home *** CD-ROM | disk | FTP | other *** search
-
- THIS IS SHAREWARE - PLEASE READ END OF DOCUMENTATION FOR DETAILS
-
- -----------------------------------------------------------------------------
- Scanner, v1.36 (29-May-1992) - © 1991,1992 Tor O. Houghton
- -----------------------------------------------------------------------------
-
- PLEASE READ VERSION INFORMATION IN FILE 'Versions'
-
- Please note that this product is a primarily a detector - i.e. it detects
- rather than removes viruses. Removal code for each virus will often come in
- later versions, but as I don't have time to disassemble each virus on the fly
- (unlike Alan Glover) I add the detection routines first so that new versions
- can be released quickly.
-
- Viruses detected by Scanner (media):
-
- ARCHIE
- BBCECONET
- CEBIT
- ICON (+ removal - all known versions)
- IMAGE (+ removal)
- LINK (+ removal)
- MODULE
- MYMOD (+ removal)
- NETSTATUS (+ removal / both 2048 and 2072 byte versions)
- PARASITE
- SPRITE
- THANATOS
- TRAPHANDLER (+ removal)
- VALID (+ removal)
- VIGAY
-
- In-memory detection of:
-
- BBCECONET (+ removal)
- CEBIT
- EXTEND
- LINK (+ removal)
- MYMOD (+ removal)
- NETSTATUS (+ removal)
- NETMANAGER (+ removal)
- PARASITE
- TRAPHANDER (+ removal)
-
- Detects files which are inoculated against:
-
- ARCHIE (Hypo1210)
- EXTEND ([0a]||[FF])
-
- Can remove ARCHIE and EXTEND inoculation fingerprints from files. I have
- heard reports that this won't work if files are compressed using CFS.
-
- For information about each virus, refer to the Archimedes Virus Reference
- Document by Alan Glover and I.
-
- A bit about the screen layout:
-
- .---------------------------------------------.
- | | <- Current directory
- |=============================================|
- | | <- File found and checked
- | |
- | |
- | |
- |=============================================|
- | | <- File contained material
- | | worth mentioning, and is
- | | therefore written here
- | | with colour coding
- |===============================--------------'
- | |
- | | <- Status report
- '------------------------------'
-
- A few notes on the colour coding:
-
- RED - Scanner found virus code, but could/did not remove it. Such files
- should be removed from where they are and either deleted or
- stored in a safe place for future versions of Scanner (or any
- similar program) to handle them.
- When a LINK virus has been found, a number in parenthesis will
- appear. This is the current infection count.
- MARK: ⇨
-
- PEACH - Scanner found something but couldn't determine what it was. It
- might be a virus, but Scanner is "not sure".
- MARK: ?
-
- MAGENTA - Scanner found virus code, and successfully managed to remove it
- from the file.
- MARK: ☓
-
- GREEN - Scanner inoculated a file against a specific virus attack. This
- is currently not available. In fact - I don't think it ever will
- be. It *is* a rather useless countermeasure.
- MARK: €
-
- YELLOW - Scanner found a file with an inoculation 'fingerprint', and just
- notifies you of this.
- MARK: -
-
- -----------------------------------------------------------------------------
-
- Using <Scanner$Dir>.!RunImage from CLI or customized Obey file:
-
- *<Scanner$Dir>.!RunImage <param 1> <param 2> <param 3> <param 4>
-
- Parameter 1: Scanner search dir, e.g. $ or CFS#SCSI::4.$.Incoming
- Parameter 2: Log file - "_" for default if parameter 3 and 4 are used, else
- blank.
- Parameter 3: Remove inoculation fingerprint? (Y/N)
- Parameter 4: Remove virus code from infected files? (Y/N)
-
- E.g. 1: "*<Scanner$Dir>.!RunImage ADFS::0.$ _ Y N" will remove inoculation
- fingerprints in files located on ADFS drive 0, using the default filename for
- the log file.
-
- E.g. 2: "<Scanner$Dir>.!RunImage ADFS::0.$" will scan ADFS drive 0 without
- taking any action whatsoever.
-
- -----------------------------------------------------------------------------
-
- THIS PROGRAM IS SHAREWARE
-
- What this means in practice:
-
- If you are a single user, send a floppy to the address below.
-
- If you are distributing this through a PD/SW library, send 3
- floppies to the address below. Magazines are considered business.
-
- If you are a business or school please send 1 floppy and five (5)
- pounds to the address below.
-
- I think that this is only fair, as I have spent countless hours upgrading and
- adding features to this product.
-
- I have recently received some discs from several users. You have only sent me
- 1 disc, so I've kept it. You have been registered, but new upgrades will not
- be sent unless you send me another disc. Sorry (but my idea was to use the
- discs for my own purpose! :-).
-
- -----------------------------------------------------------------------------
-
- Copyright notice: This program is copyright. This means - DO NOT MODIFY, but
- please put this program on the next disc to your friend or
- penpal. It is here to help, but not entirely for free! :-)
-
- ALSO - I take no responsibility for lost data...
-
- -----------------------------------------------------------------------------
-
- Send more viruses (or heavily detailed documentation) to me! (On a clearly
- marked disc! LINK infected 20 files before I found it!!!)
-
- How to reach me:
-
- Tor O. Houghton
- Fjellveien 4
- PO Box 142
- 1361 Billingstad
- NORWAY
-
- Tel: +47 2 84 75 69
- Fax: +47 2 84 82 87
-
- Email - Internet : bhotvedt@usit.uio.no
- EMail - The World of Cryton : #121 (Badger)
- EMail - Excelsior! (M)BBS +47 2 846379 : Tor Houghton