Re: Re: virus code is never executed - virus or not?]]]]
Antony Stone <Antony-E2RgWYyNWflCkLs28/y7ANBc4/[email protected]> Sun, 11 Jan 2004 16:12:22 +0000
| Newsgroups | gmane.comp.security.virus.openantivirus.general |
|---|---|
| Message-ID | <[email protected]> |
On Sunday 11 January 2004 3:07 pm, Fridrik Skulason wrote:
> I can only repeat what I said earlier - samples like that are not viruses
> by definition - they may or may not be detected, and when they are not, the
> risk is so minuscule that it is not worth worrying about...it is like the
> risk of a random useful program suddently becoming destructive becayse of a
> single-bit corruption on the hard disk - it is just not something worth
> worrying about
I agree with all you have said, however you have overlooked the final point I
made in my last posting, that the original question asked "assuming we do
detect this, how should we report it?".
Therefore your comments about the corrupted code being almost impossible to
detect, whilst perfectly valid in the situations you have put forward, do not
answer the original question regarding how to report something after it *has*
been detected as a virus, although it looks strange that the entry point is
not pointed to by a jump instruction (or equivalent).
I still believe that viral code should always be reported as such (perhaps
with a modifier such as "damaged", "dormant" or "variant") and let the end
user decide, but do not make them think there is no virus there at all.
If the code in question is not detected as a virus, then I agree with you that
we should not expend any additional affort in trying to work out what it is.
Antony.
--
Most people have more than the average number of legs.
Please reply to the list;
please don't CC me.
-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html