home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: mcafee@netcom.com (McAfee Associates)
- Newsgroups: comp.virus
- Subject: Re: SCAN 95b doesn't find MtE in EXE files (PC)
- Message-ID: <0011.9211091912.AA05064@barnabas.cert.org>
- Date: 3 Nov 92 00:41:41 GMT
- Sender: virus-l@lehigh.edu
- Lines: 32
- Approved: news@netnews.cc.lehigh.edu
-
- bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev) writes:
-
- [...description of MtE virus samples deleted for brevity...]
- >Just some more information. Of the above missed samples, 141 (of 142)
- >Questos were unencrypted and 143 (out of 145) correctly infected
- >Groove EXE files. The fact that they are unencrypted, means that they
- >can be easily detected, if SCAN contained a signature, picked from the
- >body of the MtE (not from the body of the particular virus). This is
- >so obvious, that I cannot figure out why SCAN is not doing it
- >already... Let's hope that it will be included in the next version.
- [...rest of message deleted...]
-
- If VIRUSCAN did not pick up unencrypted copies of a virus, that means
- that we do not have a copy of the virus. Readers may wish to note
- that sometimes the MtE produces an "unencrypted" virus, that is, one
- where no MtE encryption is performed. In this case, no MtE virus
- would be found, and VIRUSCAN (SCAN) would have to look for the actual
- virus code. If we do not have a copy of that particular MtE-based
- virus, then unencrypted copies will not be found until we receive a
- copy and analyse it.
-
- Regards,
-
- Aryeh Goretsky
- Technical Support
- - --
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- McAfee Associates, Inc. | Voice (408) 988-3832 | INTERNET:
- 3350 Scott Blvd, Bldg 14 | FAX (408) 970-9727 | mcafee@netcom.COM
- Santa Clara, California | BBS (408) 988-4004 | CompuServe ID: 76702,1714
- 95054-3107 USA | USR HST Courier DS | or GO MCAFEE
- Support for SENTRY/SCAN/NETSCAN/VSHIELD/CLEAN/WSCAN/NETSHIELD/TARGET/CONFIG MGR
-