 2008

About Packer.XComp.A false positive as Virus listed in AntiVirus Databases

1 comments
Hello it's me again Packer.XComp.A, BitDefender was give me this Name on 13. Feb. 2008 and mark me to be a Virus his Friend Ikarus was follow a few days later. I am one year old, my true name is XComp/XPack I'm a freeware PE32-imagefile packer/rebuilder please analyze me again and pack random Files.exe

Im a FREEWARE EXE PACKER my Name is Xcomp I am 1 Year old and this is the story how BitDefender via VirusTotal called me to be a Virus with the name Packer.XComp.A on 13 Feb 2008.rar
If I am a Virus your name is Johann the butler and your analysis is wrong.
I'm here: soft-lab.de/JoKo/ExePack.htm
Don't touch me if you belief I am dangerous or want any outgoing or incoming network connections. I don't want anything online cause I'm done to make big files smaller. Maybe my heuristic is a little bit high but not more as UPX in version > 1.9
Someone did some terrible tests with me. Believe it or not but they was unpack some files done with PECompact using the option to injected/select a dll and some other packers (my Memory requirement are not very high so I forgot if there was commercial Packers between). A pe explorer tool show after unpacking: "Warning! Import section follows the Resource section." After that I have compressed the unpacked files and ignored the warning "this file is already packed with PECompact,... and others", there was some rests inside left by unpacking. Later some wrong signatures with other packer names was come to my packed output files (it' wasn't me) and finally got submitted to VirusTotal. What was follow you can figure out. The AV results played crazy by every different signature shown a different result.
At this time no one was known or read the news by VirusTotal by them blog page, that they possible forward all files and results (experimenting include). That was the end as my signature as packer/compressor was end up in the list of viruses. I'm sorry for that tests but that was not me as packer alone.
I did my job to pack the files as little tool XComp.
I was a subject to test AntiVirus Software but they forgot to care about anonymity.

Maybe you can now imaginate why I am in the positive Virus Database by packer name Packer.XComp.A even if I do not have or produce any kinds of viruses as packer/compressor freeware tool. I think I am wrong on place there.

Anti-Trojan Elite v3.91

0 comments
Anti Trojan Elite(ATE) is a malware remover, it can detect and clean malware in disk or memory.

Anti Trojan Elite provide a real-time malware firewall for user, once a trojan or keylogger would been loaded, the ATE can detect, block and then clean it in time. The ATE can detect more than 35000 trojans, worms and keyloggers currently, and the number of malware ATE could clean is growing up very quickly, we collect world-wide malwares, user can using our auto live update feature to get the power to clean these new malwares in time.

Anti Trojan Elite has some useful utilities especially. The network utility can been used to disconnect suspicious TCP connections; The process utility can been used to kill suspicious processes even the process has the system priviage, even it has the ability to unload suspicious modules in all processes; The registry repair utility can been used to repair registry altered by malware; The registry monitor utility can been used to repair any change of important registry keys and values with real time.

Download Site
Share Link

Azureus 3.0.4.3 Beta 28

0 comments
AZUREUS VUZE 3.0.4.3 Beta 28 CHANGELOG


FEATURE: Core | Added µTorrent PEX support [amc1]
FEATURE: Core | Azureus probes trackers for UDP-capabilities on first scrape/announce now and uses udp instead of http where available [The 8472]
FEATURE: Core | Added option to enforce IP bindings even when the specified interfaces are not available (useful when Azureus should not use certain network interfaces) [The 8472]
FEATURE: UI | Added option for "Open Containing Folder" menu action - which may integrate better with non-standard file browsers [amc1]
FEATURE: UI | Added option for "Show Torrent Menu" -- Users can now decide to see the Torrent menu in the menubar or not [knguyen]
FEATURE: UIv3 | New menu configuration for Vuze and Vuze Advanced UI's [knguyen]
FEATURE: UI | Fast Renaming (not moving) in the Files tab (click on name column) and Open Torrent (click on dest. name column) dialog [The 8472]
FEATURE: UI | Completed downloaders column [The 8472]

CHANGE: Core | Further memory footprint reductions; for additional tweaks see http://www.azureuswiki.com/index.php/Reduce_memory_usage [The 8472]
CHANGE: Core | Reimplemented LT extension protocol code [amc1]
CHANGE: Core | DND/Compact (aka Delete) priority now deletes all files that do not share pieces with normal/high priority files [The 8472]
CHANGE: Core | Queuing rules now don't start any further torrents if the global up/download speed limits are reached [The 8472]
- makes "don't count torrent ..." minimum speed rules more useful to dynamically regulate the queue lengths
- recovers faster from chain reactions in case of connection loss
CHANGE: Core | Made the crypto handshake a bit less predictable [The 8472]
CHANGE: Core | Added support for IPv6 compact announces (client) and udp-multiscrapes (client+server) [The 8472]
CHANGE: Plug | Added support for plugins which implement mainline DHT [amc1]

BUGFIX: Core | Request limiting/Priorities no longer pinch off LAN peers if seperate LAN speeds are enabled [The 8472]
BUGFIX: UI | Shells no longer use the low-res frog icon, the normal main window icon is now used instead [amc1]
BUGFIX: UI | Limiting comments in General View to 5k characters under WinXP to avoid crashes due to faulty comctl32.dll [The 8472]
BUGFIX: UI | Setting speed parameters manually now disables autospeed [The 8472]

To use, rename the downloaded AzureusXxxx-Bxx.jar file to Azureus2.jar to replace your old jar in the Azureus program dir: ChangeTheAzureusTwoJarFile
Azureus v2 vs. v3 (Vuze) FAQ
Changelog
Commitlog
Snapshot RSS Feed
Beta Site: http://azureus.sourceforge.net/index_CVS.php

Download:
Azureus3043-B28.jar - 17 Feb 2008 04:27:30 AM [10277654 bytes]
Azureus3043-B28.jar.torrent

Universal Share Downloader v1.3.4.9 + Captcha Kis 1.7.8.10 Latest Version

1 comments

With Installer Menu:
Download: Universal_Share_Downloader.rar (8146 KB)

As Self Extractor NEW!: Universal_Share_Downloader-New.exe
- Mirror1 - Mirror2 - Mirror3 - Mirror5

As Zip Archive:
Download: Mirror2 - Mirror3 - Mirror4

Select your Language after install/first use.
"INSTALL" then " dalje", then "Yes" then "Dalje" and "Exit" . After you open it just go to Language button at the top and change your language. Have fun.
7zip, rar and sfx just extract and make your settings.


Update Servers:
http://usd.altupdate.ru/USD/
http://blackmanos.narod.ru/
Homepage:
http://www.dimonius.ru/dusd.php

Program Virus Free! (not packed with Xcomp packer/Packer.XComp.A) AV firms forced to use UPX, PECompact and commercial exe packer such as ASPack.
Scanned with 2 Engines

Last Minute Private Build:
novaya versiya: USDownloader.exe - Mirror - Mirror - Mirror
MD5 Hash: 151e61c910664515eded7f5ca9a04495
http://www.viruschief.com/report.html?report_id=2c09093a483fa6ce88e21d617ffe662898e25e25

If someone can connect to board.coderz-heaven.de and get me the progri right on top of screen
jigga.no-ip.biz/Screen.png
cause my IP is forwarder for the same IP (ipid.shat.net: HTTP Forwarded For: same ip, Proxy Connection: [None]) website mean a Proxy is in use and show: No Proxies allowed / Keine Proxys erlaubt
no access to the board! please post comment.

16 February 2008

Norman Malware Cleaner 2008/02/13

0 comments
Norman Malware Cleaner 2008/02/13Norman Malware Cleaner is a Norman program utility that may be used to detect and remove specific malicious software (malware).

Note that it should not be used as a substitute for running normal proactive antivirus protection, but rather as a reactive tool to handle systems that are already infected.

By downloading and running the program below it will clean an infected system completely:

kill running processes that are infected
remove infections from disk (including ActiveX components and browser helper objects)
restore correct registry values
remove references created by malware in hosts file
remove windows firewall rules for malicious programs

Scanner Engine Version: 5.91.10
Variants: 1304976

Fize Size: 15684KB
Language: English
OS: Win2000/XP/2003
License: Free
Homepage: http://www.norman.com - http://norman.no
More Security Programs: http://webshop.norman.com


Norman Antivirus & Antispyware License for 3 PC's EUR 39.99:

Key features

* Antivirus
* Norman SandBox
* Rootkit detection
* Antispyware

Norman Security Suite License for 3 PC's EUR 49.99:
+
* Personal Firewall
* Antipharming
* Parental Control

Download: http://download.norman.no/public/Norman_Malware_Cleaner.exe

Detect: BitComet\tools\CometBrowser.exe (infected with W32/Delf.AXSP)

Attention backup your windows hosts file cause it:
Removed hosts entry: all away

By the test here according the log file all entries says: path/filename (Error whilst scanning file: I/O Error) up to the button: A fatal error occured whilst scanning.
0xC0000005 (5900BAF0)


it also Detect from Webroot Software, Inc. ("www.webroot.com"") Window Washer:
\Common Files\Webroot Shared\ShellWash.dll ("Window Washer Shredding Shell Extension for Shredding Files and Folders v6.0.1.409") dll as infected with W32/Agent.CWXB at 0x02AE0000
You can Google all webroot reg. soft download: http://www.google.com/search?q=sales.webroot.com%2Fdownloads%2Fregistered%2Flinks%2F
and get free license here: webroot.com/activate
invalid links like mfpsetup1.exe change to mfpsetup1_1.exe (filename1_1.exe)
Firewall: webroot.com/forms/wdfformhdlr.php?formname=desktopfirewall

Links I uploaded from Google search and catch result sites:
ssfsetup.exe | cssetup.exe | shsetup.exe | pwsetup.exe | wwsetup.exe | mfpsetup.exe | dfsetup.exe | sspsetup1_1.exe | ssbetasetup.exe | accsetup.exe | |


Suggestion: Run detected items in future only in a Sandbox for example:
Sandboxie 3.22 - Sandboxie.v3.01 342.53 KB
Do a Backup before running Norman Malware Cleaner it will make a possible Virus "general clean up".

Virus Detection List Binary:
nvcbin.def.v5.90.00-Detbin1304976-list.7z (874.18 KB)

MD5: ec520eed5ec38cb23fe4f1bc00086b1e
SHA1: 967cd8da763d7af5699128d6a3462b9dbfb6a0a5
CRC32: 81e5ad7d
nvcbin.def.v5.90.00-Detbin1304976-list.TMP File
size extracted: 60.029.317

How to catch the unknown (36MB movie)

Archive