home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: Checking high memory with VSCAN (PC)
- Message-ID: <0009.9211101922.AA06969@barnabas.cert.org>
- Date: 4 Nov 92 10:47:09 GMT
- Sender: virus-l@lehigh.edu
- Lines: 39
- Approved: news@netnews.cc.lehigh.edu
-
- padgett@tccslr.dnet.mmc.com (A. Padgett Peterson) writes:
-
- > >Till now, there are no known viruses that use the last two methods.
- > >Since the known-virus scanner can detect only known viruses, it is
- > >obviously useless to check places in memory where no known virus can
- > >reside.
-
- > Sorry to niggle but must point out that the above refers to MS-DOS
- > (and its close family) only.
-
- Well, yes, that's why there is a "(PC)" in the subject line... :-)
-
- > More specifically to an Intel based
- > system (PC) in REAL mode. Once operating in PROTECTED mode or with
- > virtual DOS boxes, all bets are off. I point this out only so that
- > people running Windows do not do a memory-only SCAN from a DOS box and
- > possibly miss an infection in another. If you are going to run from
- > Windows, it is best to check the programs on disk as well.
-
- Correct, I have several times posted messages about the difficulties
- to scan "the whole memory" under Windows in protected more... In fact,
- it is still possible to do it there - by switching back and forth
- between protected and real mode, but under OS/2 all bets are off...
-
- > Vesselin is correct that no known virus (though I'm not sure about that
- > new Windows specific one - haven't seen it) exploits this though I
- > am sure that it is just a matter of time.
-
- The only Windows-specific virus that we know is not memory resident...
- :-) As you can see, the virus writers have solved the problem in the
- easiest way... :-)
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.0 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-