Re: virus code is never executed - virus or not?
"Christopher T. Crawford" <[email protected]> Fri, 09 Jan 2004 14:14:00 -0500
| Newsgroups | gmane.comp.security.virus.openantivirus.general |
|---|---|
| Message-ID | <[email protected]> |
Rainer Link wrote: > Hi, > > consider the following scenario. A file contains (part(s)) of > viruscode, but the entry point points to the acutal host code. > Therefore, the virus > code is not being called. What should the virus scanner do? > > - nothing. As per definition, the virus (code) never replicates, it's > not a virus. > - report it as a "new/modified variant of <blah>", as the virus code > is not complete/modified. > - report it as <blah> damaged" (or similar) as it contains virus code > but is not functional. > - report it as being infected with virus <blah>. As one may change the > entry point to the virus code and the virus (still) may work (although > I'd say that's very unlike except probably for macro viruses). > > I personally would vote for do nothing. Is there some common > sense/practice for such a case? > > TIA. > > best regards, > Rainer Link > > I would call this infected (dormant). Any file that contains malicious code should be considered a threat even if it does not automatically execute its payload. There is always the potential for multi phase virii, which the first virus could infect a file in a dormant state, and a second ( typically utilizing a different infection vector ) would activate the previously delivered payload. This has yet to been seen, but no one can say that these idiots writing malicious code aren't inventive, and multi-phase infection theory has been discussed/published in the past. If the code is malicious, the file is malicious, period. Clean if possible or delete. Christopher Crawford > > ------------------------------------------------------- > This SF.net email is sponsored by: Perforce Software. > Perforce is the Fast Software Configuration Management System offering > advanced branching capabilities and atomic changes on 50+ platforms. > Free Eval! http://www.perforce.com/perforce/loadprog.html > _______________________________________________ > Openantivirus-discuss mailing list > Openantivirus-discuss-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org > https://lists.sourceforge.net/lists/listinfo/openantivirus-discuss ------------------------------------------------------- This SF.net email is sponsored by: Perforce Software. Perforce is the Fast Software Configuration Management System offering advanced branching capabilities and atomic changes on 50+ platforms. Free Eval! http://www.perforce.com/perforce/loadprog.html