home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!newsserver.jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: ianst@qdpii.comp.qdpi.oz.au (Ian Staples)
- Newsgroups: comp.virus
- Subject: Cansu virus plague revisited (PC)
- Message-ID: <0013.9301271940.AA16908@barnabas.cert.org>
- Date: 16 Jan 93 11:37:36 GMT
- Sender: virus-l@lehigh.edu
- Lines: 37
- Approved: news@netnews.cc.lehigh.edu
-
- Further to my earlier post on this recent outbreak, a couple of other
- questions have arisen:
-
- When using CLEAN (v.99) to remove the Cansu virus from floppies things
- normally work as you would expect. BUT, every now and then a disk bobs
- up (only with 5 1/4" in our experience) which CLEAN thinks it can't cure.
-
- The message is something along the lines of "Cansu virus detected in
- boot sector, can not be safely removed."
-
- What gives? Why do some (most) work okay but some don't? Furthermore,
- once this message appears CLEAN then thinks it can detect the virus in the
- memory of the PC ("Warning: Virus active in memory. Power down...etc.").
-
- This seems to be the same "problem" that occurs with reading the directory
- of an infected disk or with using SCAN (v.99) on an infected disk - the
- virus, or at least it's signature - is left in memory and the subsequent
- CLEAN operation aborts as a result.
-
- Incidentally, CLEAN also has a somewhat confusing message when it is being
- run with the /MANY option. If the virus is detected and removed on a floppy
- and the next disk is in fact okay, CLEAN will give a message that it has
- found one virus but that there is no virus on the new disk. We eventually
- worked out that it is probably just giving a cumulative count of what it
- has found as you feed disks through the drive. BUT, the first time you
- see the message in an atmosphere charged with suspicion, concern, and
- a great deal of ignorance, it is pretty bloody confusing! I think McAfee
- could do a bit better than that.
-
- Any comments from people who know out there?
-
-
- - --
- Ian Staples | Internet : ianst@qdpii.comp.qdpi.oz.au
- c/- P.O. Box 1054, | Fax : +61 (0)70 923 593
- MAREEBA Queensland 4880 | Voice : +61 (0)70 921 555
- Australia. | Home : +61 (0)70 924 847
-