Discussion about the binary newsgroups and how to successfully participate in the file-exchange
Postby Mr Edd » Sun Nov 09, 2008 6:16 am

Is it just me or have the binary newsgroups been flooded with malware recently? It's getting so it's hard to find a genuine file these days I have wade through floods of trojans, etc. Usually they're not that hard to detect they're usually only kB's in size, and have multiple files with different names but with exactly the same filelength, sometimes dozens of them. If I roughly know what the filesize ought to be I can set to filter by size, but even so it's getting really annoying. It's getting to be as bad as Kazaa used to be. Newsgroups used to be free from such crap. It's almost enough to force me back to BitTorrent!
Postby chainmail » Sun Nov 09, 2008 9:00 am

Many groups such as a.b.warez have become buried under such a huge flood of trojans that it's become hard to find any real files anymore. This is not "classic" spam, but nasty malware like keyloggers and backdoor trojans that are being posted under many different names to the binary newsgroups in massive numbers. When using a binary usenet search engine, you are likely to get hit with a flood of trojans no matter what your search terms might be. It's only been in the last year or two that this has developed, and the amount of trojans spammed on usenet seems to double about every month or two.

This is one spammer's flood of trojans from someone named " (Jenny)"

Here's header ID details from one of these spammed trojan files

Code: Select all
From: (Jenny)
Newsgroups: alt.binaries.comp,,alt.binaries.warez,
Subject: Premiere_NDS_Crack.exe (1/9)
X-Newsposter: YENC-POWER-POST-A&A-v11b (Modified POWER-POST www.We don't like spam here
Message-ID: <part1of9.9KF6SAIoPwh1q3WfFL9W@powerpost2000AA.local>
Lines: 3008
NNTP-Posting-Date: Sun, 09 Nov 2008 08:18:27 UTC
Organization: Firstload
Date: Sun, 09 Nov 2008 08:18:27 GMT
Xref: Hurricane-Charley alt.binaries.comp:44517652 alt.binaries.warez:37707883
X-Received-Date: Sun, 09 Nov 2008 08:18:58 UTC (s02-b31)

This particular file is 3.08MB (although the size varies among the hundreds spammed) and is identified by several AVs as "Zlob Trojan Downloader" (which is a backdoor trojan) but most AVs on do not even recognize it as any kind of virus. This may be because the file hash/signature changes so frequently.

Trying to filter out this spammed malware is going to be a continuous challenge, since everything about them - the filenames, file sizes, poster's name, file extensions, etc - can vary to a great degree, and the spammers will of course evolve alongside anti-spam filters.

The only way these virus distributors are going to be stopped is if people start reporting them to the spammer's newsgroup providers where the stuff was originally posted. Sadly, many of the popular binary grabbers and NZB downloaders - unlike traditional newsreaders - are apparently not able to extract the message ID info, which is needed to report usenet abuse to the originating NSP. Maybe this is why these trojan spammers seem to rarely get reported, compared to spammers in text newsgroups, and the same perpetrators continue plying their trade day after day.
Postby paolari » Fri Jun 05, 2009 12:50 am

How can i clean/delete a trojan from an infectected program without hurting the program?
Postby ejonesss » Fri Jun 05, 2009 2:10 am do not even recognize it as any kind of virus. This may be because the file hash/signature changes so frequently.

instead of just the hash couldnt the way the program acts be scanned for?

for example if you want to scan for a key logger by scanning every program and looking for code that is designed to intercept keys and store them and either quarantine or delete that program.

unfortunately it probably will flag legit programs like the system clipboard or macro programs like quickeys because they record the keyboard when you want to make it retype something,email, word programs and such.

but that may be the only way to insure it catches the bad stuff.
Postby HouseCrowd » Fri Jun 05, 2009 6:52 am

paolari wrote:How can i clean/delete a trojan from an infectected program without hurting the program?

Most decent anti-virus software will attempt to repair infected files rather than delete them (where possible). Just update your AV software and scan the file.
