home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: SCAN 95b doesn't find MtE in EXE files (PC)
- Message-ID: <0013.9211101922.AA06969@barnabas.cert.org>
- Date: 4 Nov 92 11:27:52 GMT
- Sender: virus-l@lehigh.edu
- Lines: 65
- Approved: news@netnews.cc.lehigh.edu
-
- Stefano_Turci@f0.n462.z9.virnet.bad.se (Stefano Turci) writes:
-
- > I hope you'll be able to read this message, I never wrote in this area
- > before.
-
- You did fine; I was able to read your message. A very interesting one,
- BTW!
-
- > Do you know LZEXE ?
-
- [stuff deleted]
-
- > Well, I converted the files from COM to EXE, and made some scanning
- > tests with the mentioned programs.
-
- Ha, yes, indeed, that's interesting. It's similar to using PKLite or
- LZEXE, or one of the dozen other compressors to hide the initial
- infected file. Of course, all replicants will be detected correctly,
- but if the dropper (because what you did is to create droppers) will
- remain undetected and continue to spread the infection...
-
- > Gobbler 2.99 beta 5
- > TbScan 4.3
-
- > got each infected file.
-
- I find this hard to believe... Did you try Gobbler with unencrypted
- replicants of CryptLab? Did you try TbScan with unencrypted replicants
- of Fear? Those scanners are usually missing these viruses...
-
- > I have personally tried to infect a COM file starting from a .EXE
- > converted file and the infection was made correctly, that is the
- > converted files are still able to propagate the virus, so I think the
- > authors of the "missing-in- action" programs should improve their a-v
- > packages. 8-)
-
- I agree with you. There is no reason why scanners that claim to be
- able to scan inside PKLited and LZEXEd files (and SCAN, F-Prot, and
- VirX do claim to be able to do so; F-Prot even scans inside files
- compressed with other compressors) should be unable to scan inside COM
- files converted to EXE format...
-
- > Well, I'm trying to write my own Mte detector.
-
- If you do, we'll be glad to test it here.
-
- > I run it on a high number of files infected with two Mte-based viruses
- > ( Dedicated and Pogue) and it is able to detect all of the infected
- > files, but how could I say if it will work for *EVERY* mutation and
- > for *EVERY* Mte-based virus ?
-
- > I think it's impossible.
-
- You are right, it's impossible. That's why, our tests can only prove
- that a scanner is NOT able to detect the MtE-based viruses reliably.
- Otherwise we can only say that we have been unable to find an MtE
- replicant that the scanner does not detect.
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.0 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-