Re: virus code is never executed - virus or not?]]]]

Fridrik Skulason <[email protected]> Sun, 11 Jan 2004 15:07:12 +0000
Newsgroups gmane.comp.security.virus.openantivirus.general
Message-ID <[email protected]>
>> I guess you have never written a virus scanner, and you are just wrong
>> here.
>
>The point is that I think end users want to know if a file contains some code 
>which looks like a virus. 

But that is the problem - it does not "look like a virus" until after it is 
decrypted, and it will only be decrypted if it is executed or emulated,
and if you do not know where to start executing/emulating, it looks just like
a chunk of random gibberish.  

In practice, what happens is as follows:

  1) If the virus is a true EPO virus, AV producers will add detection of
     it.  In some cases they may not be able to - there are several scanners
     out therere that just cannot handle difficult EPO viruses like Zmist or
     Etap/Simile.

  2) If some of the replicants of the virus have a chance of being executed,
     AV producers will generally add detection of the non-working ones - 
     at least when practical....sometimes it just is not doable, as the 
     virus may be too badly corrupted, or incorrectly encrypted.

  3) If none of the replicants have a chance of working under any realistic
     circumstances, AV producers will generally add detection of the original
     "first generation" samples, but may or may not bother with the non-working
     replicants.

>and let the end user decide, but do not make them think there is no virus 
>there at all.

I can only repeat what I said earlier - samples like that are not viruses
by definition - they may or may not be detected, and when they are not, the
risk is so minuscule that it is not worth worrying about...it is like the risk
of a random useful program suddently becoming destructive becayse of a 
single-bit corruption on the hard disk - it is just not something worth worrying
about

--
Fridrik Skulason   Frisk Software International   phone: +354-540-7400
Author of F-PROT   E-mail: [email protected]       fax:   +354-540-7401


-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html