home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!cis.ohio-state.edu!news.sei.cmu.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: OS2SCAN99 checked (OS/2)
- Message-ID: <0011.9301221631.AA12947@barnabas.cert.org>
- Date: 14 Jan 93 12:00:49 GMT
- Sender: virus-l@lehigh.edu
- Lines: 38
- Approved: news@netnews.cc.lehigh.edu
-
- KARGRA@GBA930.ZAMG.AC.AT writes:
-
- > OS2CLEAN: at least I found no problems, when I tried to clean my system from
- > [JERU].
-
- Are you -absolutely- certain about that? You see, Jerusalem makes some
- silly assumptions about the format of the EXE files. As a consequence,
- it destroys some EXE files it infects (e.g., WordPerfect). It is my
- understanding, that it will destroy all Windows applications, and I
- think that OS/2 applications have a similar structure. Therefore, no
- disinfector would be able to recover such files, although some
- intelligent disinfectors warn the user that these files are destroyed.
-
- > Is there a reason, why you still
- > don't scan *.DLL?
-
- At least I do not know any virus that could infect them... And since
- SCAN is able to detect only known viruses, it doesn't make sense to
- scan objects that the known viruses do not infect...
-
- > You added new extensions, of which I never thought, they
- > would contain executable code (*.PIF). So I learned some new things. If
-
- The .PIF files contain a pointer to an executable file. Therefore, it
- is possible to apply a companion-type attack to them - change the
- pointer to another executable that contains the virus body and let the
- virus itself execute the original program. However, no such virus
- exists yet, which means that there is no need for a scanner to scan
- these files. They should be checked by the integrity checkers,
- however.
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-