I think you all know the virus SIIS, wich has lots of line (more than 500)
and wich hides near to perfect. But not perfect. You can even see a unusual
modul and a 'WinOldApp' in the Application Close window. Nothing is perfect.
My new spionage virus removes its code from the Document, and writes
anywhere in ThisDocument_Close the recover-code (1 lines long).
The user sees nothing.... okay, if he looks closer to the class, he may find it.
This two samples are advanced stealth. For all who have no idea how to do it yet:
Try to remove the code from the document in the runtime.
I won't tell ya any code how to do this. I only will tell ya theoretics and repetitions:
You can run an extern application, that restores the code, after
closing word.
Pro: No code in the Document
Contra: The Application has to run, or the virus desinfects itself!!!
Contra: a extra module left
You could remove the code from the Document, and store it in the variable area
Pro: only 1% code left, small virus
Contra: 1% code left; the user may find them!!
Remove the entire code from the Document and the Normal.dot
Pro: No code left anywhere
Contra: the virus desinfects itself. (if there are enough infections on asystem, this
method ain't worst)
Take a look on this virii:
Unseen
Marrauder
SIIS