Cryptlab

Threat description

Details

Category:
Platform: W32

Summary

This is not really a virus, but a "add-on" product supplied by the person who calls himself Dark Avenger. It can be used to give any virus a "polymorphic" ability, making it undetectable with a signature-based scanner.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details

Instead an algorithmic approach is used, which may (theoretically) produce false alarms. So, if F-Secure anti-virus products ever report a single file as containing MtE, don't be too alarmed - it might just be a false positive. If you get an alarm from a data file (non-executable), it's a certain false positive. Send a sample and we'll fix it.

One known false alarm is a file called 120492_v.dxf. If you find MtE from this file, simply ignore it.

Another known false alarms is from a data file called bf1g2.acm. This file is from a game called Baldur's Gate. If you find MtE from this file, simply ignore the false alarm. We are working to fix this.

Several viruses are known to make use of this Mutation Engine:


Variant:Pogue

Other: Resident, COM-files

A variant of the Gotcha virus.


Variant:Dedicated, Fear

Other:Non-Resident, COM-files

Those two viruses are almost identical - but with different text messages. They would be considered totally unremarkable, if not for the inclusion of the engine.


Variant:Groove

Other: Resident, COM/EXE-files

This virus is targeted against several anti-virus product, attacking their data files.


Variant:Cryptlab

Other: Non-Resident, COM-files

Unknown effects.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More