home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!newsserver.jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: os2-stuff (OS/2)
- Message-ID: <0006.9301271940.AA16908@barnabas.cert.org>
- Date: 15 Jan 93 06:04:18 GMT
- Sender: virus-l@lehigh.edu
- Lines: 36
- Approved: news@netnews.cc.lehigh.edu
-
- chess@watson.ibm.com (David M. Chess) writes:
-
- > >could infect them by mistake. How are the DLL and DRV files loaded in
- > >OS/2? If they are not loaded using any INT 21h/AX=4Bxxh function, then
- > >it is rather unlikely that any of the currently known viruses will
- > >infect them...
-
- > No, no OS/2 call does an INT 21 at all; that's one of the main
- > reasons that no DOS virus runs in native OS/2. Operating system
- > calls in OS/2 are done using Protect Mode constructs like call
- > gates (I forget the details again!), not using INTs. DC
-
- OK, but suppose that the user opens a DOS window. Suppose also that
- s/he runs an infected DOS program in this window and the virus becomes
- resident. Does OS/2 access some DLLs in order to handle the running of
- a DOS program in a DOS window? Are those accesses visible to the
- program running in the DOS window? If they are not, then none of the
- currently existing viruses will infect a DLL file and there is no need
- to scan such files...
-
- Another possibility is a virus like Frodo, which (erroneously)
- infects files with different extensions, because it thinks they are
- COM or EXE. But Frodo's criteria for executable extension does not
- classify "DLL" as such and I don't know other viruses which do the
- same stupidity...
-
- So, it seems that there is indeed no need to scan the DLL files,
- right? Or am I missing something?
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-