home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!news.centerline.com!noc.near.net!hri.com!spool.mu.edu!agate!usenet.ins.cwru.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: mcafee@netcom.com (McAfee Associates)
- Newsgroups: comp.virus
- Subject: Generic detection of Boot Sector/MBR viruses (was Re: Is this a real virus?) (PC)
- Message-ID: <0003.9212181845.AA00632@barnabas.cert.org>
- Date: 16 Dec 92 19:24:03 GMT
- Sender: virus-l@lehigh.edu
- Lines: 34
- Approved: news@netnews.cc.lehigh.edu
-
- Good morning Vesselin,
-
- You wrote:
- >Ah, this explains the "Generic Boot Virus" report... It seems to me
- >that SCAN is using some kind of heuristics (Aryeh?) and reports a
- >"generic" boot (or partition) virus each time when something seems
- >wrong with the boot sector(s) - like missing names of the hidden DOS
- >files, missing signature (0AA55h), etc. In your case the whole
- >contents of the boot sector has been destroyed, so its contents has
- >become obviously "abnormal". This has triggered SCAN's heuristics
- >(just a wild guess; I'm not certain that it is indeed so).
-
- The Generic Boot Sector and Master Boot Record (partition table) virus
- detection routines are actually looking for several common instructions
- that appear over and over again in different viruses such as Stoned,
- Joshi, and so forth. By looking for these, we can detect variants/new
- viruses based on older viruses.
-
- The Generic Boot Sector/MBR code is not doing a "fitness check" to see
- if the partition table (the actual data) or 55 AA signature is valid,
- since those would not neccessarily be due to a virus infection (e.g.,
- could be an unformatted drive). Likewise, we don't do a filename check
- since that could cause false positives with non-DOS operating systems
- such as Unix and OS/2.
-
- Regards,
-
- - --
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- McAfee Associates, Inc. | Voice (408) 988-3832 | INTERNET:
- 3350 Scott Blvd, Bldg 14 | FAX (408) 970-9727 | mcafee@netcom.COM
- Santa Clara, California | BBS (408) 988-4004 | CompuServe ID: 76702,1714
- 95054-3107 USA | USR HST Courier DS | or GO MCAFEE
- Support for SENTRY/SCAN/NETSCAN/VSHIELD/CLEAN/WSCAN/NETSHIELD/TARGET/CONFIG MGR
-