Go to Support Home Page
Go to Online Knowledgebase

  #1  
Old 02-11-2007, 03:57 PM
solcroft solcroft is offline
Advisor
 
Join Date: Jan 2007
Posts: 253
Default What does sequence:novirus:Packed/NSPack mean?

Very often I see this reported as the name of malware that my files are infected by. I'm especially curious as to what the "novirus" part means. Thanks in advance for answers.
Reply With Quote
  #2  
Old 02-11-2007, 08:29 PM
Support's Avatar
Support Support is offline
Moderator
Subscriber
Moderator
 
Join Date: Nov 2006
Posts: 630
Default

Solcroft

Thank you for your report.

I have escalated this report to the Technical Support team.

They will respond to your query soon.

Kind regards,

Nicholas
PC Tools Support Services
Reply With Quote
  #3  
Old 02-12-2007, 04:29 AM
PC-Pete's Avatar
PC-Pete PC-Pete is offline
Advisor
Junior Volunteer
Subscriber
 
Join Date: Jan 2007
Location: Australia
Posts: 346
Default Meaning of "novirusPacked/NSPack"

I think 'novirusPacked/NSPack' is the name PCTAV gives to code that it suspects is related to a particular family of backdoor/trojans, e.g. Ewido/AVG Antispyware might call it 'Hupigon'.

Pete
Reply With Quote
  #4  
Old 02-12-2007, 05:28 AM
solcroft solcroft is offline
Advisor
 
Join Date: Jan 2007
Posts: 253
Default

Hrm. I suppose that's possible, but the part that makes me curious is that NSPack is the name of a "packing" format used to compress and encrypt executable files. PCTAV reports this string by other names as well, the ones I've recall off the top of my head right niw include Packed/Upack and Packed/NSAnti.

The reason why I'm curious as to this is that I'd like to understand what PCTAV means when it flags files as infected by this malware - whether it's triggering its heuristics on a packed file, or simply marking a packed file as somehow corrupt or unusable, or something else. I could then have an easier time sorting out the malware undetected by PCTAV that I intend to submit to PC Tools, so they coul in turn have an easier time analyzing them.
Reply With Quote
  #5  
Old 02-12-2007, 10:43 AM
Inf0Byt3 Inf0Byt3 is offline
Member
 
Join Date: Jan 2007
Posts: 16
Lightbulb

AFAIK this is not an infection! It is a simple executable packed with an exe protector/compressor. For example download FSG and use it on an executable. After that scan it and you'll see that PCTools reports it as Novirus.FSG or something like that. This is because the engine does not have unpacking support for runtime-compressed files like UPX, Petite, FSG, Mew and others.

Note for the developers
This should be added, it would improve the detection rate dramatically !!!
__________________
PCTools proud user !
Reply With Quote
  #6  
Old 02-12-2007, 11:10 AM
solcroft solcroft is offline
Advisor
 
Join Date: Jan 2007
Posts: 253
Default

Ah, damn.

Are you sure PCTAV flags UPX executables as well? Because if it does, and if it performs the judiciously indiscriminate flagging that you describe, this is very bad news for PCTAV...
Reply With Quote
  #7  
Old 02-13-2007, 09:36 AM
Inf0Byt3 Inf0Byt3 is offline
Member
 
Join Date: Jan 2007
Posts: 16
Default

Well, I tested this with all UPX versions I could download and it seems PCTAV scans the file as-is if it's runtime compressed. Some other packers (like morphine for instance) are a bit harder to uncompress and may contain scrambling/encryption so it's a bit hard to write a depacker for each version. I guess that's why PCTAV flags them as potential threats. However the UPX compressed files are not flagged as containing the 'no-virus sequence' so i guess they are scanned as normal exes.

Sorry for talking before testing with the UPX packer.
__________________
PCTools proud user !
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:01 PM.