Welcome, Guest. Please login or register.
Did you miss your activation email?
May 24, 2013, 11:55:21 PM

Login with username, password and session length

664014 Posts
70626 Topics
145258 Members

Latest Member: dearl2m43

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  General Security Questions and Comments
| | |-+  What happened to metamorphic viruses?
« previous next »
Pages: [1] Go Down Print
Author Topic: What happened to metamorphic viruses?  (Read 3019 times)
q4knowledge
Newbie
*
Offline Offline

Posts: 5


« on: May 23, 2012, 06:33:23 PM »

Do virus writers still attempt to make metamorphic or polymorphic code or have antiviruses over come this?

Out of curiosity, why are all metamorphic and polymorphic viruses file-infectors? Wouldn't it be a lot simpler to make a standalone program (worm) that rewrites itself? Furthermore for a file-infector  to work it needs to know whether it has infected a file before, which would be difficult.
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1795


« Reply #1 on: May 25, 2012, 10:41:02 PM »

Quote
Do virus writers still attempt to make metamorphic or polymorphic code
Well yeah, Polymorphic would be easier to write.   Reason: if the goal is for going undetected (like hiding from a traditional av scanner: basically blacklist detecting) why make it more complex then needed.  I won't get into the specifics as this isn't a malware programming forum Evil

Quote
have antiviruses over come this?
Depending on the AV, but to keep it as simple as possible.  Yes to some degree.

Quote
file-infector  to work it needs to know whether it has infected a file before
It all depends on how its coded.  example just infecting executable files or a specific ones like .bat files in a certian and/or all folders   Shocked

Quote
Wouldn't it be a lot simpler to make a standalone program (worm) that rewrites itself?
Of course


Logged

It's hard being a crooked Admin when the files won't pass an md5checksum test.  But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
q4knowledge
Newbie
*
Offline Offline

Posts: 5


« Reply #2 on: May 30, 2012, 03:33:25 PM »

Reason: if the goal is for going undetected (like hiding from a traditional av scanner: basically blacklist detecting) why make it more complex then needed.  I won't get into the specifics as this isn't a malware programming forum

What is?
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16722



« Reply #3 on: June 02, 2012, 04:23:50 PM »

What is?
Most certainly not this forum.
Logged

Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.043 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com