Re: virus code is never executed - virus or not?

"Christopher T. Crawford" <[email protected]> Fri, 09 Jan 2004 14:14:00 -0500
Newsgroups gmane.comp.security.virus.openantivirus.general
Message-ID <[email protected]>
Rainer Link wrote:

> Hi,
>
> consider the following scenario. A file contains (part(s)) of 
> viruscode, but the entry point points to the acutal host code. 
> Therefore, the virus
> code is not being called. What should the virus scanner do?
>
> - nothing. As per definition, the virus (code) never replicates, it's 
> not a virus.
> - report it as a "new/modified variant of <blah>", as the virus code 
> is not complete/modified.
> - report it as <blah> damaged" (or similar) as it contains virus code
> but is not functional.
> - report it as being infected with virus <blah>. As one may change the 
> entry point to the virus code and the virus (still) may work (although
> I'd say that's very unlike except probably for macro viruses).
>
> I personally would vote for do nothing. Is there some common 
> sense/practice for such a case?
>
> TIA.
>
> best regards,
> Rainer Link
>
>
I would call this infected (dormant).  Any file that contains malicious 
code should be considered a threat even if it does not automatically 
execute its payload.  There is always the potential for multi phase 
virii, which the first virus could infect a file in a dormant state, and 
a second ( typically utilizing a different infection vector ) would 
activate the previously delivered payload.  This has yet to been seen, 
but no one can say that these idiots writing malicious code aren't 
inventive, and multi-phase infection theory has been discussed/published 
in the past.  If the code is malicious, the file is malicious, period.  
Clean if possible or delete.

Christopher Crawford

>
> -------------------------------------------------------
> This SF.net email is sponsored by: Perforce Software.
> Perforce is the Fast Software Configuration Management System offering
> advanced branching capabilities and atomic changes on 50+ platforms.
> Free Eval! http://www.perforce.com/perforce/loadprog.html
> _______________________________________________
> Openantivirus-discuss mailing list
> Openantivirus-discuss-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
> https://lists.sourceforge.net/lists/listinfo/openantivirus-discuss





-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html