home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ornl!rsg1.er.usgs.gov!darwin.sura.net!wupost!zaphod.mps.ohio-state.edu!ub!dsinc!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: padgett@tccslr.dnet.mmc.com (A. Padgett Peterson)
- Newsgroups: comp.virus
- Subject: Re: Need info on MONKEY virus (PC)
- Message-ID: <0002.9211191448.AA21875@barnabas.cert.org>
- Date: 17 Nov 92 06:42:46 GMT
- Sender: virus-l@lehigh.edu
- Lines: 22
- Approved: news@netnews.cc.lehigh.edu
-
- >From: martin@cs.ualberta.ca (Tim Martin; FSO; Soil Sciences)
-
- >Third, the Monkey virus specifically (and successfully)
- >bypasses Padgett's Disk Secure program. This virus represents
- >a rare case: a very specific attack against a very specific
- >disk security system. Fortunately most scanners will find
- >the virus in memory. Again this stresses the importance of
- >having a multi-layer antivirus strategy.
-
- Like I said, no software is proof against a directed attack, *however*
- the DOS validator (CHKSEC) in the latest DS will detect the fact that
- the proper code is not resident in memory and the Monkey cannot
- prevent *that*.
-
- Incidently, it was said that FixMBR cannot remove the Monkey - this is
- true however if FixMBR was executed *before* infection and the .DAT
- file saved, use of it as directed after booting from floppy will
- restore the MBR & table as will the DiskSecure recovery disk.
-
- Cooly (in Chicago in November ?)
-
- Padgett
-