Dr. Richard Ford [email protected] Polymorphic Viruses. What are we going to talk about?. Szor 7 Another way viruses try to evade scanners. Virus Scanners. Look for “known” viruses Basically, used to look for hex strings in files Virus writers tried to make this more difficult… .
LEA si, Start MOV sp, 0682Decrypt: XOR [si], si XOR [si], sp INC si DEC sp JNZ DecryptStart:
MOV EDI, 00403045hADD EDI, EBPMOV ECX, 0A6BhMOV AL, [key]
Decrypt:XOR [EDI], ALINC EDILOOP DecryptJMP Start
DB key 86