home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!swrinde!gatech!destroyer!gumby!yale!yale.edu!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: tck@fold.ucsd.edu (Kevin Marcus)
- Newsgroups: comp.virus
- Subject: Re: A user's view of IBM's antivirus/2 (OS/2)
- Message-ID: <0015.9212212018.AA02123@barnabas.cert.org>
- Date: 18 Dec 92 07:45:16 GMT
- Sender: virus-l@lehigh.edu
- Lines: 30
- Approved: news@netnews.cc.lehigh.edu
-
- >> or that their boot record had changed (because they
- >> changed a volume serial number).
- >
- >Hey, they should be really power users, if they know how to do that!
- >For instance, I don't know how it can be done, without reformatting
- >the disk, or using a sector editor... And anybody who is competent
- >enough to mess with a sector editor in the boot sector, should not be
- >surprised by a message that the said sector has been modified
- >afterwards...
-
- Well, I don't have the entirety of the original sentence, so I might
- be missing something, but, int 25h will let you read in the boot
- sector, you modify it however, and rewrite it with int 26h.
-
- Additionally, I have just recently seen some 486-50s with AMI BIOS's
- (copyright 1992, I dont' know the exact date, though), that allow for
- a "bootsector virus protection". Which is somewhat funny. Since I do
- a lot of fdisking and formatting of drives on new systems, they scream
- these messages, "Boot sector write - continue? (Y/n)" type of thing.
- THe funniest thing, however, is that it didn't do that when I ran sys
- on a hard drive. In fact, they mean bootsector of floppy, or MBR on
- hard drive. For example, it would seem to me that Form would not be
- detected when infected a hard drive, thought the floppy infection
- would. Maybe I should drag a copy to work and see what happens...
-
- - --
- || Kevin Marcus, Computer Virologist. (619)/457-1836; RE-xxx, TSCAN ||
- || INET: tck@bend.ucsd.edu []-[]-[]-[]-[]-[]-[]-[]-[]-[]-[]-[]-[]-[]-[]
- || tck@fold.ucsd.edu || All I wanted was a Pepsi... ||
- || datadec@watserv.ucr.edu || And she wouldn't give it to me...||
-