home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: MtE ?? (PC)
- Message-ID: <0005.9211091912.AA05064@barnabas.cert.org>
- Date: 2 Nov 92 14:34:43 GMT
- Sender: virus-l@lehigh.edu
- Lines: 42
- Approved: news@netnews.cc.lehigh.edu
-
- hps@sdf.lonestar.org (Holt Sorenson) writes:
-
- > MtE is the Mutation Encryption Engine developed by Dark Avenger. It
- > changes filesizes, checksum, and other info that would make it
- > possible to detect a virus in a file at runtime so that the virus can
- > continue to hide on your computer. The latest version is .91b, unless
- > DA has released a newer one. You can get it from your favorite AV
- > researcher that trusts you or off a virus bbs. I won't give you any
- > such info (bbs's or copies of the software.) If you don't know
- > assembly, it wouldn't help you much anyway.
-
- Couldn't people get their facts right before posting? Anyway, here is
- the correction:
-
- 1) Dark Avenger has indeed been involved heavily in the development
- of the MtE, but according to some sources, this is not -entirely- his
- product.
-
- 2) All the MtE does by itself is to take a piece of code, encrypt it
- using a random key, generate a random decryptor, prepend the decryptor
- to the code, and return a pointer to the area of memory that contains
- the decryptor and the encrypted code. Nothing more. Not a virus per
- se. Everything else has to be supplied by the virus writer. The
- changes of the file sizes, checksums, and other info that you are
- mentioning come from the virus, not from the MtE. It is perfectly
- possible to write a stealth MtE-based virus, that will hide these
- changes.
-
- 3) The latest available version of MtE is 0.90-beta. What has been
- distributed as 0.91 and what many people blindly believe to be 0.91 is
- just a bugfix in the random number generator (not in the MtE).
-
- 4) No self-respecting anti-virus researcher will distribute the MtE
- package to anybody except other anti-virus researchers.
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.0 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-