F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Cryptlab





NAME:MtE
ALIAS:Mutation Engine
ORIGIN:Bulgaria

This is not really a virus, but a "add-on" product supplied by the person who calls himself Dark Avenger. It can be used to give any virus a "polymorphic" ability, making it undetectable with a signature-based scanner.

Instead an algorithmic approach is used, which may (theoretically) produce false alarms. So, if F-Secure anti-virus products ever report a single file as containing MtE, don't be too alarmed - it might just be a false positive. If you get an alarm from a data file (non-executable), it's a certain false positive. Send a sample and we'll fix it.

One known false alarm is a file called 120492_v.dxf. If you find MtE from this file, simply ignore it.

Another known false alarms is from a data file called bf1g2.acm. This file is from a game called Baldur's Gate. If you find MtE from this file, simply ignore the false alarm. We are working to fix this.

Several viruses are known to make use of this Mutation Engine:

NAME:Pogue
TYPE:Resident COM-files
A variant of the Gotcha virus.

NAME:Dedicated
VARIANT:Fear
TYPE:Non-resident COM-files
Those two viruses are almost identical - but with different text messages. They would be considered totally unremarkable, if not for the inclusion of the engine.

NAME:Groove
TYPE:Resident COM/EXE-files
This virus is targeted against several anti-virus product, attacking their data files.

NAME:Cryptlab
TYPE:Non-resident COM-files
Unknown effects.