home *** CD-ROM | disk | FTP | other *** search
- -----------
- SPRITEUTILS
- -----------
-
- This virus spreads by inserting a line in !Run files, loading a
- trojan SpriteUtils module. It intercepts the SWI vectors to process
- Econet_SetProtection and Econet_ReadProtection to return, and
- allow modification of two RPC`s, one to turn off all protection,
- and the other to restore the settings with just RPC`s enabled.
- It also attempts to disable the VProtect module, and will succeed
- with earlier versions. However, a new version of VProtect will
- have no problem in preventing the virus from being loaded in to
- a clean machine. It claims 2K of RMA workspace, and never release
- it, not does it restore the Econet protecting setting it first found.
-