home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
GEMini Atari
/
GEMini_Atari_CD-ROM_Walnut_Creek_December_1993.iso
/
zip
/
diskutil
/
hospital.lzh
/
HOSPITAL
/
STVIRUS.DOC
< prev
next >
Wrap
Text File
|
1989-08-31
|
5KB
|
124 lines
07001020209800
1VIRUSES(1)Atari STVIRUSES(1)
218/5/89Page #18/5/89
F0000000
9[................................................]011
ü
ëVIRUSES(ST)
Ç
AcompaniondocumentfortheHOSPITAL
virusdetection/preventionsuite
NeilForysth
DepartmentofComputerScience
Heriot-WattUniveristy
HuntersClose
79Grassmarket
Edinburgh
neil@uk.ac.hw.cs
ëTHEHOSPITALPROGRAMS
Ç
ItwouldbealietosaythatifyouusetheHOSPITALprograms
youwillêneverÇsufferfromavirusattack.Thepeople(?)who
writeviruseswilleventuallygettheseprogramsandtryto
inventnewwaysofinfectionandavoidingdetection.However,
usingsomecombinationoftheprogramsisdefinatelyagood
precaution.Theycertainlydoagreatjobagainstallthe
virusesI'veseentodateandshouldanysmartervirusescome
alongIwillmodifymyprogramsaccordingly.
Treatallformatteddisksthatyouaregivenorbuywith
suspicion.Thisincludescommerciallyavailiablepackages.I
haveseenavirusinfecteddiskthatcamestraightoutofits
clingwrappedbox.Thesoftwarehousewasnotbeing
irresponsible,theywerethevictimofavirusattack.
ëOTHERHELPFULUTILITIES
Ç
êAFMTbyNeilForsyth
ÇInadditiontothebootsector,somediskvirusesusethe
extraFATsectorsonadisk.Thereareusuallysixoftheseon
singlesideddiskandfouronadouble.Theyareneverusedon
thecurrentdoubledensitydisksystems.
TheAFMTdiskformatterreducesthesizeoftheFATtoa
minimumleavingnofreeFATsectorsforavirustohideinand
givingyoumorediskspace.
êDT(DiskToolbox)byNeilForsyth
ÇThisutilityallowsyoutoreversablychangetheexecutability
ofabootsector.Ifthebootsectordoesnotcontainavirus
andperhapsneedstoberunforaprogramtoworkthenitcan
easilybechangedback.TheRAMloadableversionofTOSfrom
Atariusesanexecutablebootsectortoloadasdoalotof
commercialgames.
êVKILLERbyGeorgeWoodside
Ç
Thisisanexcellentprogramforthebulkcheckingofdisks
forpossibleviralinfection.Ithasmanyfeaturesfor
analysisanddestructionofviruses.Itcanalsotellyoua
fewthingsaboutanyknownvirusesitfinds.
êFLUbyGeorgeWoodside
Ç
Thisprogramdemonstratesthesymptomsofmanyofthejoke
typevirusesthatGeorgehascomeacross.
ëLINKVIRUSESÇ
Therearesomevirusesthatinfectprogramsinsteadofdisk
sectors.Ihaveneverseenoneofthese'linkviruses'but
haveaprettygoodideahowtheymightworkandhopetocreate
programstosafeguardagainstthemsoon.
ëHARDDISKVIRUSESÇ
CurrentlytheredoesnotêseemÇtobeanyvirusesthatattack
harddisksbutI'msurethattheywillappear.Theonlyadvice
Icanofferhereistobackupyourharddiskdataregularly.
IdomeanêdataÇhereandnotprograms.Youcanalwaysre-
installanapplicationprogramandthecopyontheharddisk
thatislostmayhavebeeninfected.
ëMYTHS
Ç
Therehavebeensomereports,allofthemunconfirmed,of
programsthatareabletowritetodiskswiththewrite
protectnotchon.Ibeleivethistobeabsolutenonsenseand
probablycausedbydelayeddiskwritesfromcacheprogramsor
floppyserialnumbersbeingthesame.Whenwritingmydisk
formatter(AFMT),Ihadtobypasstheoperatingsystemand
accessthehardwaredirectlyandnevermanagedtowritetoa
writeprotecteddisk.
(FromtheWesternDigital1772DiskControllerDataSheet)
9 [........................................]011
"Writeprotect:Thisinputissampledwhenevera
WriteCommandisreceived.Alogiclowonthisline
willpreventanyWriteCommandfromexecuting
(internalpull-up)."
9[................................................]011
Theonlywaythiscouldbecircumventedwouldbetomodifythe
diskdriveoritsconnectiontothecomputer.HoweverIam
openmindedenoughtobeleivethisphenomenonifandwhenI
everseeitandyoucanbeprettysureI'lltellyouifIdo!