home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!spool.mu.edu!howland.reston.ans.net!zaphod.mps.ohio-state.edu!cis.ohio-state.edu!news.sei.cmu.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: Clearing out old signatures (PC)
- Message-ID: <0017.9301121242.AA22066@barnabas.cert.org>
- Date: 7 Jan 93 19:46:14 GMT
- Sender: virus-l@lehigh.edu
- Lines: 37
- Approved: news@netnews.cc.lehigh.edu
-
- riordan@tmxmelb.mhs.oz.au (Roger Riordan) writes:
-
- > To guard against possible unknown viruses like to Chinese Fish,
- > which install themselves in high memory, but do not set the top of
- > memory down, we recently added a feature to VET to fill unused
- > memory with a diagnostic procedure which gives a warning message,
- > and locks the PC, if anything attempts to execute unused memory. So
- > if you run VET, and an unknown virus of this type is already in
- > memory, you get the warning as soon as VET calls an interrupt the
- > virus has trapped.
-
- Hmmm... How do you achieve that? One could fill the free memory with
- INT xx instructions and intercept interrupt number xx, but
- nevertheless chances are that the "something" that has been active in
- the unmarked memory will be called in the middle of the INT
- instrcution... The chances for this to happen are 50%... Ahh, I think
- I guessed it - you use interrupt number 0CDh? :-)
-
- > We investigated, & found that they were using Microsoft Lan Manager.
- > When PROTMAN was run from CONFIG.SYS a block of code was installed
- > at 7000:7800, but top of memory (as recorded at offset 2 in the PSP)
- > remained 9FFF:0000. If this code was overwritten by running VET (or
- > anything else) before the user logged in, the system would crash
- > when the program NBP.EXE was run as part of the log in procedure.
-
- Hmmm, that's a serious bug in the Lan Manager, IMHO... If it indeed
- keeps active code at that segment, then it could be overwritten by
- ANYTHING! A large program, multiple copies of the command interpreter,
- anything...
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-