home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!dtix!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: os2-stuff (OS/2)
- Message-ID: <0001.9301062041.AA14693@barnabas.cert.org>
- Date: 5 Jan 93 22:25:57 GMT
- Sender: virus-l@lehigh.edu
- Lines: 23
- Approved: news@netnews.cc.lehigh.edu
-
- KARGRA@GBA930.ZAMG.AC.AT writes:
-
- > as pointed out in point 10 at least *.dll and *.drv files contain code which
- > cannot be executed by the user, but is loaded and executed as any other *.ov?
- > As there are viruses which infect overlays, they can be infected in a similar
- > way.
-
- Could somebody check how exactly the DLL and DRV files are loaded in
- OS/2? The only reason that "some viruses can infect overlays" is that
- they infect on INT 21h/AH=4Bh, instead of INT 21h/AX=4B00h. Since some
- overlays are loaded with INT 21h/AX=4B03h, a sloppy written virus
- could infect them by mistake. How are the DLL and DRV files loaded in
- OS/2? If they are not loaded using any INT 21h/AX=4Bxxh function, then
- it is rather unlikely that any of the currently known viruses will
- infect them...
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-