home *** CD-ROM | disk | FTP | other *** search
- T R I D E N T P O L Y M O R P H I C E N G I N E D E T E C T O R
-
- D E M O N S T R A T I O N V E R S I O N
-
- (C) 1993 by CSE Ltd. & Thunderbyte B.V.
-
- Computer Security Engineers Ltd. Thunderbyte B.V.
- P.O. Box 45610 P.O. Box 1380
- 2504 BA The Hague 6501 BJ Nijmegen
- The Netherlands The Netherlands
- Phone: +31 70 3622269 Phone: +31 80 787881
- Fax : +31 70 3652286 Fax : +31 80 789186
-
-
-
- T R I D E N T P O L Y M O R P H I C E N G I N E D E T E C T O R
-
- D E M O N S T R A T I O N V E R S I O N
-
- (C) 1993 by CSE Ltd. & Thunderbyte B.V.
-
-
- In 1992, a virus-author using the name Dark Avenger released a highly
- mutating polymorphic module called the Mutation Engine (MtE). Anti-virus
- developers all spent months to develope an accurate solution for this
- problem as vira using the MtE are able to have several million 'faces'.
- Even after one year since the MtE was first used, several notorious
- anti-virus programs are still not able to detect the MtE-based vira
- reliable.
-
- In January 1993, a new mutation engine called Trident Polymorphic
- Engine (TPE) was written and released by somebody calling himself
- 'Masud Khafir of the TridenT virus research group'. The TPE is based on
- the MtE, but solved several bugs which are present in the MtE. Furthermore
- the TPE has the ability to use almost every instruction within its
- decryption routine thus making it more difficult to detect it. There are
- no holes inside the generated decryption-routines like MtE generated
- decryption-routines which makes it less difficult to detect.
-
- Despite the difficulty of detecting TPE-based vira, Frans Veldman of
- Thunderbyte B.V. and Righard Zwienenberg of Computer Security Engineers Ltd,
- have developed an algorithm which does detect the TPE-based vira. The next
- version of Thunderbyte B.V.'s scanner TBSCAN and CSE's scanner PCVP-SCAN
- will include the algorithm which do detect these vira.
-
- Since users always want to test scanners and its algorithms, this
- special demonstration program has been created. The algorithm used within
- this program is almost equal to the one used in both the scanners, but
- has been limited to only detect the samples which are generated by the
- TPE-GEN.COM file which is distributed within every released TPE-archive
- version.
-
- Information about the products mentioned above may be obtained from
- the above mail and telephone numbers. The authors of the algorithm can
- be reached at these numbers as well.
-
- Frans Veldman March 5, 1993 Righard Zwienenberg
-
-
-