home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ornl!rsg1.er.usgs.gov!darwin.sura.net!zaphod.mps.ohio-state.edu!ub!dsinc!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: frisk@complex.is (Fridrik Skulason)
- Newsgroups: comp.virus
- Subject: Re: F-Prot's (v2.05) memory scanning. (PC)
- Message-ID: <0005.9211191448.AA21875@barnabas.cert.org>
- Date: 17 Nov 92 08:58:23 GMT
- Sender: virus-l@lehigh.edu
- Lines: 16
- Approved: news@netnews.cc.lehigh.edu
-
- cz1jed@orac.sunderland-poly.ac.uk (J.EDWARDS) writes:
-
- >After hours of failing to get Windows to install, the owner suddenly
- >announced he thought his computer might be infected. I ran F-Prot
- >straight away and sure enough it announced it had detected 'Stoned' in
- >memory. I booted from my clean floppy and when running F-Prot again
- >it claimed the hard-disk was infected with not 'Stoned' but
- >'Michaelangelo'.
-
- The reason for this is simple - The memory scan only reports the virus
- family, not the exact variant name. As Michelangelo has been
- classified as a member of the "Stoned" family, it reports "Stoned".
- When you scan the boot sector, F-PROT identifies the variant - in this
- case Michelangelo.
-
- - -frisk
-