The road less truvelled: W32/Truvel

By: Peter Ferrie

By the addition of a relocation table, Vista executables can be configured to use a dynamic image base. That essentially turns them into executable DLLs. Now a virus has come along that has made a ‘breakthrough’ by infecting these executables - or it would be a breakthrough if it weren’t for the fact that relocatable executables have been supported since Windows 2000. Peter Ferrie takes an indepth look at the buggy W32/Truvel.

The full article is currently available to subscribers.

If you are already a VB subscriber, please login to view the full article.

Virus Bulletin - independent malware advice

  • Thought-provoking news and opinions from respected members of the AV industry.
  • Detailed analyses of the latest virus threats.
  • Feature-length articles exploring new developments in the fight against viruses.
  • Interviews with leading anti-virus experts.
  • Independent indepth evaluations of current AV products.
  • Easy-to-read comparative reviews featuring the unique VB100 award scheme.
  • VB Spam Suppplement - a monthly magazine supplement covering spam and anti-spam techniques.

Poll

Should anti-virus software be free for personal use?
Yes
No
I don't know

Leave a comment
View 43 comments

Jobs Career Sidebar

VB100 certification

VB100 VB's testing team put 24 anti-malware products to the test on the server version of Microsoft's latest iteration of the Windows platform: Windows Server 2008. John Hawes has all the details on which products managed to secure a VB100 award and which need have a little more work to do.
See full results.

Virus Bulletin currently has 144,116 registered users.