WinHex Virus?
From time to time there appear proof-of-concept viruses for various platforms and applications that have their own scripting language interpreters. Almost a year ago a proof-of-concept virus for IDA (Interactive Disassembler Pro) appeared. IDA is our primary tool for reverse-engineering malware. No one in the industry was infected. As far as we know.
A few days ago someone sent us a new proof-of-concept virus. This time it was for WinHex, the powerful computer forensics, data recovery, and IT security tool. The virus prepends itself to all available .WHS (WinHex script) files. The infected WinHex scripts stop working and the only thing that they can do at that point is to spread the virus further. We named the virus “Vred.A”. Here’s a short description for the virus…
The developer of WinHex has been notified of the case.
Name : Virus:WH/Vred.A
Type: Virus
Category: Malware
Summary
Vred.A is a proof-of-concept virus for WinHex.
WinHex is a powerful computer forensics, data recovery, and IT security tool.
Back to the Top
Detailed Description
Vred.A is a proof-of-concept virus that is written in script language, that is used by the powerful computer forensics, data recovery, and IT security tool called WinHex.
Here’s a screenshot of the WinHex utility:
The virus contains less than 20 commands that allows it to look for all available .WHS (WinHex script) files and to prepend itself to them. As a result all infected scripts stop working until the virus’ code is removed from them.
It should be noted that WinHex shows a warning before running any script, so the virus can not replicate without user’s interaction: