home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: KEY Press virus & McAfee v97 (PC)
- Message-ID: <0004.9211091912.AA05064@barnabas.cert.org>
- Date: 2 Nov 92 14:13:47 GMT
- Sender: virus-l@lehigh.edu
- Lines: 47
- Approved: news@netnews.cc.lehigh.edu
-
- mcafee@netcom.com (McAfee Associates) writes:
-
- > We've reproduced the problem of SCAN reporting a variant of the
- > KeyPress virus multiple times in a file and will be fixing this in a
- > subsequent version of SCAN.
-
- While you are at it, please also have in mind that:
-
- BetaBoys.Rattle is reported as Rattle [Rttl] and Mexican [Mex];
- Burger.* are reported as Burger [Burger] and FamilyQ [FQ];
- Cascade.1701.D is reported as JoJo [JoJo] and Yap [Yap];
- Crew.* (except Crew.1.C) are reported as Crew-2480 [2480] and FamilyM [FM];
- FaxFree.Topo is reported as Lamer [Lam] and Topo [Topo];
- Happy_New_Year.1600 is reported as Happy N.Y. [HNY] and Voronezh [Vor];
- Horse.1154.* are reported as 512 [512] and Horse [Hrs] (in some files only);
- Jerusalem.Mummy.1_2 is reported as Mummy [Mum] and FamE [FE];
- Jerusalem.Timor is reported as 1241 [1241] and Jerusalem [Jeru];
- Leprosy.G is reported as infected twice by Leper [OW];
- Leprosy.Plague is reported as Viper [Vip] and Plague [Plg];
- MShark is reported as FamN [FN] and FamM [FM];
- Murphy.Brothers is reported as Brothers [Bro] and 1530 [1530];
- Murphy.Tormentor.* are reported as LixoNuke [Lix] and Murphy [Murphy];
-
- Sorry for the long list, but I hope that it might help to some other
- readers too. Hope you'll fix that in your next version.
-
- > >places... Unfortunately, this is not always the case, which explains
- > >why SCAN does not detect Commander Bomber infections reliably - the
- > >virus can reside just anywhere in the file and control is transferred
- > >to it in a non-trivial way...
-
- > Are you sure of this? The reason I ask is that does not always use
- > the "top-and-tail" (or "beginning-and-end," etc.) method of searching
- > for file-infecting viruses, especially if a "fragmentation attack" is
- > performed.
-
- Am I sure about -what-? That SCAN 97 does not detect Commander Bomber
- reliably? Yes, I am sure about it. It doesn't detect it reliably. It
- misses this virus in some of the infected files.
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.0 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-