home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!cs.utexas.edu!zaphod.mps.ohio-state.edu!cis.ohio-state.edu!news.sei.cmu.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: New way of opeing files??? (PC)
- Message-ID: <0020.9301221631.AA12947@barnabas.cert.org>
- Date: 15 Jan 93 05:50:16 GMT
- Sender: virus-l@lehigh.edu
- Lines: 32
- Approved: news@netnews.cc.lehigh.edu
-
- antkow@sis.uucp (Chris Antkow) writes:
-
- > Apparently, there is a new way of opening files which some AV
- > Utilities don't catch. I've heard that the NuKE group is starting to
- > use function AX,6C00h/INT 21h to open files...
-
- First, the method is not new - it was introduced in DOS 4.0. Second,
- it is not backwards compatible - if a virus uses it, it will not run
- under DOS 3.30 and below. Third, there are already viruses using this
- function (or intercepting it) - since quite a lot of time... :-)
- Fourth, the knowledge of the members of the NuKE group about the
- internals of DOS is not very impressive, if one takes a look at the
- incredibly boring and silly viruses they continue to produce...
-
- > Can anyone confirm the
- > use of this function and are there any AV programs that trap this
- > function?
-
- I don't know, but why bother? First, even if a monitoring program
- traps this function, it can be easily bypassed, using one of the many
- tunneling techniques. Second, with this function it is possible only
- to open or create (i.e., destroy) a file. If the virus wants to infect
- it, it has to Write to it, and most monitoring programs I am aware of,
- do trap the write operation...
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-