home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!cs.widener.edu!dsinc!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: chess@watson.ibm.com (David M. Chess)
- Newsgroups: comp.virus
- Subject: How do MtE utilizing viruses detect themselves? (PC)
- Message-ID: <0012.9301281842.AA17847@barnabas.cert.org>
- Date: 18 Jan 93 21:07:19 GMT
- Sender: virus-l@lehigh.edu
- Lines: 14
- Approved: news@netnews.cc.lehigh.edu
-
- >From: Malte_Eppert@f535.n240.z2.fidonet.bad.se (Malte Eppert)
- >
- >Can anybody tell me how MtE utilizing viruses detect themselves in an
- >infected file? Or do they reinfect the file each time they attack it,
- >like old Jerusalem? Can't an algorithmic scanner use the method used
- >by MtE itself to detect it?
-
- The MtE itself is just a garbler-generator, and so doesn't contain any
- self-id code of any kind. Viruses that use the MtE just use some sort
- of simple test that will have lots of false positives ("Is there an M
- in the first four bytes of this file" or "Is the seconds field on this
- file 14?" or whatever). This is fine for the virus (since it's OK if
- it fails to infect 1% of files), but unusable for anti-virus programs
- (since a 1% false positive rate would be unacceptable). DC
-