ATTACKS ON WIN32 - PART II

Péter Ször · 2000

In 1998 several anti-virus companies introduced heuristic scanning for 32-bit Windows viruses. As a result the number of anti-heuristic viruses is on the rise. In my paper I will introduce infection methods with special attention to the anti-heuristic infection techniques. I will also provide results achieved by testing old Win32 viruses and worms on Windows 2000. This provides a better understanding of the impact of old Win32 viruses on Windows 2000 and vice versa. The current number of 32-bit Windows viruses is almost 400. We have reached the point when automatic replication, detection and repair for the simple Windows viruses is becoming mandatory. PE repair is becoming very difficult if not impossible. Unfortunately, we have seen examples of new binary virus variants that were the result of inexact PE repair. This is a valid scenario since several products use CRCs to identify Trojans and worms. When a networked worm gets infected and repaired the result can be an unknown Windows virus. In this section I will describe the inexact nature of PE file repair. Furthermore, I will introduce the common techniques used by 32-bit Windows email worms and find out the possibilities, if any, of detecting them more generically. In the last part of the presentation I would like to talk about possible new virus models we are likely to see in the near future.

Read the paper · More papers on PaperTik