<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Hero &#187; Packed</title>
	<atom:link href="http://sechero.com/tag/packed/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Mon, 12 Jul 2010 23:27:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs</title>
		<link>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs-3/</link>
		<comments>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs-3/#comments</comments>
		<pubDate>Mon, 25 May 2009 21:44:51 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Packed]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Bugtraq: PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs URL: http://www.securityfocus.com/archive/1/503800]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/archive/1/503800">Bugtraq: PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs</a></h1>
</p>
<p>PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs
<p>URL: <a href="http://www.securityfocus.com/archive/1/503800">http://www.securityfocus.com/archive/1/503800</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs</title>
		<link>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs-2/</link>
		<comments>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs-2/#comments</comments>
		<pubDate>Mon, 25 May 2009 20:30:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Packed]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs &#60;!&#8211; Envelope-to: email@address Delivery-date: Mon, 25 May 2009 21:27:50 +0100 Received: from outgoing.securityfocus.com ([205.206.231.27] helo=outgoing3.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1M8gly-0007Hw-9E for email@address; Mon, 25 May 2009 21:27:50 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing3.securityfocus.com (Postfix) with QMQP id DBED2236FD1; Mon, 25 May [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=86266">PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Mon, 25 May 2009 21:27:50 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.27] helo=outgoing3.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1M8gly-0007Hw-9E 	for email@address; Mon, 25 May 2009 21:27:50 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing3.securityfocus.com" title="http://outgoing3.securityfocus.com" target="_blank">outgoing3.securityfocus.com</a> (Postfix) with QMQP 	id DBED2236FD1; Mon, 25 May 2009 14:24:55 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 1040 invoked from network); 25 May 2009 16:18:46 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;         d=gmail.com; s=gamma;         h=domainkey-signature:received:received:message-id:from:to:cc:subject          :date:mime-version:content-type:content-transfer-encoding:x-priority          <img src='http://sechero.com/wp-includes/images/smilies/icon_mad.gif' alt=':x' class='wp-smiley' /> -msmail-priority:x-mailer:x-mimeole;         bh=U5avKvFgz5HgwmGOPr5cworxmwPKe2LmHj3+hLQtZZI=;         b=j6LfEK5NoNoXHMy+lgszx0ngySphcfbTM0sWBCx+krjSnStEA10fCcsipy65BX61gC          KzcCKNRGElmrwTVrluhXnm/ZBLdrePV56tHHcfELZIYlc7BqXnjhAtmEsNh4PT4LvIDV          46ZQUqqx5fS2HQ04NVJN5fgNimKt2DriYIWeM= DomainKey-Signature: a=rsa-sha1; c=nofws;         d=gmail.com; s=gamma;         h=message-id:from:to:cc:subject:date:mime-version:content-type          :content-transfer-encoding:x-priority:x-msmail-priority:x-mailer          <img src='http://sechero.com/wp-includes/images/smilies/icon_mad.gif' alt=':x' class='wp-smiley' /> -mimeole;         b=PwoQeDWinTeE/nVvAmm+Znj0NlYQQVHEIxYUMxWV97U2GOsTeluyCgwlDGjw79ZlhU          M3slnaKtX4rSLlZgQqBwkyoLe8JAZi6TIUUfdeplxfY/a3UW5k5bOfRGjbBP0KEqd0Lt          RWxRH8Jcvzdf6Aybe4UpFRAKlQoM4POXTPz2w= Message-ID: &lt;C27C7C74DC944F639243FA91F5792010@DIED&gt; Cc: &quot;SBUGTRAQ&quot; &lt;bugtraq@securityfocus.com&gt; MIME-Version: 1.0 Content-Type: text/plain; 	format=flowed; 	charset=&quot;iso-8859-2&quot;; 	reply-type=original Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.5512 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5579 X-IMAPbase: 1176125385 9184 Status: O X-UID: 9184 Content-Length: 1297 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs</title>
		<link>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs/</link>
		<comments>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs/#comments</comments>
		<pubDate>Mon, 25 May 2009 16:18:32 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Packed]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs Posted by Piotr Bania on May 25 ABSTRACT Nowadays most of the malware applications are either packed or protected. This techniques are applied especially to evade signature based detectors and also to complicate the job of reverse engineers or security analysts. The time one must spend [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/May/0204.html">PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs</a></h1>
</p>
<p>Posted by Piotr Bania on May 25
</p>
<p>
<p> ABSTRACT <br /> 
<p>Nowadays most of the malware applications are either packed or protected.  <br /> This techniques are applied especially to evade signature based detectors  <br /> and also to complicate the job of reverse engineers or security analysts.  <br /> The time one must spend on unpacking or decrypting malware&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/May/0204.html">http://seclists.org/fulldisclosure/2009/May/0204.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/generic-unpacking-of-self-modifying-aggressive-packed-binary-programs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Sims 3 Leaked Two Weeks Before Its Launch</title>
		<link>http://sechero.com/the-sims-3-leaked-two-weeks-before-its-launch/</link>
		<comments>http://sechero.com/the-sims-3-leaked-two-weeks-before-its-launch/#comments</comments>
		<pubDate>Tue, 19 May 2009 01:21:52 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://sechero.com/the-sims-3-leaked-two-weeks-before-its-launch/</guid>
		<description><![CDATA[The Sims 3 Leaked Two Weeks Before Its Launch It can¡¦t get any better than this for gamers: The Sims 3 video game has been leaked on torrents two weeks before its official release. This is just unbelievable, as a few weeks ago, the an unfinished version of the Wolverine movie was leaked on torrents [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31350">The Sims 3 Leaked Two Weeks Before Its Launch</a></h1>
</p>
<p>It can¡¦t get any better than this for gamers: The Sims 3 video game has been leaked on torrents two weeks before its official release. This is just unbelievable, as a few weeks ago, the an unfinished version of the Wolverine movie was leaked on torrents about 30 days before its premiere. According to Electronic Arts and Maxis, the game will officially be released on Junde 2, and for the moment none of them reacted on The Sims 3 leak on torrents.</p>
<p>We can say that hackers and pirates have won another battle against publishers and distributors, and this will have to hurt EA a lot. For the moment we can¡¦t tell for sure if the game is real as the packed/unpacked leaks are sized somewhere near 5GB. The small size of the game makes us think that this is not the actual game, but maybe it¡¦s an unfinished version of The Sims 3 life simulation game.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31350">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31350</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/the-sims-3-leaked-two-weeks-before-its-launch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Bulletin for May 2009</title>
		<link>http://sechero.com/microsoft-security-bulletin-for-may-2009/</link>
		<comments>http://sechero.com/microsoft-security-bulletin-for-may-2009/#comments</comments>
		<pubDate>Tue, 12 May 2009 08:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Microsoft Security Bulletin for May 2009 The table below lists the Microsoft vulnerabilities for May. MS Bulletin Number Microsoft Bulletin Title Severity Impact of Vulnerability Affected Software CVE ID MS09-017 Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340) Critical Remote Code Execution Microsoft Office 2009-0220 2009-0221 2009-0222 2009-0223 2009-0224 2009-0225 2009-0226 2009-0227 [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.fortiguardcenter.com/advisory/FGA-2009-18.html">Microsoft Security Bulletin for May 2009</a></h1>
</p>
<p>The table below lists the Microsoft vulnerabilities for May.<br />
<table class="threats">
<tr align="center" class="tdBoldBgGray">
<th>MS Bulletin Number </th>
<th width="33%">Microsoft Bulletin Title</th>
<th width="10%">Severity</th>
<th width="15%">Impact of Vulnerability</th>
<th width="20%">Affected Software</th>
<th width="12%">CVE ID</th>
<tr>
<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx">MS09-017</a></td>
<td>Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340)</td>
<td align="center">Critical</td>
<td align="center">Remote Code Execution</td>
<td>Microsoft Office</td>
<td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0220">2009-0220</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0221">2009-0221</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0222">2009-0222</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0223">2009-0223</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0224">2009-0224</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0225">2009-0225</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0226">2009-0226</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0227">2009-0227</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0556">2009-0556</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1128">2009-1128</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1129">2009-1129</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1130">2009-1130</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1131">2009-1131</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1137">2009-1137</a>  </td>
</tr>
</table>
<h2 class="title">Threat Remediation</h2>
<p>
<p>Fortinet provides coverage on Microsoft vulnerabilities in May 2009.</p>
<table class="threats">
<tr align="center" class="tdBoldBgGray">
<th>CVE Number</th>
<th width="70%">Signature Name</th>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0220">CVE-2009-0220</a></td>
<td>MS.PowerPoint.PP4X322.DLL.Code.Execution</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0221">CVE-2009-0221</a></td>
<td>MS.PowerPoint.Atom.Integer.Overflow</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0222">CVE-2009-0222</a></td>
<td>MS.PowerPoint.PP4X322.DLL.PackedData.Buffer.Overflow</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0223">CVE-2009-0223</a></td>
<td>MS.Powerpoint.Converter.Code.Execution</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0224">CVE-2009-0224</a></td>
<td>MS.Powerpoint.Objects.Size.Heap.Overflow</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cvemitre.org/cgi-bin/cvename.cgi?name=2009-0225">CVE-2009-0225</a></td>
<td>MS.Powerpoint.Old.File.Format.Parsing.Code.Execution</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0226">CVE-2009-0226</a></td>
<td>MS.PowerPoint.File.Format.Converter.Code.Execution</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0227">CVE-2009-0227</a></td>
<td>MS.PowerPoint.File.Stack.Buffer.Overrun</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0556">CVE-2009-0556</a></td>
<td>MS.PowerPoint.OutlineTextRefAtom.Memory.Corruption</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1128">CVE-2009-1128</a></td>
<td>MS.PowerPoint.PSTSoundEntity.Code.Execution</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1129">CVE-2009-1129</a></td>
<td>MS.PowerPoint.PSTExEmbed.Code.Execution</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1130">CVE-2009-1130</a></td>
<td>MS.PowerPoint.HashCode10.Code.Execution</a></td>
</tr>
<tr>
<td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1131">CVE-2009-1131</a></td>
<td>MS.PowerPoint.CurrentUserAtom.Remote.Code.Execution</a></td>
</tr>
</table>
<p>For more information on new and enhanced signatures, visit the <a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="http://www.fortiguardcenter.com/contactus.php">Contact Us</a> web page.</p>
<p>
<h2 class="title">Document History</h2>
<p>
<table class="threats">
<tr align="center" class="tdBoldBgGray">
<th width="25%">Revision Date</th>
<th width="15%">Version Number</th>
<th width="60%"> </th>
</tr>
<tr>
<td align="center">Tuesday, May 12, 2009</td>
<td align="center">1</td>
<td>Initial Documentation.</td>
</tr>
</table>
<p><b>Reference:</b>
<ul>
<li>Microsoft Security Bulletin Summary for May 2009: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx</a></li>
</ul>
<p>URL: <a href="http://www.fortiguardcenter.com/advisory/FGA-2009-18.html">http://www.fortiguardcenter.com/advisory/FGA-2009-18.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/microsoft-security-bulletin-for-may-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4005</title>
		<link>http://sechero.com/4005/</link>
		<comments>http://sechero.com/4005/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 16:59:49 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4005 JS/TrojanDownloader.Iframe.NDX, Win32/Adware.Antivirus2008, Win32/Adware.Coolezweb, Win32/Adware.NewWeb (2), Win32/Adware.SystemSecurity, Win32/Agent.WPI, Win32/Autoit.CL, Win32/AutoRun.IRCBot.V, Win32/Packed.Crpak.Gen, Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NMY (4), Win32/TrojanClicker.VB.NFM, Win32/TrojanDownloader.VB.NXG (2), Win32/Waledac.IT (5), Win32/Waledac.IU URL: http://www.eset.com/joomla/index.php?option=com_content&#38;task=view&#38;id=5938&#38;Itemid=26]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=5938&amp;Itemid=26">4005</a></h1>
</p>
<p>JS/TrojanDownloader.Iframe.NDX, Win32/Adware.Antivirus2008, Win32/Adware.Coolezweb, Win32/Adware.NewWeb (2), Win32/Adware.SystemSecurity, Win32/Agent.WPI, Win32/Autoit.CL, Win32/AutoRun.IRCBot.V, Win32/Packed.Crpak.Gen, Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NMY (4), Win32/TrojanClicker.VB.NFM, Win32/TrojanDownloader.VB.NXG (2), Win32/Waledac.IT (5), Win32/Waledac.IU
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=5938&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=5938&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4005/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>6661 (bitdefender_antivirus)</title>
		<link>http://sechero.com/6661-bitdefender_antivirus/</link>
		<comments>http://sechero.com/6661-bitdefender_antivirus/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://sechero.com/6661-bitdefender_antivirus/</guid>
		<description><![CDATA[CVE-2008-6661 (bitdefender_antivirus) Multiple integer overflows in the scanning engine in Bitdefender for Linux 7.60825 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed (1) NeoLite and (2) ASProtect packed PE file. URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6661]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6661">CVE-2008-6661 (bitdefender_antivirus)</a></h1>
</p>
<p>Multiple integer overflows in the scanning engine in Bitdefender for Linux 7.60825 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed (1) NeoLite and (2) ASProtect packed PE file.
<p>URL: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6661">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6661</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/6661-bitdefender_antivirus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WMF!sd6, Packed.Generic.181..</title>
		<link>http://sechero.com/wmfsd6-packedgeneric181/</link>
		<comments>http://sechero.com/wmfsd6-packedgeneric181/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 18:54:27 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/wmfsd6-packedgeneric181/</guid>
		<description><![CDATA[Mal/Behav-009, Trojan.Win32.StartPage, Exploit.IMG-WMF!sd6, Packed.Generic.181.. URL: http://www.threatexpert.com/report.aspx?md5=d7638903e602c080eed9130a5c7d3d5f]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=d7638903e602c080eed9130a5c7d3d5f">Mal/Behav-009, Trojan.Win32.StartPage, Exploit.IMG-WMF!sd6, Packed.Generic.181..</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=d7638903e602c080eed9130a5c7d3d5f">http://www.threatexpert.com/report.aspx?md5=d7638903e602c080eed9130a5c7d3d5f</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/wmfsd6-packedgeneric181/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Packed.Generic.202, Vundo.gen.w, Troj/Virtum-Gen, Trojan:Win32/Vundo.gen!BB..</title>
		<link>http://sechero.com/packedgeneric202-vundogenw-trojvirtum-gen-trojanwin32vundogenbb-9/</link>
		<comments>http://sechero.com/packedgeneric202-vundogenw-trojvirtum-gen-trojanwin32vundogenbb-9/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 16:35:14 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/packedgeneric202-vundogenw-trojvirtum-gen-trojanwin32vundogenbb-9/</guid>
		<description><![CDATA[Packed.Generic.202, Vundo.gen.w, Troj/Virtum-Gen, Trojan:Win32/Vundo.gen!BB.. URL: http://www.threatexpert.com/report.aspx?md5=4be7fb3ea1584dc7ee732a04e2ac127f]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=4be7fb3ea1584dc7ee732a04e2ac127f">Packed.Generic.202, Vundo.gen.w, Troj/Virtum-Gen, Trojan:Win32/Vundo.gen!BB..</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=4be7fb3ea1584dc7ee732a04e2ac127f">http://www.threatexpert.com/report.aspx?md5=4be7fb3ea1584dc7ee732a04e2ac127f</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/packedgeneric202-vundogenw-trojvirtum-gen-trojanwin32vundogenbb-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan-Dropper.Vb, Backdoor.ProRAT.K, Trojan.TDss, Packed.Generic.202..</title>
		<link>http://sechero.com/trojan-droppervb-backdoorproratk-trojantdss-packedgeneric202/</link>
		<comments>http://sechero.com/trojan-droppervb-backdoorproratk-trojantdss-packedgeneric202/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 16:10:46 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://sechero.com/trojan-droppervb-backdoorproratk-trojantdss-packedgeneric202/</guid>
		<description><![CDATA[Trojan-Dropper.Vb, Backdoor.ProRAT.K, Trojan.TDss, Packed.Generic.202.. URL: http://www.threatexpert.com/report.aspx?md5=7fa61f8b1ed99c1699c431790b990d36]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=7fa61f8b1ed99c1699c431790b990d36">Trojan-Dropper.Vb, Backdoor.ProRAT.K, Trojan.TDss, Packed.Generic.202..</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=7fa61f8b1ed99c1699c431790b990d36">http://www.threatexpert.com/report.aspx?md5=7fa61f8b1ed99c1699c431790b990d36</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/trojan-droppervb-backdoorproratk-trojantdss-packedgeneric202/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Infostealer, Packed.Win32.Krap.c, Mal/EncPk-FH, Backdoor:Win32/Bifrose.AE..</title>
		<link>http://sechero.com/infostealer-packedwin32krapc-malencpk-fh-backdoorwin32bifroseae/</link>
		<comments>http://sechero.com/infostealer-packedwin32krapc-malencpk-fh-backdoorwin32bifroseae/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 14:42:06 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/infostealer-packedwin32krapc-malencpk-fh-backdoorwin32bifroseae/</guid>
		<description><![CDATA[Infostealer, Packed.Win32.Krap.c, Mal/EncPk-FH, Backdoor:Win32/Bifrose.AE.. URL: http://www.threatexpert.com/report.aspx?md5=a4fb655c5f9bf7ab68261c584637d5c7]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=a4fb655c5f9bf7ab68261c584637d5c7">Infostealer, Packed.Win32.Krap.c, Mal/EncPk-FH, Backdoor:Win32/Bifrose.AE..</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=a4fb655c5f9bf7ab68261c584637d5c7">http://www.threatexpert.com/report.aspx?md5=a4fb655c5f9bf7ab68261c584637d5c7</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/infostealer-packedwin32krapc-malencpk-fh-backdoorwin32bifroseae/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mal/TibsPk-A, Trojan.Spammer, Packed.Generic.209, Trojan.Win32.Inject.qwd, New..</title>
		<link>http://sechero.com/maltibspk-a-trojanspammer-packedgeneric209-trojanwin32injectqwd-new/</link>
		<comments>http://sechero.com/maltibspk-a-trojanspammer-packedgeneric209-trojanwin32injectqwd-new/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 07:17:28 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/maltibspk-a-trojanspammer-packedgeneric209-trojanwin32injectqwd-new/</guid>
		<description><![CDATA[Mal/TibsPk-A, Trojan.Spammer, Packed.Generic.209, Trojan.Win32.Inject.qwd, New.. URL: http://www.threatexpert.com/report.aspx?md5=a156bccc0b8bd1ca1ce3810a4e79f82b]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=a156bccc0b8bd1ca1ce3810a4e79f82b">Mal/TibsPk-A, Trojan.Spammer, Packed.Generic.209, Trojan.Win32.Inject.qwd, New..</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=a156bccc0b8bd1ca1ce3810a4e79f82b">http://www.threatexpert.com/report.aspx?md5=a156bccc0b8bd1ca1ce3810a4e79f82b</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/maltibspk-a-trojanspammer-packedgeneric209-trojanwin32injectqwd-new/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W32.Harakit, Packed.Win32.Klone.bj, Worm:AutoIt/Renocide.gen!A</title>
		<link>http://sechero.com/w32harakit-packedwin32klonebj-wormautoitrenocidegena/</link>
		<comments>http://sechero.com/w32harakit-packedwin32klonebj-wormautoitrenocidegena/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 06:54:20 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/w32harakit-packedwin32klonebj-wormautoitrenocidegena/</guid>
		<description><![CDATA[W32.Harakit, Packed.Win32.Klone.bj, Worm:AutoIt/Renocide.gen!A URL: http://www.threatexpert.com/report.aspx?md5=e025b36629d5ce396fffe658b9a8ba38]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=e025b36629d5ce396fffe658b9a8ba38">W32.Harakit, Packed.Win32.Klone.bj, Worm:AutoIt/Renocide.gen!A</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=e025b36629d5ce396fffe658b9a8ba38">http://www.threatexpert.com/report.aspx?md5=e025b36629d5ce396fffe658b9a8ba38</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/w32harakit-packedwin32klonebj-wormautoitrenocidegena/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Packed.Win32.Krap.i, Spam-Mailbot.h.gen.a, Spammer:Win32/Tedroo.A..</title>
		<link>http://sechero.com/packedwin32krapi-spam-mailbothgena-spammerwin32tedrooa/</link>
		<comments>http://sechero.com/packedwin32krapi-spam-mailbothgena-spammerwin32tedrooa/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 03:47:08 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/packedwin32krapi-spam-mailbothgena-spammerwin32tedrooa/</guid>
		<description><![CDATA[Packed.Win32.Krap.i, Spam-Mailbot.h.gen.a, Spammer:Win32/Tedroo.A.. URL: http://www.threatexpert.com/report.aspx?md5=e03ec08c6068edc43d4e0aac119250ac]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=e03ec08c6068edc43d4e0aac119250ac">Packed.Win32.Krap.i, Spam-Mailbot.h.gen.a, Spammer:Win32/Tedroo.A..</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=e03ec08c6068edc43d4e0aac119250ac">http://www.threatexpert.com/report.aspx?md5=e03ec08c6068edc43d4e0aac119250ac</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/packedwin32krapi-spam-mailbothgena-spammerwin32tedrooa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Packed.Generic.209, Trojan-Downloader.Win32.Agent.bmrg, Generic.dx..</title>
		<link>http://sechero.com/packedgeneric209-trojan-downloaderwin32agentbmrg-genericdx/</link>
		<comments>http://sechero.com/packedgeneric209-trojan-downloaderwin32agentbmrg-genericdx/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 02:03:44 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Packed]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/packedgeneric209-trojan-downloaderwin32agentbmrg-genericdx/</guid>
		<description><![CDATA[Packed.Generic.209, Trojan-Downloader.Win32.Agent.bmrg, Generic.dx.. URL: http://www.threatexpert.com/report.aspx?md5=e28b7cfec3df1c7ce3e0977ef6588db0]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.threatexpert.com/report.aspx?md5=e28b7cfec3df1c7ce3e0977ef6588db0">Packed.Generic.209, Trojan-Downloader.Win32.Agent.bmrg, Generic.dx..</a></h1>
</p>
<p>
<p>URL: <a href="http://www.threatexpert.com/report.aspx?md5=e28b7cfec3df1c7ce3e0977ef6588db0">http://www.threatexpert.com/report.aspx?md5=e28b7cfec3df1c7ce3e0977ef6588db0</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/packedgeneric209-trojan-downloaderwin32agentbmrg-genericdx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

