home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Turnbull China Bikeride
/
Turnbull China Bikeride - Disc 2.iso
/
STUTTGART
/
ANTIVIRUS
/
SCANNER
/
!Scanner
/
Versions
< prev
next >
Wrap
Text File
|
1993-01-08
|
15KB
|
244 lines
The version history of Scanner:
1.00 (12-Dec-1991) - Will find files, albeit not very nicely put
on the screen.
1.02 (12-Dec-1991) - Nicer layout! Scans for NETSTATUS and
ARCHIEVIRUS viruses. Provides removal of the
NETSTATUS virus from !Boot files.
1.03 (10-Jan-1992) - Added check and kill for TRAPHANDLER virus.
LINK check added (at 5am!!!). Working on
disinfection.
1.04 (11-Jan-1992) - Finds infection count in LINK virus. (Module
offset: 2F0)
1.05 (12-Jan-1992) - Small bug fixes.
1.06 (14-Jan-1992) - Completed disinfectant code for LINK virus.
1.10 (22-Jan-1992) - Fixed bugs and added error 'routine'.
1.12 (25-Jan-1992) - Added IMAGE virus scan & kill.
1.13 (26-Jan-1992) - Added !Boot search for IMAGE infections. I
want to know if this works!! (I haven't got
the damn virus...)
1.14 (03-Feb-1992) - Got the MODULE virus in the post today, so
added scan for this. Thanks to Eivind Hagen
for that one.
1.15 (03-Feb-1992) - Added MYMOD scan and kill. Also added option
for logfile. Please note that 1.14 has a wrong
version date. It should be 02-Feb-1992!
1.16 (12-Feb-1992) - Bugs removed. Added CEBIT scan.
1.17 (19-Feb-1992) - Added kill for 2048 byte version of NetStatus.
Thanks to Alan for notifying me on that one.
1.20 (04-Mar-1992) - Added in-memory detection of CEBIT (removal),
EXTEND, LINK (removal), MYMOD (removal),
NETSTATUS (removal), NETMANAGER (removal),
PARASITE and TRAPHANDER (removal).
1.21 (13-Mar-1992) - Added disc scan for PARASITE and THANATOS.
1.22 (13-Mar-1992) - REMOVED in-memory removal of CEBIT as this one
has to be patched before it can shut down.
Call me lazy, but I'm afraid all you can do is
reset the computer if Scanner detects it in RMA.
Added scan for SPRITE and scan/kill of VALID.
I apologize to those who had to download both
versions.
1.23 (18-Mar-1992) - Scanner seemed to detect PARASITE viruses in
modules which weren't infected. This is now
fixed temporarily by checking the accompanying
!Boot file in an infected application. I wish
I could make it more reliable, but I don't have
enough examples of the virus to do that. Added
"NOT SURE" colour. See above.
1.24 (23-Mar-1992) - Did small changes to virus reports to make them
comply to the Archimedes Reference Document.
E.g. ARCHIEVIRUS is now ARCHIE, and VIGAYVIRUS
is VIGAY. In other words, no major change, but
I'd forgotten that we changed those names in
our document!
1.25 (30-Mar-1992) - Bug fixes(!). Added option for removal of
ARCHIE inoculation fingerprint.
1.30 (15-Apr-1992) - A big leap (.5) in version number due to the
implementation of OS_GetEnv to make Scanner
work from a command line. Thanks to Herbert
zur Nedden for this routine (although I *was*
thinking of using GetEnv too! Thanks for saving
a lot of time doing experimenting! :-). This
version was done at The Gathering 1992, coughed
together by Deadline/Crusaders. At the moment
I'm pretty awake, but wait......... :-)
Also - I think there's a new version of MODULE
around. Scanner didn't detect this new one
anyway!!
1.31 (15-Apr-1992) - I'm in for a long night... Parameters missing.
Removal code for EXTEND inoculations completed.
I guess it didn't become such a long night
after all!
1.32 (18-Apr-1992) - Added scan and kill of ICON. Also added scan
of suspicious files - currently checks sprite
and absolute files. Fixed 'Press space...' when
Scanner finishes. Fixed serious bug whihc didn't
allow Scanner to search on writeprotected discs!
1.33 (24-Apr-1992) - Added scan for BBCECONET virus. Also modified
'strange' scan, it was slightly weird... Now
detects if first word has "<instr>NV" or
<instr> reg,reg where reg=reg. I.e. MOV r0,r0.
I don't know if this is of any use, and might
prove to be annoying, but...
Please refer to the Archimedes Virus Reference
Document for full info about this (and the
other) viruses. Current version is 1.26p.
Please note that version 1.32+ scans suspicious
for sprite files too! (Forgot to mention it.)
1.34 (28-Apr-1992) - First of all, I was told by Svlad Cjelli to
credit him! :-) I got IMAGE from him through
Alan. BTW, Svlad, you *are* credited in AViD...
And yes - you'll have to send a disc. Second, I
am working on the STRANGE criteria. Seems it
bummed out quite badly in v1.33! Sorry about
that - I hope it will be better in this version.
I think it does! Finds if BBCECONET is in
memory, kills it if so.
1.35 (23-May-1992) - Fixed ? PARASITE warning on short module names.
Should be OK now. Other fixes in PARASITE scan
routine. Did some editing of the Doc file.
1.36 (29-May-1992) - Bugs bugs bugs. Thanks Alan... :-P
I really needed *that* after a nice day on the
beach! Also added EXTEND media search. I guess I
didn't think people were that anxious to find
that one since it was so old. (I treated it as
an extinct virus for the time being.) Added
VCZMod (MYMOD dropper?) scan, but no kill as I
don't know if this is a module on it's own or
in an application. Also detects any version of
VIGAY (due to a silly filelength check, the 2432
byte version never showed up!). When I get hold
of NETMANAGER, a media scan & removal will be
added.
1.37 (01-Jun-1992) - EXTEND scan routine updated to also scan for the
different module names (in case there are
dormant viruses - e.g. virus file, but never gets
loaded because !Boot/!Run is not infected).
Now finds "VCZMod" (MyMod dropper), and deletes
it if found (and if kill is active).
1.40 (03-Jun-1992) - Added NETMANAGER scan/kill. Completed integrity
check. Made Scanner EXCLUSIVLY available from
me, and modified registration fees. It is now
illegal to UPLOAD/EMAIL/FTP Scanner to any BBS
or server. Made !RunImage smaller.
Special thanks go to Alan Glover for super
support and always good updates on Killer and
a steady supply of viruses. Also, I'd like to
extend my thanks to John Kortink for Translator
and for defining the phrase "I'm pissed off by
unregistered users".
Also thanks to the 12 people who have
registered so far (you know who you are)!
Current version of AVRD is 1.31p.
1.41 (11-Jun-1992) - Fixed count% bugs. Added MODE87 kill and scan.
Added infection count display for MODE87.
Added GARFIELD scan. Fixed print bug.
Kills GARFIELD if in memory.
1.42 (20-Jun-1992) - Scanner is now commercial. Read !Help.
Added CODE scan/kill. Added GARFIELD kill.
Added SPRITEUTILS scan/kill. Fixed small bugs.
1.43 (18-Jul-1992) - Added T2 scan (media/memory). Fixed small
printing bug. Renamed ICON to ICON-xxxx,
NETSTATUS to NETSTATUS-xxxx and GARFIELD to
GARFIELD_W in the "Viruses" file to match the
descriptions in AVRD 1.42+.
1.44 (20-Jul-1992) - Fixed "? STRANGE!" bug when encountering
BBCECONET.
1.45 (20-Jul-1992) - Added check for writeprotected discs. Noticed
after release of 1.44 that the files "Doc" and
"Versions" were wrong.
1.46 (16-Aug-1992) - Added MODULE code removal - files only. I guess
you have waited long for this one. Sorry - but
time hasn't permitted me to add this until now.
Also I have to get myself a new monitor - this
Philips shite which Acorn provided is ready for
the scrapyard. It suddenly decided to dim down
on me (I guess it's the PSU). Renamed GARFIELD
to GARFIELD_W for AVRD compatibility. Rewrote
report layout (both in file and screen) a bit.
1.47 (04-Sep-1992) - Added GARFIELD_I search/destroy mission. Also
added TERMINATOR and BIGFOOT scan routines.
Garh - I'm using a TV as a VDU, and it really
sucks!
1.48 (15-Sep-1992) - Added IRQFIX awareness. Both media and memory
is covered. IRQFIX is identical to EXTEND,
except that the ASCII text within them is
different. I don't have a sample yet, so
Scanner only looks for the filenames which
IRQFIX saves itself under. In other words:
no in-depth checking (and so no removal code).
Immense thanks go to The German Archimedes
User Group (GAG) and Herbert zur Nedden!
1.49 (21-Sep-1992) - Added INCREMENT awareness.
1.50 (26-Sep-1992) - Fixed bug in MODULE removal code. Please
check your disinfected modules if you used
Scanner to clean them!
1.51 (12-Oct-1992) - DISTRIBUTE THIS VERSION FREELY. Also please
note that the email address has been changed.
(The reason for this being FreeWare (DON'T
PUT IT IN ANY PD LIBRARIES!) is that for the
upcoming BBC Acorn User Show I won't have
time to register new users there! You will
need to register with me if you want upgrades
of this product, though.)
This version has a "timer" in it, though,
warning you about one month from now that it
is considered old. You may still use it, but
are advised NOT to.
1.55 (29-Dec-1992) - Whoah. Finally I got around to adding three
new viruses. Media scan only, of ARCUEBUS,
HANDLER and RUNOPT. Also, I had to REMOVE
the code for MODULE file-cure. Some version
has apparrently majorly f*cked up the clean
routine, and at present I haven't had time
to clean it up. So, Scanner will DETECT
MODULE, but won't remove it.
Also! BIG THANKS to Olaf Krumnow, whom has
added SparkFS compatibility. Scanner now
searches archives if you have SparkFS
installed. Thanks again!
Scanner is still FreeWare. Please read
!Help for details. Distribute freely, but
don't put it in PD/SW libraries. USENET
distribution (FTP/Mail) is wholeheartedly
permitted! :)
All the best for 1993, all of you!
1.56 (08-Jan-1993) - Fix the T2 in-memory check to avoid false
alarms when later versions of VProtect
are resident.
Versions prior to 1.02 were never released to the public, as there were
killers around for the viruses killed/detected by those versions.
Known problems:
Won't kill MODULE infected files correctly. This routine has
been removed, though.