home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: cjkuo@ccmail.norton.com (Jimmy Kuo)
- Newsgroups: comp.virus
- Subject: Re: SCAN 95b doesn't find MtE in EXE files (PC)
- Message-ID: <0004.9211101922.AA06969@barnabas.cert.org>
- Date: 3 Nov 92 20:31:09 GMT
- Sender: virus-l@lehigh.edu
- Lines: 46
- Approved: news@netnews.cc.lehigh.edu
-
- Stefano Turci writes:
- [after converting MtE infected COM files to EXEs and then LZEXE'd them]
- >The results were a bit strange, in fact:
- > F-prot 2.05
- > Scan 97
- > VirX 2.4
- >missed *ALL* the converted files, while
- > Gobbler 2.99 beta 5
- > TbScan 4.3
- >got each infected file.
-
- >The viruses in the files missed by F-prot, Scan and VirX in the .EXE
- >form were all found out by the same programs in the original .COM
- >version.
-
- >I have personally tried to infect a COM file starting from a .EXE
- >converted file and the infection was made correctly, that is the
- >converted files are still able to propagate the virus, so I think the
- >authors of the "missing-in- action" programs should improve their a-v
- >packages. 8-)
-
- These results are not surprising nor should they be alarming. There's
- a ever going argument in the anti-virus field relating to the premise
- that anti-virus software must be able to detect every absolute
- infected file. The opposing side argues that it is not necessary to
- detect such files as those above (or specific files found in some
- reviewers' collections) which do not create children of the same form.
-
- The argument for the second opinion says that if you detect the
- infected form of the children, you will know if something is going on
- in the computer. Once something is known to be affecting the
- computer, theories related to integrity checking can take over. Files
- such as those created above and certain files in reviewers'
- collections cannot spread in that convoluted form and need not worry
- endusers. (A version of this argument applies to whether it is
- necessary to detect absolutely 100% of MtE mutations, i.e. integrity
- checking takes over.)
-
- It should be the form that propagates that we worry about. And though
- you didn't note it, I'm sure all the files infected by your creations
- were detected by all the packages above. Thus end-users need not
- worry about your peculiar forms of MtE files because you're not going
- to put those files on anyone else's computer. :-)
-
- Jimmy Kuo cjkuo@ccmail.norton.com
- Norton AntiVirus Research
-