DECEMBER 1991 This is a personal listing of some of the files located in the VIRUS Section (IDIR 316) of the Canada Remote System Bulletin Board System. They include the filename, the CRS description, and my own notes from my own impressions. In some cases, where I make no notes, the accompanying description is sufficient. This is not intended as a review, but may serve as a helpful summary for anyone considering his/her own exploration. At minimum it may prevent a member from downloading junk.-- David Kesterton, Suite 116-32, 65 Front St.W.,Toronto, Ontario M5J 1E6 (Author HAWKBEAT, HAWKBT11). ========================================================================== ASCII READERS ASCIICHK, BOMB-SQD, CHECKALL [STR], SCAN_ASC BACKUP UTILITIES COLUMBUS (Boot), DBACK, DBACK10 (FAT) CLEANUP AIDSOUT (Aids), CLEAN77, CLEAN80, CLEAN82, CLEAN84 CLEANV80, FIND1701 (1701), M-DAV (Dark Avenger) M-DISK (Boot), M-DISL (Boot), M-JRUSLM (Israeli-B, Brain), M-VIENNA (Vienna), MD (Boot), PCCYBORG (Aids) PONG-V15 (PingPong), SIEVE (Jerusalem B), V80CLEAN DATABASE DIRTYD9C, PCVI305B, TROJAN2, TROJM88, VIRUSCAT VIRUSUM, VSUM9103, VSUM9104, VSUM9105, VSUMX106 VSUMX107, VXRF0791 DOCUMENT PROGRAMMING CRCSET11, CRCSET13, CYCLIC DOCUMENT REVIEW TB-TEST (hardware anti-virus card) DOCUMENT WARNING 12TRICKS (12 Tricks), AIDS! (Aids), CYBORGV1 (Aids) PCAIDS4 (Aids), AVENGER (Toronto Avenger) BRAINMCP (Brain), CRISISV.TXT (Toronto Avenger) HACK78, LIMAVIR (Lima), SCAN78_, SCANV78, SCAN78TJ SCAN78NO (Scan 78 alert), NASATXT (Softguard) PRODIVIR (Dark Avenger), SUG-WORM (Softguard) TWELVE (12 Tricks), VIRALERT, VIRUSINF (Datacrime II) WARNSCAN, WINVIR (Windows users) FILE COMPARISON ALERT13U, CANARY, CAWARE, CHKUP32, CNY91E, CNY91G CRC_HDV2, CY91G, DELOUSE [in package], DETECT31 EXPEL11, FICHECK4, FILETEST, HMO301, MIC10, NV3 PCDANTV, PCDATA#1, -#2, -#3, -#4, PROCRC10, SENTRY SENTRY02 (?), SSCRC, SYSCHK1, SYSCRC, VALIDAT VCHECK10, VDETECT IMMUNIZATION EXERUN10A, FLUSHOT3, FSHLD14, FSP181, FSP_182 IMMUNE12, NETP21, VIRUSVAC INNOVATIVE CDEFND10, INTCHAIN [flawed], VIRSIM, VIRSIM10 VIRSIM11 LISTED BUT UNAVAILABLE 1991, IBMVIRUS, NAV5 MISCELLANEOUS ROID06 (animation parody), VALIDATE (CRC codes) VIRUSES (Book reviews) MISFILED (Wrong Section) BANUTIL.ZIP, CHKSUM11, FC100, TBMOD640, TSRTXT VAX-DOX, VAXTRN, ZZAP56A PACKAGED UTILITIES BOMBCHEK [BOMSQAD, WPHD, FPHD, CHK4BOMB], BOMBFREE [BOMBSQAD, CHK4BOMB, DPROTECT, EARLY, WPHD], CHECKALL [STR, READBAS], CHECKALL [STR, READBAS], COLUMBUS [ST0, RT0], VAUBA211 (French utilities), VIRUSKIT [BOMBSQAD, DBACK, DELOUSE, FPHD, WPHD, RT0, ST0, TRAPDISK, VALIDATE], WORMCHEK, YUPIPSS (Yugoslavian) SCANNERS AVS222, AVS223E, CES_402, DC89SCAN (DataCrime) FPROT114, FP-115, FP-115A, FPROT200, HCOPY, HTSCAN12 HTSCAN15, IBMSCAN1, JIV_31, NETSCN77, NETSCN80 NETSCN82, NETSCN84, NO_PLO1, PVIRUS10, SCAN7, SCAN76-C SCANRS42, SCANV80, SCANV82, TBSCAN20, TBSCAN23 TBSCAN26, TBSCNX29, TBS38619, TSAFE, UNVI1601, V3 V80SCAN, VANADEMO, VB_110, VIRCHK21, VCHK203, VCHK21 VIKIT404, VIRCDE12, VIREX16, VIROTECT, VIRSCAN VIRSRCH, VIRUSCAN, VIRUSFIX, VIRX12, -14, -15, -16, -17, -18, VRS03V19, VSCAN149 SCANNER UTILITIES AUTOSN30, AUTOSN32, BRT21A, CHOT11, CKOT, CKZP101 CVT-22, CENTRAL2, DLCHK12, DSCHK12, DMC_100, DMC_110 JREZIP20, PKINSV65, RESQ11, SCANSHEL, SCANTL1722 SCANZIPS, SFSHEL10, SHEZ64, SUPSC30, UNZIPIT, UPCHKTD VC100B, VC140CGA, VC200EGA, VC250EGA, VC250LTE VC350EGA, VC300LTE, VCOPY77, VIRUSTST, VIRZIP12 VIRZIP14, VIRUZ, VSHELL12, VTEC12, VTEC16A, VTEC18A VTEC20, VTEC25A, VTEC26, VTEC30A, ZIPVCHKB, ZVTEST10 SIGNATURES 15ALL01 (Norton), ALL9104 (Norton), NAVUPD01 (Norton) SIGS (Central Point), TBVIRSIG (Tbscan), VIRUSSIG (Tbscan), VIURSSIU (Tbscan) STUPID (Tell me ANTVIRUS, CURE100, IMMUNE12, KILLVIR2, NETP21, NOX they're not) SENTRY, SENTRY02, STEP110, WCV201 TESTERS TB-TEST TSR VIRUS SPECIFIC BANDAID, BLUESHOT.ARC TSR WRITE PROTECT DVI, HDSENTRY, NOX, SECUR209, SECUR224, SECUR225 SECUR226, SECUR227, SECUR228, SECUR229, STEP110 STOP1, TRAPDISK, TROJAN, VSHL140, VSHLD77, VSHLD80 VSHLD80B, VSHLD82, VSTOP254, VSTOP300, VSTOP400 VTAC48 TUTORIAL ANTI-VIR, GBSON104, GORETSKY, HOHVIRUS, IBMPAPER MYTHS_3, VIRESSAY, VIRPRES, VIRUSD, VIRUSKIT, VIRUS101 12TRICKS.ZIP 6577 02-22-90 "Complete description of a Trojan that was installed in Coretest and the 12 nasty things it does. (SCAN58 detects it)." >A 17-FEB-1990 USENET trojan alert from Alan Solomon, Bucks, England and Christoph Fischer, West Germany. 15ALL01.ZIP 24742 07-26-91 "Complete update of viruses for Norton anti-virus 1.5" 1991.ZIP 2778 08-09-91 "Warning about the new outbreak of old virii from the East Coast." > [ Listed in IDIR 316 but not available for downloading] AIDS!.ZIP 4277 01-17-90 "12/89 Docs on a Cyborg from McAfee" >Another report on the Cyborg AIDS virus. See also CYBORGV1.ZIP, PCAIDS4.THD. AIDSOUT.ZIP 38566 12-20-89 "AIDSOUT AIDS Trojan Remover will remove ..." >To remove the AIDS virus, by Jim Bates. ALERT13U.ZIP 63253 09-10-90 "Check for viruses" >Turkey time! This program has a decent menu, and that's it. It's a file comparison program in which the user has to update the filelist, and it only handles about 200 files. I tested it on 1 file, size 21,400 bytes, and it took 40 seconds to update and another 40 seconds to verify -- 1 file only! From Robert W. Reed, Casselberry, Florida (1988). ALL9104.ZIP 19973 04-24-91 > Norton Anti-Virus signature update. See 15ALL01. ANTI-VIR.ZIP 98381 06-04-91 (and also) ANTI-VIR.ZIP 144644 07-28-90 "Tutorial And installation routines for anti-viral software." > See VIRUSKIT.ZIP {DEL} ANTVIRUS.ZIP 38956 07-11-89: "Virus-Free v1.0: Arche's TSR anti-virus util" >Due to the lack of a manual (referred to but not included), rather sloppy English, and the mystery of trying to figure out what it's supposed to be doing, ARCHE's Virus-Free Complete (sic) Computer Protection is an INCOMPLETE package that I haven't the patience to waste my time with. ASCIICHK.ZIP 13152 09-10-90 "Anti-Virus Extracts" > Huh? It's not extracts, i.e. documents; it extracts ASCII values. It includes the C and PASCAL code and is rather fast. By George Dinwiddie of Columbia, Maryland. AUTOSN30.ZIP AUTOSN32.ZIP 38896 03-18-91 "AutoScan v3.2 ->AutoScan v3.2 Front end for SCAN.EXE & various compression programs. Looks inside comPressed files & keeps a log of checked files. (06-10-91)." >Good stuff. Just update your AUTOEXEC.BAT to include a path command (example is provided) that tells DOS where to find the AUTOSCAN.EXE file, the necessary unarchiving files (such as PKUNZIP.EXE), and McAfee Associates SCAN.EXE. Then edit the configuration file (by adding or deleting a semi-colon to comment out or include various features). Once that's done, from any directory that contains archived files, just type AUTOSCAN. The program then proceeds to automatically and rapidly unarchive compressed files in a work directory, scan the files for viruses, send a report to the monitor and to a LOG file, then delete the files from the work directory. By Nick Tucker, MountainTop Technologies. AVENGER.ZIP 3141 04-29-91 "Information on the NEW *DARK AVENGER* VIRUS! Includes info on identifying it and adding the Id string to SCANV for future safety! This variation of the Dark Avenger is *NOT* detected by SCANV 76-C version!!! A must!" >See also CRISIS_V.TXT. AVS222.ZIP AVS223E.ZIP 76908 03-21-91 "AVSearch v2.23: virus scan program that looks for 75 virus strains in memory, partition table, boot record and files, w/many options; 12/05/90; Tjark Auerbach/Detlev Hoppenrath." >Tjark and Detlev's shareware version (stripped down) of their Commercial program ANTIVIR, another virus scanner. Where McAfee & Associates are overbearing, Tj and Det are overly humble, almost apologizing for bringing this out in spite of the big USA scanning industry. (For this, I like them, but I haven't tested the program.) BANDAID.ZIP 9216 10-02-90 "TSR anti virus. Works from Oct 1 - 31 '89" >From Panda Systems*, a mini-version of the MONITOR program from the Panda Utilities, free as a public service (for commercial on-line systems, not private BBS's), to detect expected Oct 1989 attacks from a few viruses. This is an unnecessary file, unless your system date is set wrong, or unless you're studying the subject. BANUTIL.ZIP 366061 06-08-91 "Banyan Vines utilities from the Association of Banyan Users. Real time savers." > Wrong Section - utilities for Banyan E-mail Streettalk. {DEL} BLUESHOT.ARC 46976 08-31-89 "IBM internal use anti-virus toolkit." > A TSR from IBM Israel, (1989) to detect and prevent spread of some earlier common viruses - Jerusalem, Brain, Austrian, Austrian2, Bouncing Ball, Datacrime. Also contains early version of IBM's virscan. It's all dated, so of no particular value, unless you want to collect a few virus signatures. BOMB-SQD.ZIP 15468 01-22-90 "Check for Trojan bomb" >BOMB-SQD: This is not the Andy Hopkins BOMBSQAD. This 1986 effort from Associated Bulletin Board Services, San Bernadino, California, is another ASCII reader and INT 21H displayer. It is much faster than CHK4BOMB. BOMBCHEK.ZIP 17448 03-25-91 "A trojan condom for your computer" >This includes Andy Hopkins BOMBSQAD (TSR to halt upon READ WRITE VERIFY FORMAT [R W V F] or [U parameter to uninstall]. Also includes WPHD (Write Protect Hard Drive), FPHD (Format Protect Hard Drive). The only inferior program is CHK4BOMB, an ASCII reader which is a precursor to the more efficient LABTEST* (by the same author). BOMBFREE.ZIP 51313 07-28-91 "To protect your computer from virus." > Packaged utilities, antiques: BOMBSQAD, CHK4BOMB, DPROTECT, EARLY, WPHD. BRAINMCP.ZIP 8228 08-31-90 "Info on Brain VIRUS" >Primitive, wordy, 1988 report from Georgetown Univ, Washington D.C., of no particular use, except for quaint ancient history comment: "Currently [May, 1988] there are 39 known strains of computer viruses as reported by the National Bulletin Board Services Association." BRT21A.ZIP 88584 06-10-91 " The Bridge Terminus 2.1A: Menu/Front End for ARC/LHA/PAK/ZIP & McAfee's virus scan. Mouse support." > Another decompress & scan. CANARY.ZIP 108747 06-17-91 "Acts as a fire alarm to warn you when your computer is infected with a Virus. 04/16/91" >This Canary walks like a turkey. COMMAND.COM, CANARY.EXE and CANARY.DAT are scanned each run for changes. It's a miniature file comparison program which is hopelessly abbreviated, needlessly slow, and overly documented. They want $50 -- it's not worth fifty cents. CANARY.DAT changes with each run, perhaps with a counter in case it is not registered after 90 days or 90 tries - maybe it flies away if you don't pay. CAWARE.ZIP 16361 09-10-90 "Make your 'C' programs immune from viruses." >For TURBO C users to make their C-source programs self-check CRC and filesize. Untested. {ARC} CDEFND10.ZIP 40376 12-05-89 "New antivirus program - changes com/exe" > From Michael Dorio, MAFIAWARE, (1989). He wants $50 for you to register, it's worth maybe $5. The idea is that to make your .COM and .EXE files less of targets to viruses, his batch files rename the extensions to .MMM and .DDD. To run them, you type RUN . It's an interesting idea that could be expanded on, the only defects being: 1) you can't choose your own extension aliases, so viruses could adjust for this trick, 2) many pgms are executed by selecting from within controlling pgms, like Norton Commander, and expect the original extension, 3) viruses don't limit themselves to seeking merely file extensions. CENTRAL2.ZIP 67248 09-25-91 "Ega Version of virus central." > Alejandro Abello, "The High-flying Hard-lander". Ornate, unnecessary high-end shell. See VC100B. CES_402.ZIP 39816 08-08-91 "Code Execution Simulation v4.02. A new approach to virus protection." > Ornate Dutch scanner, requires a lot of memory. Untested. CHECKALL.ZIP 29317 09-10-90 "Checks for Trojans" >Uncompresses to STR.ZIP and READBAS.ZIP, the former is yet another ASCII reader, but not too bad because it has definable string length parameters and stops after 22 lines if you're sending the results to your monitor, so it won't scroll away (Ed Nather, University of Texas, Astronomy Dept.), includes C source. The latter is 1985, Nelson Ford, Software Library of Houston Area PC Users. It reads a "basic program from Dos that was not saved in ascii. It saves you from having to load Basic to see what a program is." CHKSUM11.ZIP 6382 11-28-90 "Calculate the negative checksum of .EXE file" >This should be in the Programming - Assembly Language section. This is an OCT 1987 project from James P. Morgan of Orlando, Florida, concerning the negative checksums of .EXE files that are calculated by the DOS linker. CHKUP32.ZIP 77006 09-10-90 "CHECKUP v3.2 4/20/89: good virus protection CRC file check/compare to master." > Turkey. In spite of the enclosed hype, it failed to impress. It has to be "launched", for each separate extension and each directory that you want to scan. Each "launch" produces a big report file. CHOT11.ZIP 49891 04-17-90 "Checks inside zips with scan.exe for viruses" > Another decompress & scan. {ARC} CKOT.ZIP 49435 10-24-91 "Virus scanner for BBS' or stand alone." > Checkout v1.1 1989, by John Bince. Another decompress and scan, requiring McAfee's scanner. CKZP101.ZIP 16816 01-12-91 "CHECKZIP 1.01 Virus testing Shell for zips adds wildcard file extraction and fixes bugs with timestamping." > Another decompress & scan. CLEAN77.ZIP CLEAN80.ZIP 88183 06--26-91 "Companion program to McAfee's SCANV80.ZIP..." CLEAN82.ZIP CLEAN84.ZIP CLEANV80.ZIP > More cumbersome material from McAfee and Associates. If I ever get a virus on my system, I'm going to erase (zero-out) the files, and restore any other drive components that have been tampered with (from my own resources). CNY91G.ZIP CNY91E.ZIP 88183 06-26-91 "Canary V91e Virus Detection and alarm alerts you to any virus effects." > That xanthic turkey again. See CANARY.ZIP. {DEL} COLUMBUS.ZIP 12418 09-22-89 "Protection for the Columbus Day Virus." >Contains ST0.EXE, RT0.EXE, and 'C' code. ST0 sends a copy of your hard drive's track 0 to floppy in A drive. RT0 writes that same copy from A drive back to your hard drive. It works. CRCSET11.ZIP CRCSET13.ZIP 37418 06-10-91 "CRCSET v1.3 anti-virus algorithm that uses 32-bit CRC to verify the integrity of the running program; includes C and TP source code. Update includes faster calculation and fix for Microsoft C. 06/10/91" >For C and Turbo Pascal programmers who want to inject a Cyclic Redundancy Check (CRC) into programs to be executed. Good math notes and background information. 1991, from Keven Dean. CRC_HDV2.ZIP 23098 09-10-90 "Generate CRC to check on file integrity." > A speedy but primitive and tedious CRC calculator. I was unable to get it to check my entire hard drive in one shot; it'll do a directory at a time, and it does all the files or just one kind of file. Also, you have to verify the results by hand. CRISIS_V.TXT 2552 04-18-91 "Warning re Dark Avenger virus" > Toronto virus scare, a variation of the DARK AVENGER uploaded to ROSE BBS. See also AVENGER.ZIP. CURE100.ZIP 7346 04-11-90 "The ultimate cure for the virus scare." State of Georgia humour -- haw, haw. PLACEBO.DOC claims that PLACEBO.EXE is a cure-all from the fear of viruses past, present and future. Viewing the .EXE file turns up the text: "This program does nothing, so get out of my .EXE. It is a Placebo like it says. McAfee is the anti-Christ. It's a joke son..." CVT-22.ZIP 34070 04-03-90 "Virus check and/or convert to/from archive formats: ARC, DWC, LZH, MD, PAK, ZIP, ZOO, others. Supports user defined compression params, nested archives, saves/removes ZIP comments, plus many other features, v2.2 UPACKEXE." > Another decompress & scan. CY91G.ZIP 93464 06-25-91 "PC Canary. Virus detector for miners..." > See CANARY.ZIP. CYBORGV1.ZIP 8888 12-20-89 "More info on the PC Cybrog Corp. AIDS trojan auto- matically; good for sysops w/adult files, protected zips, w/unique passwords." > See also: AIDS!.ZIP & PCAIDS4.ZIP. CYCLIC.ZIP 5823 10-27-90 "CRC-16 & 32 routine w\TC source" >Description should read "w\TP" - it's just 2 files, both Turbo Pascal, docs are in the files. See other CRC notes if you're into CRC's and Turbo Pascal, otherwise of no use. (1986, Steven Satchell) DBACK10.ZIP 2393 07-13-89 "Creates backup of FAT in case of a virus" DBACK.ZIP (1987, Eric Gans, part of VIRUSKIT.ZIP) >DBACK10 kept giving me a read error. I remembered the VIRUSKIT version, DBACK.COM; so I tried it, and got same read error. Tried my own pgm which incorporates a FAT reader and analyzer -- it worked. I don't know what DBACK's problem is. DC89SCAN.ZIP 22528 10-21-89 "Scans for DataCrime virus v1(a) & 1(b)" >Yep. And also in DOC an advertisement for other Sector Technology Products. 1986, Michael Allen. Antique, and unnecessarily large. DELOUSE.ZIP (packaged in VIRUSKIT.ZIP) >It verifies checksums of files that you specify in a .DAT file, full path and filename required. I played with it for a while, finally settling on the method of adding " > FILENAME.EXT" to the command line during Update and Verify to get it to send the results to a file I could later review. It just gives checksum results and YOU have to create the .DAT file for all files in all directories - cumbersome. DETECT31.ZIP 35591 03-23-90 "The Detective v3.1 file tracking/virus" > A file comparer, but you have to check the CRCs generated by hand. Primitive. DIRTYD9C.ZIP 80998 04-13-90 "The Dirty Dozen v9.0c:hacked/trojan/virus, TXT, maintained by Eric Newhouse" > Dated: lists of viruses and trojan droppers -- needs to be combined into a more accessible and cross-referenced format like Patricia Hoffman's excellent VSUM project. DLCHK12.ZIP 9527 03-19-91 "DLCHECK v1.2 Automates scanning of downloads for computer viruses using McAfee's SCAN and standard archive utilities." > Another decompress & scan. DMC_110 DMC_100.ZIP 25274 05-20-91 "DayMaintC. A frontend for McAfee's SCAN, will do a total scan on system once per day, to be placed in AUTOEXEC.BAT." > Another decompress & scan program. DVI.ZIP 1730 05-12-91 "Dynatron antivirus interceptor, the best! 1 files (sic) New: 05/04/91" >Contains 1 file, a .COM file which is smaller than the .ZIP file itself. Its a TSR, like BOMBSQAD. In spite of the absence of documentation, running it tells you to select parameters. I wanted it to ask if I wanted to write to the BOOT sector and to a .COM or .EXE file. It worked for the BOOT sector, pausing first, but it failed for .COMs as I was able to overwrite them with ease. EXPEL11.ZIP 73856 02-27-90 "EXPEL v1.1 virus control device that includes a selective write-protect function, 9 different levels of CRC checks, and Sample Track functions. 02/20/90 Toltech. > This 1990 Quebec program compares files for changes. I found it the slowest of all that I tested. You could make it faster by selecting level 9#, but that meant checksumming only every 9th byte as a result of which it failed to detect subtle file changes. As to its write-protect function, all it does is set the file attribute to READ-ONLY, one of the simplest defenses that any hostile software can bypass with ease. Amateurish. EXRUN10A.ZIP 22547 09-05-90 "Modify EXEs so won't run w/o EXERUN in ram TSR pgm, guard against tampering/viruses. Allows check for other required pgms/password V1.0a >Poorly worded utility from Japanese name in a Quebec post box number. Apparently, the sofware will lock a file which will not run unless a) EXRUN is loaded into memory, b) the checksum matches, c) you enter your password, d) you are running the file on another machine (by checking machines BIOS and DOS), and other requirements not clearly understood because the doc file is so confusing. FC100.ZIP 27335 10-22-89 "File Check v1.0 for Windows 3. Virus/file corruption checker." >One of the nicest little pgms I've seen in this section yet. The only problem is that it doesn't belong in this section. It is NOT a FIle Check for Windows or anything else; it's a Utility called FC-File Commenter 1.0, 1989, by Ronald C. Bieber. It lets you add comments to file listings. {DEL} FICHECK4.ZIP 84155 12-31-89 "Check file integrity (look for growing bugs)" >This was the best Shareware File Comparison pgm that I tested, not as quick or comprehensive as my own commercial pgm, but quite successful once you get it going. You have to add complex parameters to the command line, and it wants to be run from a floppy, and it occasionally gives strange error codes, other than that its a decent, usable effort. FILETEST.ZIP 55634 07-11-89 "Handy Virus Detector". >Its a FILE COMPARISON program that you have to tell what files to compare by adding the paths and files to a data file. It took 1 minute and 10 seconds to update 2 -- that's TWO -- files! For 200 selectable files it would take an hour and a quarter. 1988, from L.P. Levine. Probably the worst product in its class that I have ever encountered! FIND1701.ZIP 24094 08-23-89 "Detect and Remove '1701' VIRUS" FLUSHOT3.ZIP 10182 01-22-90 "This is Version 3 of the COMMAND.COM virus va[ccine]." >I have heard reports of vaccine-style program attachments causing hard drive lockouts, and having had 1 security software lock me out of my own hard drive due to an early version bug, I prefer to avoid testing such security devices. FP-115.ZIP 252290 05-26-91 "F-PROT v 1.15 Lastest version of Excellent virus scanner from Iceland. Very Comprehensive. Good Docs." FP-115A.ZIP FPROT114.ZIP FPROT200.ZIP "Complete rewrite...Easier to use/set up." > I've seen other BBS reviews of versions earlier than 2.00 describing it as confusing. That's true. But not so with 2.00. Even though it is still evolving, it is a superb scanner! Has a comment from author that few of the virus-scared will ever recognize: "Signature-based virus scanning is not the ultimate solution to the virus problem." FSHLD14.ZIP 34354 09-19-90 "FILE SHIELD v 1.4: designed for software distributors, it shields executable files so that virus infections are instantly detected and automatically removed; 08/27/90; McAfee Assoc." >Adds code to an .EXE file to allegedly shield it from a virus. I tested it on my own program, first adding shield, then changing contents of program. Program ran, as if nothing had changed. I then tried fresh program with shield and added extraneous bytes to the end, simulating standard virus attack. Test run caused system hang, had to warm reboot. Maybe it has to be a real virus. I would prefer a self-verification by checksum/CRC for guaranteed results of tampering, instead of an iffy procedure like FILE SHIELD. FSP181.ZIP "... Searches for over 100 viruses." FSP_182.ZIP 100533 05-01-91 "L*FluShot+ v1.82 virus protector *UNTESTED* Install program to registered users and there is a FluShot Plus Plus." >See FLUSHOT3.ZIP GBSON104.ZIP 9557 07-16-91 "Steve Gibson Infoworld Article on Virus's." > By Steve Gibson: (1989). General virus talk. GORETSKY.ZIP 5422 07-04-91 "PRIMEr on Virus Scanners From Aryeh Goretsky of the MCAfee Staff." > Aryeh Goretsky, McAfee Associate: minor tutorial on 3 anti-virus protection types. HACK78.ZIP 3210 05-19-91 "Info re:hacked/trojan SCAN78. Text. Last revision date in archive 05-15-91." >Seems to be quite a number of files on this topic. But just more promo stuff to authenticate the McAfee Dynasty. See also: SCAN78_.ZIP, SCANV78.ZIP, SCAN78TJ.ZIP, SCAN78NO.ZIP. HCOPY.ZIP 34090 07-18-90 "Utility that checks for viruses while copying files to or from your harddisk." >This is a free utility that works like the DOS copy command. HCOPY.EXE, the only file in the package, will scan for 68 viruses as you use it to copy files from one location to another. It uses the IBM virus signature list. The purpose is to promote HyperACCESS/5, a communications package, which also scans for viruses as you upload/download. I tested it by entering some IBM virus signatures into some dummy .COM files, and it worked fine (I also scanned the same files with IBM's VIRSCAN, McAfee's SCAN, and Skulason's F-FCHK. Only IBM's scanner and HSCAN caught the potential virus. That is not a knock on SCAN or F-FCHK, as they likely scan for the same virus using signatures or in manners other than VIRSCAN uses.) The documentation data (which you get when you just type HCOPY with no parameters) says that: "While HCOPY identifies only known viruses, the odds of hitting a new virus are 10,000 to 1, according to virus experts." That's why it only scans for 68 viruses (presumably the common ones), rather than the 680+ that Patricia Hoffman has listings for. However, once you register HCOPY (it costs nothing!), you can have access to the up-to-date versions through their BBS (Hargraeve's BBS (313) 243-5915). I have my doubts about the same value being applied to a communications software, because the viruses would be virtually undetectable in an archived state. Even Hargraeve's says: "viruses in files packed with ARC, PKARC, or other compression programs can be detected only after the files are unpacked." [For that matter, why not just scan your directory containing new files, before doing any copying.] HDSENTRY.ZIP 8124 01-22-90 "Memory resident protection against Trojans." >Duplicate of TROJAN.ZIP. 1987 by Andrew Fried. Free TSR protector, in the style of BOMBSQAD, except that you test the new programs on your floppy. Writes, etc. will be permitted, BUT NOT TO THE HARD DRIVE, only read requests and resetting to hard drive are permitted. Good idea, dated technique. The ASM source code is included. HMO301.ZIP 34893 04-14-90 "Calc files/ CRC & check for changes v3.01 w/C" >Another file comparison program that YOU have to provide the file names for. I won't waste the time with any more programs that do not recognize that computers were designed as time-savers (among other things). HOHVIRUS.ZIP 4065 10-22-90 "Beginner's help in combatting viruses. Uploaded by ExecNet staff." >Virus perspective (text) from Jack Pizza, House of Help BBS. Amusing, realistic, informative. Contains good definition of a virus writer. HTSCAN12.ZIP 31605 01-25-91 "Htscan 1.12 Programmable virus scanner." HTSCAN15.ZIP "...Use virus signature database in VIRUSSIG.ZIP" >Dutch utility to scan viruses, but lacks VIRSCAN.DAT or HTSCAN.DAT with signatures, by Harry Thijssen, 1990, Netherlands. (Jan R. Terpstra, maintains VIRSCAN.DAT.) Too many of the other virus scanner authors have their own encoded signature files (Skulason, McAfee, Norton). That's understandable since 1) big bucks are involved 2) presumably their own people put the effort into gathering & parsing the virus samples. But it all leads to a vastly fragmented area of protection, especially considering how limited virus scanning really is. IBMPAPER.ZIP 26698 04-18-90 "IBM research paper on viruses." (duplicate of VIRUSD.ZIP) "Coping with Computer Viruses and Related Problems", text from IBM (Steve White, David Chess, Jimmy Ko). IBMSCAN1.ZIP 110590 7-29-90 "IBM's very own virus detector. Very good!" >DUPLICATE MATERIAL: VIRSCAN.ZIP (7996) contains only 7 boot signatures, and 21 file signatures, and a read.me file. Ignore it. IBMSCAN1.ZIP is also older material, (12 boot sigs, 51 file sigs) but it has the actual virus scanner, and a file comparison program - CHECKUP (like most, somewhat slow, but decent). The file to get is: VSCAN149.ZIP -- no CHECKUP here, but well over 200 boot and file signatures. Get your copy fast - as it may not last (it's not licensed to be listed on BBS's.) IBMVIRUS.ZIP 109459 10-09-91 "IBM's VIRUSCAN version 2.12 shareware edition similar to SCAN with documentation, etc." > [This was listed in IDIR 316 but not available for downloading] IMMUNE12.ZIP 12399 06-03-91 "Immunizes files against common virus. Quite good for the price! Last revision date in archive:05-21-1991." >1991 by David Grant of PCVRF Electronics BBS. The idea here is that by adding a code to locations in your executable file, you can fool a virus into thinking that the program is already infected, and it will leave it alone. This version is prepared to innoculate your files against Jerusalem sUMsDos and Vienna-62 and variants. This is of extremely limited value, even with the promise by David Grant to expand to include other viruses. The reason for this is: 1) other viruses might expect the locations to contain THEIR code, and so think the files are not infected 2) many viruses do not use this technique 3)in the game of "cops-and-robbers", as the cops improve their technology, so too do the robbers advance their technology -- this does not deter viruses; it merely makes the challenge greater for a virus creator, and it gives the user a false sense of security about his files. INTCHAIN.ZIP 8628 02-04-88 " Detects Viruses by comparing interrupts" >It's supposed to send a copy of your interrupt vectors and the first ten bytes of the interrupt to a filename of your choice, but it constantly failed due to a divide error, then flunked out, hanging system. {ARC} JIV_31.ZIP 18253 09-08-89 "Virus detector/immuniser from Israel." >Another virus scanner, 1989, by Noam Herzenstein and Ori Berger. This is an old package; to get the updated version, you'll have to phone Israel. JREZIP20 61538 07-14-91 "Jonathan Richards Intelligent Rezipper 2.0! Scan for viruses, delete files from within a zip file, Insert Comments, skip files that have authenticity checking, reset the zip file date, rezip files within a zip file and do the above without having to actually rezip the file! Shareware $15" > Jonathan Richards ZIP utility to use with SCAN.EXE. Untested. KILLVIR2.ZIP 67808 06-13-90 "Virus remover (very easy)." >Useless. It's a mixed bag containing (among other things) FLUSHOT2, IMMUNE (see IMMUNE12.ZIP), and JIV2 (even older version of JIV_31.ZIP), and a PKZIP.EXE. Maybe someone put this together to win an uploading contest. LIMAVIR.ZIP 1657 10-12-91 "VIRUSES THAT THE SCAN V82 DON'T DETECT..." > A warning about a new .COM virus ("lima") found in Lisbon on SEP 1991. LOG8910D.ZIP 86453 11-04-89 "Virus-l digest 4th week, October, 1989" >Should be renamed so it sorts better. Call it VIRL216.ZIP (issues 216 - 225). M-DAV.ZIP 14720 10-22-89 "Dark Avenger virus disinfector." M-DISK.ZIP 12309 05-12-90 "Cleans Boot/Partition table viruses from your hard drive." M-DISL.ZIP 12846 06-29-90 "McAfee virus clean-up util for any DOS ver." MD.ZIP [A duplicate or variation of M-DISK.ZIP, M-DISL.ZIP] M-JRUSLM.ZIP 9790 09-01-89 "Removes Israeli strain B viruses and Pakistani Brain virus." M-VIENNA.ZIP 11197 10-08-89 "Vienna virus disinfector." >All of the McAfee utilities are job specific. M-DISK and M-DISL are the Partition/Boot disinfectors, but only on DOS versions, 3.0, 3.2, 3.3, 4.0; M-DISK/or M-DISL should be changed to M-BOOT. The others are for Dark Avenger, Jerusalem and Vienna (not necessarily all variations). MIC10.ZIP 25316 07-16-91 "Detect the presence of a Virus." > Module Integrety Check v1.0 JUL 1990, by Steve Leonard, New York. Another slow file comparison pgm. MYTHS-3.ZIP 10029 02-14-90 "Virus Myths v3 - Rob Rosenberger." > READ THIS! Excellent virus myth information, 1990, from Rob Rosenberger (Illinois) and Ross M. Greenberg. Sample quotes: 'Viruses could destroy all the files on my disks.' "Yes, and a spilled cup of coffee will do the same thing. If you have adequate backup copies of your data, you can recover from any virus/coffee attack. Backups mean the difference between a nuisance and a disaster. It is safe to presume there has been more accidental loss of data than loss by viruses and Trojan horses." 'Viruses have been documented on over 400,000 computers.' "This statistic comes from John McAfee, a self-styled virus fighter who seems to come up with all the quotes the media love to hear. If you assume it takes five minutes to adequately document a viral infection, you have to wonder where Mr. McAfee got almost four man-years to document a problem which is less than four years old. We further assume his statistics include every floppy disk that was infected with a virus, as well as all of the computers participating in the Christmas & InterNet worm attacks. (Worms cannot be included in virus infection statistics.) The press doesn't really understand computer crimes, so they tend to call almost any- thing a virus." NASATXT.ZIP 2189 09-10-90 "Info--RE: Trojan Horse" >A small text file on background of vicious SOFTGARD protection scheme, which trashes all drives' data if SUG.ARC if used to bypass SOFTGARD protection. NAV5.ZIP 185475 08-26-91 "NORTON ANTI VIRUS 5, INSTALLABLE..." > [This was listed in CRS but not available for downloading] NAVUPD01.ZIP 2318 03-08-91 "Norton's Anti-Virus Update" >A BBS ad and a data file for some additional Norton-style virus signatures. NETP21.ZIP 25970 12-16-89 "NetGoat Plus anti-viral LAN scape goat. It becomes infected before any other program. v2.01" >First Canaries, now goats. I guess the idea is to have some program take the heat, or be "armour plated" to protect it from the evil. So what is the problem here? There's no .DOC file, just an .EXE file (hmm!). You run it and it says to run with H for help screen, R for register info, F for a flyer, or with the name of a file to give it "armour plating". I already had the Help screen so I skipped that. I tried the R and F runs, and it told me I had an unregistered copy (I knew that). It also told me that NETP size should be 34440, but it isn't, it's: 37024 (HMMM!). So then I took some necessary precautions, running 1 virus scanner, installing my own TSR interrupt protector, and preparing for changes with my own file comparison program. After I selected the correct format (I think it's right), I was told that NETP was finished and I should check the size. I did so -- same size. My TSR indicated no writes to disk had occurred. In case it had bypassed my TSR, I reran my file comparison program -- no changes to boot, fat, or any files. I reran the virus scanner to see if any memory had been infected -- nope. So what we have here is a incompetent, undocumented demo from Ian Gerada, South Africa. (Can hardly wait to rush off and register your copy, right?) NETSCN80 NETSCN82 NETSCN84 NETSCN77.ZIP 59529 04-30-91 "McAfee's network version of SCAN, NETSCAN v7.7." >Actually its the network version of SCAN 77 NOX.ZIP 5621 04-22-91 "NOX is a small TSR utility that will TOTALLY disable all writes to disk by ANY program. Good for testing programs that are uploaded. Shareware, tested against over a hundred real viruses!" >From Daniel J. Karnes, Nashua NH ("Howdy"). It works, but there's no flag to indicate that a write was attempted. You could theoretically run a large set of programs to test for vicious behaviour, stop all of their writes, and never KNOW which program was the hostile one, because all NOX does is bypass the write, flagging nothing! NO_PLO1.ZIP 24940 08-20-89 "No Plo v1.0: check for Jerusalem/Israeli virus." >From Bradford B. Taliaferro, SEMPRINIWARE: "Software that doesn't induce vomiting." Excuse me if I upchuck for a second, Brad, but your Company name made me queasy. Nothing too exciting here. NV3.ZIP 33965 09-21-89 "NoVirus v3.0 anti-virii program." >1988 from Matt Hill. This dated effort has a lot of documentation. All it does is a comparison of the system files (COMMAND.COM and the 2 hidden .SYS files). I couldn't figure out where it stored its update (because I didn't have the patience to actually read that massive .DOC file), but my own comparison program indicated an additional hidden file somewhere. It was in the root directory, NOVIRUS.DAT -- it was set to hidden, read-only. Any virus worth beans is going to overcome that. PCAIDS4.THD 40474 12-21-89 "More from USENET on CYBORG virus in ASCII..." >See also AIDS!.ZIP and CYBORGV1.ZIP. PCCYBORG.ZIP 37503 09-10-90 "McAfee's program to find and recover from the cyborg AIDS virus program." PCDANTV.ZIP 13797 09-10-90 "PC-DOS Anti-Viral pgm" >Another mini file-comparison program. (Yawn!) As well as the hidden system files, it also checks your AUTOEXEC.BAT and CONFIG.SYS. But what about the other 200 - 2500 executable files? From Ioannis Hadjiioannou. PCDATA#1.ZIP, PCDATA#2.ZIP, PCDATA#3.ZIP, PCDATA#3.ZIP "Virus Program from the PCMag -- program looks very complete set up to allow you to create your own clean up program however it dates from 1/90 and may be dated." >Dated, yeah, and jumbled, and massive. Seems to have something to do with file comparison, but only for masochists. PCVI305B.ZIP 369046 05-17-91 "Clough & Partners' PC Virus Index & database for all known viruses. V3.05b (5-7-91)..." >The quantity of material competes admirably with Patricia Hoffman's VSUM database. Having just reviewed this effort a 2nd time, I must conclude that in spite of the annoying and unnecessary sounds, the 30-second delay at the start, the additional REPORT material and the various methods of sorting the dbase, by date, Country, and so forth, this is an excellent product. PKINSV65.ZIP 93709 10-28-91 "PKinsert Version 6.5... Insert archive comments, check zip integrity, scan for virii, add and delete disclaimers, etc. Perfect 'Hands-off' SysOp upload monitor. Support for PCBoard V14.5a and Networking environments. ... includes a new 'Tagline History' feature!" > PKinsert v6.5, OCT 1991, ZIP utility for inserting comments, etc. plus checking for viruses, Montreal. Needs McAfee's SCAN. Complicated. PONG-V15.ZIP 29560 12-29-90 "Programme francais de traitement specifique du virus ping-pong (bouncing bal) version 1.5." > French PingPong disinfector, as well as a small utility to check for bad sectors, plus some assembly language source code that reveals such warning gems as: "AAARGH! Ce disque est contamin‚ !" By Dominique B‚caert, 1990. PROCRC10.ZIP "Quick CRC checker. Detects file corruption. Use this utility in your AUTOEXEC to check all unexpected alterations. Can be used as an early waring measure against hard disk failure or virus infection. Incluse src." >In my first tests I concluded that this was an "Ordinary CRC checker". But now, having tested so many file comparison programs to-date, let me revise that to: "a pearl among the slime." The documentation is concise: 1 page. Your file list comes from SETUP.BAT, just include the lines for the files you want checked, such as *.DOC. No big effort here, not like other file comparers that want you to type it all in (including the directories). SETUP.BAT will jump immediately into the UPDATE routine -- it will calculate CRCs for all defined files and create its list for future comparisons. To update in future, use UPDATE.BAT. To verify in future, use CHECK.BAT. It is a speedy little effort, taking 2 mins 40 secs for the update and 2 mins 36 secs for the verify, far better than all other SHAREWARE/FREEWARE equivalents. It's copyright 1988 by Samuel H. Smith, and appears to be FREEWARE. The update file in my test was relatively concise -- 4352 bytes, but there was no log file. The PASCAL source code is included in this no-frills, well-designed effort. PRODIVIR.ZIP 1636 06-25-91 "Report from someone who claims his Prodigy disks arrived virus infected w/Dark AVenger requiring CLEAN77!" > PRODIGY.TXT: Brief report from a computer dealer in Florida who discovered Dark Avenger on some prodigy disks. PVIRUS10.ZIP 47276 "ProVirus 1.0: a Prodigy utility to protect the Prodigy executable from viruses and icon enhancer..." > PROVIRUS, Prodigy Software virus scanner. Prodigy Utility. Virus scanner and icon enhancer, New York. RESQ11.ZIP 30619 09-17-90 "Virus Rescue v1.1" >1989 Tacoma Software Systems; another front-end prgm for McAfee stuff. A definite yawner. ROID06.ZIP 149583 10-19-90 "Weird 'Virus Detection' Animation Program." >Contains large .FLI (flick) file. Animated parody of Virus Scanner in action. Download a .FLI viewer to see it [FLIVUE.ZIP 45k]. {DEL} SCAN7.ZIP SCAN76-C.ZIP 67622 04-11-91 "McAfee's Virus Scanner v76 (corrected)." SCANV80, SCANV82 SCAN78_.ZIP, SCAN78NO.ZIP, SCAN78TJ.ZIP, SCAN78.ZIP See HACK78.ZIP. SCANRS42.ZIP 19383 08-22-91 "Updated 10-11-89 SCANRES.EXE from McAfee." > Antique McAfee Virus Scanner (1989). SCANSHEL.ZIP 7623 04-02-91 "Small shell for running MacAfee's (sic) Scan." >Even CRS can spell his name wrong. I guess it's a yawner for them, too. SCANTL17.ZIP 175299 09-03-91 "SCANTOOL v1.7 is a shell that simplifies the use of McAfee's SCAN, Clean, etc. Evaluation copy." > Scan Tool 1991, Dirk Zender. Another front-end for McAfee stuff. SCANZIPS.ZIP 2441 01-03-91 "Scans directories for viruses in ZIP files." >I guess I'll unzip it and check it out because it seems awfully small, and I wonder whose scanning pgrm we are allowed to use.... Yes another decompresser and scanner for SCAN.EXE, not as comprehensive as AUTOSN32. SCAN_ASC.ZIP 5872 12-17-90 Removes all non-printable characters from a file. Redirectable and pipeable. Useful for checking for trojans, etc. >Another ASCII reader, by Dr. Bob of Minnesota. SECUR209.ZIP 20697 11-13-90 "SECURE V2.09 anti-virus/Tojan TSR BEST." SECUR224.ZIP, SECUR225.ZIP, SECUR226.ZIP SECUR227.ZIP "... SECURE is the most powerful virus and Trojan protection system available. DOS 5 Update..." SECUR228.ZIP SECUR229.ZIP > 1991, Mark Washburn, TSR. I don't completely understand it. Not fully tested. SENTRY.ZIP 30515 09-25-91 "A virus protection program." > Alejandro Abello or McAfee. A short-cut file comparer. Fast because it looks only in limited locations. Not tested for reliability. SENTRY02.ZIP 14020 7-11-89 "Sentry 2.0 Antiviral File CHKSUM'r. J McAffee" >This is an intriguing project, from McAfee himself, apparently. He wants $15 for SENTRY VERSION 2 and if you don't pay: "...you WILL have bad dreams and your karma will turn sour. Your girlfriend will leave you for the dweeb next door and the neighborhood children will ridicule you behind your back. You will begin loosing (sic) your hair prematurely. Your chances of an audit by the IRS will increase by two orders of magnitude. You will be seduced, in a moment of madness, into buying OS/2 and will convert all of your systems three days before IBM abandons the product." The copyright is circa 1988-1989, and appears to have been first presented about the time of the infamous McAfee blunder. Here is a summary of that event as reported in the PANDA SYSTEMS "V.I.R.U.S." book. "By mid-1988, the hype surrounding computer viruses had reached a fever pitch. New York's PC EXPO featured a panel discussion ... the last day of EXPO, John McAfee, president of InterPath corporation, was burning up telephone lines across the country with his latest and greatest idea: the formation of a computer virus industry association... A press release was already written... announcing the members and their remarkable 90 percent industry market share ... As often happens ... McAfee tripped over his own shoelaces. In calls to prospective members, he recited a list of those developers 'already in' the CVIA**... McAfee's story did not ring true. At least five major developers ... declined to participate, based in part on what appeared to be McAfee's deliberate misrepresentation. Ross Greenburg [MYTHS-3.ZIP], developer of ... Flu Shot ... stated ... 'I wouldn't call it a scam, but it sure as hell is one of the more unethical things I've witnessed.' ... The CVIA folks went ahead ... (and) ... continued with its claim of 90 percent market share of anti-virus products, an impossibility in the light of the ... nonparticipants ... FLU SHOT ... CHK4BOMB and BOMBSQAD ... Press releases from the CVIA flooded editors' and reporters' desks and scarcely a day went by that a John McAfee/CVIA quote did not appear somewhere in the media ..." [For more on the background of the Scare Period, see the book, "V.I.R.U.S. PROTECTION", by Pamela Kane.] O.K. Now for Sentry 2. It appears that McAfee tried some major anti-virus projects and did not succeed, so he came up with SENTRY, a shortcut approach, based on the "Positioning Rule." In a nutshell, his program is going to check for viruses in areas that he expects them to appear in order to make the program perform faster. This cutting corners approach essentially demands that the user must have faith that the protection software won't miss anything. For the time being I will not test this product, as I have other priorities. But briefly, here is (or was) McAfee's attitude on the other techniques: the "TSR approach has numerous weaknesses...The CHECKSUM approach (i.e. file comparison), on the other hand is very time consuming and awkward to implement. Both techniques are troublesome to install and execute." As turns it out, this antique was just as troublesome to install, and as I am not so sure what it would be doing to my system, I intend to forgoe playing with it for now. SFSHEL10.ZIP 140670 04-12-91 "SafteShell v1.0 For use of SCAN & CLEAN. Very easy to use, & good for system check from floppy." SHEZ64.ZIP 161499 09-30-91 "Major update to SHEZ. Expanded Dir. display, Keystroke record/playback, Virus scan all files including SFX files, Batch mode for SYSOP use, Volume Label support, Change compression method options, numerous other additions, and corrections. One of the most ..." > Shez the Compression Companion, Jim Derr, a zipper utility. Cumbersome, hesitant. Had to reboot to exit. SIEVE.ZIP 15624 01-26-90 "Sieve v 2 detects Jerusalem B." SIGS.ZIP 1930 10-16-91 "Central Point Software Virus Signatures, this file adds new virus signatures to CPC Virus Scanner programs." SSCRC.ZIP 14578 09-10-90 "Virus Buster - check on crc on all files." >This Antique failed to uncompress properly; the .DOC file contained many extended set characters (probably due to compression problem); also, it is recommended you run it once a month. I guess that means it's slow. No test. STEP110.ZIP 17362 10-22-89 "STEP13 v1.10 TSR pgm that intercepts BIOS interrupt 13h and displays a description of what the BIOS call is about to do along with a display of input parameters (drv #, track, sector, etc.)" >I installed it, tried formatting, writing to drive, etc. Writes and formats were performed -- STEP13 failed to intervene. 1987, by Mike Parker. Garbage. STOP1.ZIP 5877 07-15-89 "Antitrojan programme to stop disk access" > By Carey Nash. It's because of outdated efforts like these that I wrote HAWKBEAT. SUG-WORM.ZIP 3203 11-27-90 "Warning of Softguard-Related Worm! Read!" SUPSC30.ZIP 62823 09-19-91 " Superscan! v3.0 Virus scanner for BBS's" > SuperScan 3.0 by "Flamming Idiot". Claims to handle integrity checking for uploads, Portage, Michigan. Decompress and scan. SYSCHK1.ZIP 9428 11-28-89 "Checks COMMAND.COM, DOS, and BIOS for viruses." >Antique and limited file comparison program (1988 from Terratech) for the system files, COMMAND.COM, IO.SYS, MSDOS.SYS. {ARC} SYSCRC.ZIP 11656 09-10-90 "SysCRC v1.0; DOS system file anti-virus checker." >Like SYSCHK1 and NV3, it does a file comparison of system files, but in addition checks for BOOT sector changes. About 1988 from PussyCat Systems. In that period of time (1987-1989), all the software in this class, could only pussyfoot around when it came to the file comparing. {ARC} TB-TEST.ZIP 4040 07-30-91 "THUNDERBYTE Virus Protection Card, a test of the *BEST* protection today." > Review of a hardware card for Thunderbyte Scanner, by Jan Terpstra. TBS38619.ZIP 5206 01-30-91 "Prog anti virus version 1.9 for 80386 cpu." > Unzips to a single .COM file which, when executed, says data file not found. Untested TBSCAN20.ZIP TBSCAN23.ZIP TBSCAN26.ZIP "Thunderbytes virus scanner mem res version requires VIRUSSIG.ZIP" TBSCNX29.ZIP 59338 07-08-91 "TSR version of the Tbscan Virus scanner from Holland. V2.9" TBMOD640.ZIP 132021 08-09-91 " New Version (6.40) of TMODEM Transfer Protocol, it's not Compatible with any Prior Versions Which should be DELETED since there's a VIRUS Threat!!!!! Read 640.DOC for Further INFO!, this is a FAST Transfer Protocol which uses 64-CRC for Error Checking." > TMODEM 6.4 protocol update TBVIRSIG.ZIP 34551 07-30-91 "TBSCAN.DAT Virus signature file for the TBSCAN / TBSCANX Virus Scanners." > Also: VIRUSSIG.ZIP & VIURSSIU.ZIP. TRAPDISK.ZIP 6151 11-14-89 "Great Virus detection." >This is an attempt to improve on BOMBSQAD, very much in the style of BOMBSQAD. There are a number of items that disturb me about this QUICKIE improvement. 1. Even though it is FREEWARE, there is no name of the author, 2. the .COM file shows a creation date of 1983, 3. the .DOC file shows a creation date of 1986 4. it tries to improve on a "BOMBSQAD bug" regarding referencing to the drive. I never found BOMBSQAD to have such a bug. And when I tested TRAPDISK, it referred to my D: drive as C:, my C: drive as B: -- fix your own bug, guy! Outdated technique, anyway. TROJ2: A legal document concerning a 1988 placing of TROJAN on a BBS. (no longer in IDIR 316) TROJAN.ZIP 2745 09-10-90 "A TSR ->PREVENTING DISK ACCESS--Beeps" >Hard Disk Sentry, 1987 Andrew Fried, no documentation here, just a small COM file and ASM source, that appears to react to INT 13h. TROJAN2.ZIP 10375 04-23-91 "Tim Sullivan's Trojan software list." >A list of Trojans (from Toronto). Some names were uncommented (not listed as Trojans), like PROKEY which, in the commercial world, is an excellent keyboard redefiner (I've used it since 1984), so I can only suppose it and others like it were included as examples of programs that have been trojanized and uploaded to BBS's. So don't go deleting any of your files just because their names appear on the list. Also includes copy of BOMBSQAD. TROJM88.ZIP 1402 09-10-90 "List of TROJANS listed in Comp. Shopper 03/88." >Another one of the TROJAN lists. Again, valid software names are included here, like SIDEWAYS, and it's from 1988, so likely the trojanized versions have long since become extinct. I'd prefer details on the events. The individual who is transmitting this list says something about frustrating the trojan makers -- but lists won't do it. TROJWARN.ZIP (no longer in IDIR 316) >A warning from a BBS SYSOP (Scott Childress, Premier BBS, Knoxville, Tenn.) whose hard drive was savaged by BARWIND, a program with a .BAS extension that escaped detection by BOMBSQAD, and evaded salvage by NORTON Format Recover. It appears it may have done its work while being installed with GW-BASIC. (You can find the file in HAWKBT11.ZIP, my own TSR effort.) TSAFE.ZIP 131043 05-28-91 "GERMAN LANG. VER OF THUNDERBYTE VIRUS SCANNER." TSRTXT.ZIP 8284 02-01-90 "TEXT Everything about viruses Gibson Rsch." >HUH? This has nothing to do with viruses. It is as it is entitled: "The History & Technology of TSR Terminate and Stay Resident Software" by Steve Gibson, InfoWorld Tech Talk Columnist and President of Gibson Research Corp. It is a very readable and informative novice piece on TSRs, but in the wrong section. TWELVE.ZIP 6580 06-05-90 "A small file about trojans." >No, it's a text file about the Twelve Tricks Trojan. See 12TRICKS.ZIP. UNVI1601.ZIP 83618 05-14-91 "French anti virus prog version ... for the detection of 220 viruses." >My French is weak, but I thought it said it scans for 330 viruses, not 220 as the CRS description says; also it scans the memory. Nothing unique here; its signature list must be in the EXE file. This scanner quickly and attractively did an excellent job. I still have to test it and other major scanners against some dummy executable files containing virus signatures. I really liked the way it displayed the tree down the lefthand side of the screen, and each file on the right hand side as it scanned. A professional effort. See also VANADEMO. UNZIPIT.ZIP 9472 10-04-90 "Will help you many times over with unzipping files from disk to disk or HD. Unzips them and scans for viruses. You will need a version of SCAN and a recent version of PKUNZIP." >Another unzip and SCAN. See AUTOSN32.ZIP and others. UPCHKTD.ZIP 53880 06-16-91 "UPChek, Test Drive Version, for users and sysops alike, test all files uploaded (for sysops) and downloaded (for users) for viruses and insert comments." > Front end for scanners. Untested. V3.ZIP 15737 12-17-90 "Korean made virus scan/defeat program. But, manual is written in Korean." > Gives a few English instructions if you run V3 without parameters. Small signature list, did not scan entire drive. Curiosity value only. V80CLEAN.ZIP (See CLEAN80) V80SCAN.ZIP (See SCAN80) VALIDAT.ZIP 3592 01-24-91 "File authentication program. Checks CRC codes." > McAfee's Validation program, churns out CRC values for an executable file. Use VALIDATE.ZIP to compare with values. VALIDATE.ZIP 5541 06-27-91 "List of validation codes for McAfee Associates and other Shareware programs. Direct from McAfee." > The CRC validation codes for comparison purposes for McAfee's VALIDATE. It not only authenticates McAfee Associates' programs, its helps impress upon your mind that the McAfee Dynasty and Association is your Big Brother. VANADEMO.ZIP 142362 01-11-91 "French prog of virus scanning demo version but with many functionalities." > A demo of the French UNVIRUS pgm, attractive and fast. An English-language version would be well-received. See also, UNVI1601. VAUBA211.ZIP 28829 12-29-90 "Programme francais de securite anti-virus version 2.11" > A package of French utilities, including some such as a screen blanker. (English language version, please.) OCT 7 1990. VAX-DOX.ZIP 5603 06-01-91 "Vaxine Dox." > A single file VAXINE.DOX, documentations for a game, VAXINE. Wrong section, The game is associated with biology, DNA, etc. VAXTRN.ZIP 4703 06-01-91 "Vaxine Trainer." > Wrong section! A trainer for the game VAXINE. Nothing to do with viruses. VB_110.ZIP 27648 12-19-89 Israeli VirusBuster program v1.10" > Antique Virus Scanner by Uzi Apple and Yuval Tal. Useless. See their later effort in association with McAfee -- VIRCDE12. VC100B.ZIP 58295 05-27-91 "Virus Central Shell for VirusScan & CleanUp." > More scan and clean support for McAfee stuff, by Alejandro Abello, "A High Flying Hardlander", 1990. Untested. VC140CGA.ZIP 86851 12-06-90 "Virus Central v1,40: shell for McAfee Associate's VirusScan/Cleanup utilities; menu-driven graphical interface w/mouse support & builtin screen saver; CGA version." VC200EGA.ZIP VC250EGA.ZIP VC250LTE.ZIP VC300EGA.ZIP VC300LTE.ZIP > See VC100B VCHECK10.ZIP 12372 09-16-88 "ALCH Check your system for virus infestation." > Alchemy Minworks, Markham, Ontario. File comparer. Define your own update file, for files to be compared. Cumbersome and slow. VIRCHK21.ZIP 89683 08-28-91 "Virus Check 2.1 Runs SCAN on set days." VCHK203.ZIP 32782 07-31-91 "Viruschk v2.03: shell for McAfee's SCAN pgm used on all USMC [(U.S. Marine Corp)] systems; it also displays the warning screen mandated by USMC security regulations; if a virus condition is found, it will lock up the user's system and with a loud tone and unmistakable screen, alert them to the infected condition." VCHK21.ZIP "...Now includes the "enforcer" program for Banyan Vines networks." VCOPY77.ZIP 41029 04-30-91 "McAfee's file copy virus detection utility, v7.7, works like XCOPY." > VCOPY will scan when copying files. More window dressing. Just scan your drive or directory before copying. VDETECT.ZIP 19066 01-23-89 "Virus Detector v1.1; tells files changed, limited." >By Tim O'brien 1988. Another File Comparison program. It claims to be very fast because of its assembly code. It was not; it didn't even check the boot sector, FAT, or available free space. VIKIT404.ZIP 99735 09-29-90 "The Virus Kit v4.04 ITALIAN virus checker DOCs are in Italian." > Mauro Bollini, 1990, Public Domain. Package of files in Italian. This could be the infamous Italian ripoff of Fridrik Skulason's FPROT, since the signature file is in Skulason's style. VIR0nnnn.ZIP [Virus newsletters, where nnnn= 4001 - 4004, 4015 - 4044, 4046 - 4068 ] VIRALERT.TXT 827 06-11-91 "Notice to all computer users - NEW Virus [15xx] has been detected in Toronto." VIRCDE12.ZIP 76928 05-19-91 "ViruCide v1.2e. Its a great virus scanner!" > By Parsons Technology, 1990, McAfee Associates, by Yuval Tal and Uzi Apple. Neat straight-forward update of UNVIRUS. Also VB_110. VIRESSAY.ZIP 17939 04-19-91 "An essay on computer viruses, done as a computer science project." > By Ilya Shlyakhter in D-Block. Virus primer. VIREX16.ZIP 62620 07-10-91 "Latest virus scanner from..." > VIREX v1.6 July 1991, Ross Greenburg's scanner, detects 500+ viruses. Untested. VIRL-nnn.ZIP [Virus-L digests, nnn = 105 - 107, 109 - 113, 115 - 120, (216 - 225are located in file LOG8910D.ZIP), 241] VIRLnnn.ZIP [Virus-L digests, nnn = 128, 145, 150 ] VIROTECT.ZIP 74996 07-06-91 "Virotect Professional virus scanning module. This is the scanning module which scans hundreds of known and unknown virus's. Works Great!" > VIROTECT version 1. They call signatures: "watermarks". Demo. Scans only drive A. VIRPRES.ZIP 219831 02-04-91 "VGA Presentation on Viruses." > Slow, irritating, Mickey Mouse tutorial by John McAfee's bunch, for patient novices only. VIRSnnnn.ZIP [Virus-L digests, nnn = 1104, 3048 - 3050, 3062 - 3064, 3066 - 3069, 3071 - 3072, 3074 - 3089, 3093 - 3101, 3103 - 3109, 3121 - 3128 ] VIRSCAN.ZIP 35537 08-22-91 " IBM's program to check for program virus." > IBM virus scanning program from APR 1990. See IBMSCAN1. VIRSIM.ZIP 27709 08-03-91 "Virus simulation program. Will simulate viruses on floppy and/or in memory. From the Ibm bbs. USE WITH CAUTION !!" VIRSIM10.ZIP VIRSIM11.ZIP > By Rosenthal Engineering, 1991, California. Creates DUMMYVIR.COM and DUMMYVIR.EXE, or messes up your boot sector only on the A: drive and ONLY WITH YOUR PERMISSION so that you can test your virus scanner. ( it talks to you throughout the procedure). I tested 1 virus scanner, Virucide (VIRCDE12.ZIP) which failed to detect the viruses. This is not a knock on Virucide, since the problem with dummy virus files is that their incorporated signatures may not be the signatures that all scanning authors' use to test for a virus. Good idea, but of limited value. I'll find out later whose scanner detects these generated dummies. Maybe the updated simulators test for other author's viruses -- I'll check it out later. VIRSRCH.ZIP 37889 02-02-91 "Scan, locate and destroy viruses. Immunize your computer against future virus attacks. From T.C.P. Cechmar Computer Products." VIRUS101.ZIP 28601 05-16-90 "Usenet tutorial on viruses incl." > Four excellent tutorials on viruses from George Woodside. (MARCH 1989). VIRUSCAN.ZIP 22704 09-05-90 "Scans disk for 19 virii." > Old version (1989) of McAfee's SCAN, plus meaningless documentation on 1704 virus, McAfee promo. Avoid it. VIRUSCAT.ZIP 5248 06-11-89 "Virus Catalogue: Aim, Scope, Format of each entry and the index. From USENET comp. virus." > TEXT. 1989. A computer virus catalogue from Hamburg. Of no value. VIRUSD.ZIP 26972 09-22-89 "IBM research paper discussing virii." > See IBMPAPER VIRUSES 2560 11-09-89 "Books for Sale from Publisher." > Two books for sale from McLelland and Stewart in Toronto, including a promo for a McAfee book which repeats a quote considered ridiculous by critics which is that there are now over 300,000 viruses infecting leading industrial corporations. See MYTHS-3.ZIP for Greenburg's comments on this now adjusted number of infections. The 2nd book is a computer handbook. VIRUSFIX.ZIP 12253 01-19-91 "Fix for RABID virus (12-03-90 DSZ Release)." > Antique scanner from 1990, scans only for RABID (Rabid Avenger?). DEC 1990. Useless. VIRUSINF.ZIP 3610 10-08-89 "Virus info from Nat'l Bureau of Std's BBS." > VIRUSINF.DOC --> Brief comments on DataCrime II. VIRUSKIT.ZIP 201216 12-15-89 "The Virus Self-Defense Kit: tutorial and pgms National Computer Security Association." >From the National Computer Security Association: Colourful, general, virus information. ANTI-VIR.ZIP assumed that some anti-virus programs were included, which they were not, so they could not be installed as stated. VIRUSKIT.ZIP contained the installible programs (BOMBSQAD, DBACK, DELOUSE, FPHD, NEW, RT0, SCAN version 50, ST0, TRAPDISK, VALIDATE, WPHD.) The menu program went into an automatic virus scan routine which hung my XT. Decent general data, but dated!. The opening screen presentation was long and unnecessary. This material is associated with the CVIA** (See quote at end). VIRUSSIG.ZIP 34194 07-08-91 "Signature Databse for TBSCAN, TBSCANX & HTSCAN virus scannners. Dated June 30 91." > Also TBVIRSIG.ZIP & VIURSSIU.ZIP. VIRUSTST.ZIP 14171 06-19-90 "System of batch files and programs." >Contains a few small batch enhancers for virus testing and setting environment variables. Of no value, unless you're in love with batch stuff. See CKOT.ZIP VIRUSUM.ZIP See VSUMnnnn.ZIP (the nnnn's are the version numbers) VIRUSVAC.ZIP 16249 08-20-89 "Vacine for SUMSDOS strain of Israeli virus" > Untested. VIRUZ.ZIP 14105 05-17-91 "Virus Program." > Dec 1989. VIR ZIP. Zip file virus checker. Eric R. Bazerghi. Another decompress & scan. VIRX12.ZIP 51050 04-12-91 "Virex Anti-Virus Scanning Program. Able to detect over 300 virus bugs. Very fast!!" VIRX14.ZIP 58331 05-24-91 "Microcom's Virus Scanner v1.4 5 files." VIRX15.ZIP VIRX16.ZIP 62827 07-05-91 "... Bugfix from recent v1.5. Scans only. Registration brings virus eradication program." VIRX17.ZIP 64493 08-07-91 " VIRx v1.7 is the Virex-PC FREEWARE virus scanner. Fully functional, including over 540 virus strings (sic). One of the fastest and most comprehensive scanners available, catching over 650 viruses." VIRX18.ZIP 66290 10-08-91 "... Detects 21 New Viruses." VIRZIP12.ZIP VIRZIP14.ZIP 17204 05-08-91 "Shell for McAfee's SCAN on ZIP files v1.4." > See VIRUZ.ZIP VIURSSIU.ZIP 34194 07-21-91 "Information file for TBSCAN. 3 files new." > Also VIRUSSIG and TBVIRSIG) VRS03V19.EXE 19456 07-29-89 "A virus checker, checks against 19 diff virus." > Contains just an .EXE file, a self-extraction of SCAN, VIRUSCAN.DOC -- old McAfee viruscan version (1989). Useless. VSCAN149.ZIP 199700 01-04-91 "Virus scanner v1.49 from BLUE." >SEE IBMSCAN1.ZIP VSHELL12.ZIP 36534 02-11-91 "Deluxe shell for McAfee's Scan/Clean and is a good interface for VIRLIST.TXT." VSHL140.ZIP VSHLD77.ZIP VSHLD80.ZIP 73497 06-26-91 "VSHIELD Infection Prevention TSR Prog. Monitors program loads on ALL drives, prevents known viruses from becoming resident or spreading on systems. Also Prevents Boot Sector infections. From McAfee ... 8 files new." VSHLD80B.ZIP VSHLD82.ZIP > VSHIELD. Goretzky TSR. Untested. VSTOP254.ZIP 31285 01-12-90 "VIRSTOP: TSR, prevents viral infections. Able to prevent infections from all currently known viruses detectable by McAfee's VIRUSCAN Will be kept current w/new versns." VSTOP300.ZIP VSTOP400.ZIP > Junk. VSUM9103.ZIP 152864 04-07-91 "Virus Information Summary Sheet by Patricia Hoffman." VSUM9104.ZIP VSUM9105.ZIP VSUMX106.ZIP "... Latest Virus summary in new Hypertext format..." VSUMX107.ZIP 330650 07-16-91 " Patricia Hoffman's Virus Summary now in EXE format Hypertext crossed referenced this is the July '91 release not for the weak of heart or otherwise paranoid!!!" >Large detailed Virus Information Summary List by Patricia Hoffman giving history and characteristics of many viruses. Excellent. See also VIRUSUM. VTAC48.ZIP 23789 11-29-90 "VTAC v4.8: virus security program which will not allow alteration of programs/system files system-level disk alterations, or formatting of harddisks; supports errorlevels for use in batch files." > PC System Security Program, 1990, by Randolph Beck. A TSR a step up from BOMBSQAD. Good ideas here. VTEC12.ZIP 92263 05-02-91 "Front End program used with McAfee's SCAN, CLEAN and VALIDATE programs." VTEC16A.ZIP VTEC18A.ZIP VTEC20.ZIP VTEC25A.ZIP VTEC26.ZIP VTEC30A.ZIP > Virus Terminus, Susan Calise. Decompress & Scan utility. VXRF0791.ZIP 12686 08-07-91 "Virus effective length cross-reference list." > Text file by Paul Ferguson July 1991, Virus name, size alias, type. Less comprehensive than Patricia Hoffman's VSUM or Clough & Partners' PCVI305B databases. Of no particular use. WARNSCAN.ZIP 3124 05-21-91 "WARNING concerning hacked version of McAfee's virus scanner program -- SCANV78.ZIP." WCV201.ZIP 12598 06-03-91 "Small utility makes 'bait' files for virus security and testing." > Write Com v. 2.01, 1991, David Grant. To aid in capturing a pure virus. A variation of the goat theory. Of no use. WINVIR.ZIP 2910 01-14-91 "Information on some viruses found in Windows applications." > DEC 1990 report to Windows users about a virus in WINCHK 1.0. WORMCHEK.ZIP 39503 09-10-90 "A worm report and auto-check batch file." > Batch file to check for worms in COMMAND.COM. 1988. Plus other utilities. Primitive, ancient, utilities, with filters, etc. Junk. YUPIPSS.ZIP 44558 01-07-91 "AntiVirus Programs by DURLAN Yugoslavija." v 1.0. > PIPSS, Version 1 by Martin Vladic, 1990. "Let me be your bodyguard." PIPSS by Boris Mazic, 1990. Untested. ZIPVCHKB.ZIP 43826 07-02-91 " Great EXTENSIVE ZIP File VIRUS Checker! From PHANTASM BBS version 1.02. Checks for ZIP's in Zip's, etc and scans for viruses! Great Util for SYSOP's to run against your BBS dirs. 1.02 fixes a bug if error unzipping file." > Phantasm ZIP file virus checker, "writtem" by Keith Luken. (I wonder if he spelled his name wrong, too.) Another decompress and scan. {ARC} ZVTEST10.ZIP 119111 12-09-89 "Automatically test ZIP files for damage & virus McAfee's SCAN and Katz' PKZIP/PKUNZIP required for both users & PCBoard (other BBS ?) sysops." > Dec 1989. Decompress & scan. Primitive. Michael Cocke. {ARC} ZZAP56A.ZIP 69202 11-05-90 " ZZAP Archive Checker Uses SCAN To Check Archives For Viruses." > Pascal source. QFIX 1.0 1990, by Ross Neilson Wentworth. Processes ZAP files. Converts between archiving formats. Wrong section. {ARC} =========================================================================== *Reference Note: From the Book, "V.I.R.U.S. PROTECTION", subheading "Vital Information Resources Under Siege", by Pamela Kane. Included with the book were the Dr. Panda Utilities, programmed by Andy Hopkins (author of CHK4BOMB and BOMBSQAD. One Utility, LABTEST, checks executable files for text strings, as well as potentially dangerous interrupts -- excellent! ** CVIA: Computer Virus Industry Association: "If the Computer Virus Industry Association or any other trade group truly wants to help companies prevent virus attacks, they should find solutions, not exploit fears."--Rachel Parker, InfoWorld.