We're back online!

Welcome to Leechermods 2026: The Signal is Amplified We’re officially heading into our 20th year! After a long period of strategic silence and low-frequency operations from our previous rural Eastern and Northern European outpost, we have fully transitioned to our new operational cycle. The Current Deployment: We are now alternating between the regulatory sanctuary of Iceland and the high-speed intelligence hubs of Singapore , before relocating to the Mekong Delta Hub for a longer-term signal persistence. Apologies for the recent downtime; I've been busy hardening our DNS configurations for enhanced security (Global HTTPS/TLS). A full site redesign (CSS, HTML, JS, and AI-integrated features) is underway to optimize our new CDN backbone and eliminate legacy graphical debt. Stay tuned. The audit never stops. Status: Moving Out. Moving Up. Operational.

Bitdefender Labs Antivirus Defense Center

Antivirus software - BitDefender - The future of security now!
maybe they mean yesterday, because before yesterdays updates and some mistakes by the unpacking engine for Inno Setup this months which have been fixed quite fast, it was a top security product.
Packer.XComp.A

BitDefender False positive by using:
Packer Compressor XComp098, XComp097 (XComp & XPack)
info:
XComp/XPack: A freeware PE32-imagefile packer/rebuilder
(c)2007 JoKo, Version 0.98 02/18/2007
from:
http://www.soft-lab.de/joko/ExePack.htm

XComp is in some cases better with compression ratio as upx.
You can compare by self:

XComp/XPack PE32-imagefile packer and/or rebuilder - Freeware

UPX: the Ultimate Packer for eXecutables (Freeware) - Homepage

BitSum PeCompact (Commercial, for students limited free) - Homepage


using LZMA compression and pack some exe, dll files, upload the files to:
VirusTotal - Free Online Virus and Malware Scan

Try upx.exe with parameters --lzma , --best , --ultra-brute
PeCompact highest compression
XComp LZMA method
about NsPack By Nort Star (Commercial), I thing is nothing to say. Just look the result in a hexeditor and see the chaos in the headers, no option to clean/optimize this mess up.

Do they have a research team or do they just drop the signatures of whole packers to them virus database if enough users submit a infected file
because someone maybe have used this packer/compressor to pack some viiri into some program applications...
It is the most ridiculous Security System I ever seen.


eMule 0.48a Sins 0.5 packed with XComp 0.98 Analysis

File size: 1701652 bytes
MD5: 2a3fe800941bd32c7495734ed83dc4e1
SHA1: cf8c09fe40369cf921deb1b4e8128914e04ff9bf

sins.exe

Where is the Virus in this sample???

OllyDbg v1.10

Check the files with:
ExEinfo PE by A.S.L.
follow the unpacking hints


BitDefenders unpacking engine mistakes. Scanning a Inno Setup file - Instyler Module 9 !
Problem resolved within 2 hours by 3 following signature updates:

G DATA InternetSecurity 2008 v12 3er - and all Problems are gone?!


G DATA InternetSecurity 2008TotalCare2008_ESP_COV.exe
GDIS2008_COV_ESP.exe
GDAV2008_COV_ESP.exe
GDAV2008_COV_FRA.exe
TotalCare2008_FRA_COV.exe
GDIS2008_COV_FRA.exe
GDAV2008_COV_ENG.exe
TotalCare2008_ENG_COV.exe
GDIS2008_COV_ENG.exe
TotalCare2008_GER_COV.exe
GDAV2008_COV_GER.exe
GDIS2008_COV_GER.exe

Trial 30 days:

All-round protection against all dangers from the internet!
Info Englisch: http://www.gdata.de/trade/GB/productview_technische/820/16/
Info Deutsch: http://www.gdata.de/unternehmen/DE/archive/160/
3 PC Licenses: € 53,95

Armadillo BitTorrent Mods infection with G Data - Dual engine scan !!!
"I've seen that with BitDefender already that this Armadillo BitTorrent Mods tries from alone to phone out even if they are not started, free run if a access rule have been created in firewall"

Comments

  1. This comment has been removed by a blog administrator.

    ReplyDelete
  2. Seh mal jetzt gibts gar keine Signatur mehr
    http://www.virustotal.com/ru/analisis/cab616e6e7766ade2462450ad2234a1c

    Jedoch packt es nicht so gut.

    ReplyDelete
  3. Das sind ja so ne Experten. Warum haun die nicht die alten UPX Versionen vor UPXv1.9 wieder rein als Virus

    ReplyDelete

Post a Comment

We would appreciate if you as readers of our blog, show us some feedback by signing up to this site with Friend Connect.
This will encourage us to publish updates in the future.

Popular posts from this blog

15x avast! Pro Antivirus 1 year 1 PC and 5x avast! Internet Security Version 6 - Review and GiveAway

Malwarebytes Anti-Malware PRO review - write a comment and one from 16 Licenses can be yours