home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
SDN¹ Plus
/
SDN1_.cdr
/
sdn
/
util1
/
clean89b.sdn
/
CLEAN89.DOC
< prev
next >
Wrap
Text File
|
1992-03-26
|
15KB
|
358 lines
CLEAN-UP Version 8.4B89
Copyright (C) 1990, 1991 by McAfee Associates.
All rights reserved.
Documentation by Aryeh Goretsky.
McAfee Associates (408) 988-3832 office
1900 Wyatt Drive, Suite 8 (408) 970-9727 fax
Santa Clara, CA 95054-1529 (408) 988-4004 BBS 2400 bps
U.S.A (408) 988-5138 BBS HST 9600
(408) 988-5190 BBS v32 9600
CompuServe GO VIRUSFORUM
InterNet mcafee@netcom.com
TABLE OF CONTENTS:
SYNOPSIS . . . . . . . . . . . . . . . . . . . . . . . . . . .2
- What CLEAN-UP is, system requirements
AUTHENTICITY . . . . . . . . . . . . . . . . . . . . . . . . .2
- Verifying the integrity of CLEAN-UP
WHAT'S NEW . . . . . . . . . . . . . . . . . . . . . . . . . .3
- Features, new viruses added in this release
OVERVIEW . . . . . . . . . . . . . . . . . . . . . . . . . . .3
- General description of CLEAN-UP
OPERATION. . . . . . . . . . . . . . . . . . . . . . . . . . .5
- How to use CLEAN-UP
EXAMPLES . . . . . . . . . . . . . . . . . . . . . . . . . . .7
- Samples of frequently-used options
REGISTRATION . . . . . . . . . . . . . . . . . . . . . . . . .8
- How to register CLEAN-UP
TECH SUPPORT . . . . . . . . . . . . . . . . . . . . . . . . .
- Information you should have ready when calling
Page 1
CLEAN-UP Version 8.4B89 Page 2
SYNOPSIS
CLEAN-UP (CLEAN) is a virus disinfection program for IBM PC
and compatible computers. CLEAN-UP will search through the
partition table, boot sector, or files of a PC and remove a virus
specified by the user. In most instances CLEAN-UP is able to repair
the infected area of the system and restore it to normal usage.
CLEAN-UP works on all viruses identified by the current version of
the VIRUSCAN (SCAN) program. CLEAN-UP can also remove unknown viruses
from .COM and .EXE files, partition table, and boot sector that have
had recovery information stored for them by the VIRUSCAN program.
CLEAN-UP runs on any PC with 320Kb and DOS 2.00 or above.
AUTHENTICITY
CLEAN-UP runs a self-test when executed. If CLEAN has been
modified in any way, a warning will be displayed. The program will
still continue to remove viruses, though. If CLEAN reports that
it has been damaged, is recommended that a new, clean copy be
obtained.
CLEAN-UP is packaged with the VALIDATE program to ensure the
integrity of the CLEAN.EXE file. The VALIDATE.DOC instructions
tell how to use the VALIDATE program. The VALIDATE program
distributed with CLEAN-UP may be used to check all further versions
of CLEAN.
The validation results for Version 8.4B89 should be:
FILE NAME: CLEAN.EXE
SIZE: 92,579
DATE: 3-26-1992
FILE AUTHENTICATION
Check Method 1: CD93
Check Method 2: 0769
If your copy of CLEAN.EXE differs, it may have been modified.
Always obtain your copy of CLEAN-UP from a known source. The
latest version of CLEAN-UP and validation data for CLEAN.EXE can be
obtained off of McAfee Associates' bulletin board system at (408)
988-4004 or from our Computer Virus Help Forum on CompuServe.
Beginning with Version 72, all McAfee Associates programs for
download are archived with PKWare's PKZIP Authentic File
Verification. If you do not see the "-AV" message after every file
is unzipped and receive the message "Authentic Files Verified!
# NWN405 Zip Source: McAFEE ASSOCIATES" when you unzip the files
then do not run them. If your version of PKUNZIP does not have
verification ability, then this message may not be displayed.
Please contact McAfee Associates if your .ZIP file has been
tampered with.
CLEAN-UP Version 8.4B89 Page 3
WHAT'S NEW
Version 89 of CLEAN-UP adds eight new removers for the 855,
1241, 1554, Holocausto, M128, Mardi Bro.'s, Mosquito, and Traceback/3066
viruses.
Please refer to the enclosed VIRLIST.TXT file for a short description
of the new viruses. For a more complete description, please refer to
Patricia Hoffman's VSUM listing.
OVERVIEW
CLEAN-UP searches the system looking for the virus you wish
to remove. When an infected file is found, CLEAN-UP isolates and
removes the virus, and in most cases, repairs the infected file and
restores it to normal operation. If the file is infected with a
less common virus, CLEAN-UP will then display a warning message and
prompt the user, asking whether to overwrite and delete the
infected file. Files erased in such a manner are non-recoverable.
Before running CLEAN-UP, verify the virus infection with the
VIRUSCAN (SCAN.EXE) program. SCAN will locate and identify the
virus and provide the I.D. code needed to remove it. The I.D. is
displayed inside the square brackets, "[" and "]." For example,
the I.D. code for the Jerusalem virus is displayed as "[Jeru]".
This I.D. must be used with CLEAN-UP to remove the virus. The square
brackets "[" and "]" MUST be included.
If SCAN finds an unknown virus in a file that had previously had
recovery information stored for it, it will notify the user that an infection
has occurred. It will not, however, display an I.D. code.
NOTE: When CLEAN is run with the /GENERIC option to disinfect
files or system areas based on the recovery information stored by SCAN,
no I.D. code should be used.
Please refer to the VIRUSCAN documentation for instructions in adding
recovery information to your system.
CLEAN-UP Version 8.4B89 Page 4
The common viruses that CLEAN-UP is able to remove
successfully and repair and restore the damaged programs are:
555 730 748 855
903 1008 1024 1241
1253 1554 1575/1591*+ 170x*
1992 2000 2100 2560
3445 4096*+ Air Cop* Alabama+
Alameda Antitelefonica Azusa Beeper
Black Monday+ Bloody! Boys Curse
Dark Avenger*+ DataLock+ December 28+ Devil's Dance
Dir-2 Disk Killer* EDV* Empire*
Enigma Fellowship+ Filler Fish+
Flash Flip*+ Form Generic Boot
Generic MBR Ghost Haifa Holocausto
Invader*+ Irish Jerusalem*+ Joshi
KeyPress*+ Korea* Lazy Lehigh
Liberty+ Lisbon* Loa Duong M128
Mardi Bro.'s Michelangelo Miky Mosquito
Murphy*+ Music Bug Nomenclature Pakistani Brain*
Perfume Ping Pong* Plastique*+ Possessed
Print Screen-2* R-11+ SBC Slayer
Slow+ Stoned* Striker+ Sunday+
Sunday2+ SVC+ Taiwan 3+ Taiwan 4+
Tequila Tokyo Topo Traceback/3066
Typo Boot V800 V-801 VACSINA*+
Vienna* Violator*+ Whale*+ Yankee Doodle*+
ZeroBug
*Denotes virus with more than one strain
+Denotes virus which attaches to overlays
AN IMPORTANT NOTE ABOUT .EXE FILES: Some viruses which infect .EXE
files can not be removed successfully in all cases. This usually
occurs when the .EXE file loads internal overlays. Instead of
attaching to the end of the .EXE file, the virus may attach to the
beginning of the overlay area, and program instructions are
overwritten. CLEAN-UP will truncate files infected in this manner.
If a file no longer runs after being cleaned, replace it from the
manufacturer's original disk.
AN IMPORTANT NOTE ABOUT THE STONED VIRUS: Removing the Stoned
virus can cause loss of the partition table on systems with
non-standard formatted hard disks. As a precaution, backup all
critical data before running CLEAN-UP. Loss of the partition table
can result in the LOSS OF ALL DATA ON THE DISK.
CLEAN-UP Version 8.4B89 Page 5
OPERATION:
IMPORTANT NOTE: POWER DOWN YOUR SYSTEM AND BOOT FROM A CLEAN
SYSTEM DISK BEFORE BEGINNING. RUN THE CLEAN-UP PROGRAM FROM A
WRITE-PROTECTED DISK TO PREVENT INFECTION OF THE PROGRAM.
Power down the infected system and boot from a clean,
write-protected system diskette. This step will insure that the
virus is not in control of the computer and will prevent
reinfection. After cleaning, power down the system again, reboot
from the system disk, and run the VIRUSCAN program to make sure the
system has been successfully disinfected. After cleaning the hard
disk, run the VIRUSCAN program on any floppies that may have been
inserted into the infected system to determine if they have been
infected.
CLEAN-UP will display the name of the infected file, the virus
found in it, and report a "successful" disinfection when the virus
is removed. If a file has been infected multiple times by a virus
(possible if the virus does not check to see if it has already
attached to a file) then CLEAN-UP will report that the virus has
been removed successfully for each infection.
To run CLEAN-UP type:
CLEAN d1: ... d26: [virus ID] /A /CHKHI /E .xxx /FR /GENERIC
/MAINT /MANY /M /REPORT d:filename /NOPAUSE
Options are:
/A - Examine all files for viruses
/E .xxx .yyy .zzz - Clean overlay extensions .xxx .yyy .zzz
/FR - Display messages in French
/GENERIC - Clean unknown viruses
(see below for details)
/MAINT - Clean DOS 4.0+ damaged boot sector
/MANY - Check and disinfect multiple floppies
/NOPAUSE - Disable screen prompting
/REPORT d:filename - Create report of cleaned files
/SP - Display messages in Spanish
d1: ... d26: - indicate drives to be cleaned
[virus ID] - Virus identification code - provided by
VIRUSCAN When it detects a virus. For a
complete list of codes, see the
accompanying VIRLIST.TXT file.
NOTE: The square brackets "[" and "]" are required.
CLEAN-UP Version 8.4B89 Page 6
The /A option will cause CLEAN to check all files on
disk. This should be used if an overlay-infecting virus is
detected.
The /E option allows the user to specify an extension or set
of extensions to clean. Extensions must be separated by a space
after the /E and between each other. Up to three extensions may
be added with the /E. For more extensions, use the /A option.
The /FR option tells CLEAN-UP to display all messages in
French instead of English.
The /GENERIC option is used to clean files or areas of the system
that have been infected with a new (unknown) virus. For /GENERIC to work,
the PC must previously (prior to infection) have had SCAN with the /AG option
run on it to store recovery information.
The /MAINT option is used to clean hard disks partitioned with
DOS 4.0 or above that have been damaged by a boot sector or partition
table infecting virus. Attempts to access disks damaged in such a
manner result in an "invalid media" message being displayed. The
/MAINT option will only clean the partition table and boot sector,
not the files.
The /MANY option is used to clean multiple floppy diskettes.
If the user has more than one floppy disk to check for viruses, the
/MANY option will allows the user to check them without having to
run CLEAN multiple times.
The /NOPAUSE option disables the "More..." prompt that appears
when CLEAN fills a screen with data. This allows CLEAN-UP to run
on a machine with multiple infections without requiring operator
intervention when the screen fills up with messages from the CLEAN
program.
The /REPORT option is used to generate a listing of
disinfected files. The resulting list can be saved to disk as an
ASCII text file. To use the report option, specify /REPORT on the
command line, followed by the device and filename.
The /SP option tells CLEAN-UP to display all messages in
Spanish instead of English.
CLEAN-UP Version 8.4B89 Page 7
EXAMPLES
The following examples are shown as they would be typed in on
the command line.
CLEAN C: D: E: [JERU] /A
To disinfect drives C:, D:, and E: of the Jerusalem
virus, searching all files for the virus in the process
CLEAN A: [STONED]
To disinfect floppy in drive A: of the Stoned virus
CLEAN C:\MORGAN [DAV] /A
To disinfect subdirectory MORGAN on drive C: of the Dark
Avenger, searching all files for the virus in the process
CLEAN B: [DOODLE] /REPORT C:YNKINFCT.TXT
To disinfect floppy in drive B: of the Yankee Doodle
virus, searching all files in the process, and creating
a report of disinfected files named YNKINFCT.TXT on drive
C:
CLEAN C: /GENERIC
To disinfect drive C: of an unknown virus using recovery
information stored on the drive by SCAN's /AG option.
CLEAN-UP Version 8.4B89 Page 8
REGISTRATION
A registration fee of $35.00US is required for the use of
CLEAN-UP by individual home users. Registration is for one year
and entitles the holder to unlimited free upgrades off of McAfee
Associates BBS or CompuServe Computer Virus Help Forum. When
registering, a diskette containing the latest version may be
requested. Add $9.00US for diskette mailings. Only one diskette
mailing will be made.
Registration is for home users only and does not apply to
businesses, corporations, organizations, government agencies, or
schools, who must obtain a license for use. Contact McAfee
Associates for more information.
Outside of the United States, registration and support may be
obtained from the Agents listed in the accompanying AGENTS.TXT
file.
TECH SUPPORT
In order to facilitate speedy and accurate support, please
have the following information ready when you contact McAfee
Associates:
- Program name and version number.
- Type and brand of computer, hard disk, plus any
peripherals.
- Version of DOS you are running, plus any TSRs or device
drivers in use.
- Printouts of your AUTOEXEC.BAT and CONFIG.SYS files.
- The exact problem you are having. Please be specific as
possible. Having a print out of the screen and/or being
at your computer will help also.
McAfee Associates can be contacted by CompuServe Forum, BBS or fax
twenty-four hours a day, or call our business office at (408) 988-3832,
Monday through Friday, 7:30AM to 5:30PM Pacific Standard Time.
McAfee Associates (408) 988-3832 office
1900 Wyatt Drive, Suite 8 (408) 970-9727 fax
Santa Clara, California (408) 988-4004 BBS 2400 bps
U.S.A 95125-4617 (408) 988-5138 BBS HST 9600
(408) 988-5190 BBS v32 9600
CompuServe GO VIRUSFORUM
InterNet mcafee@netcom.com