[comp.virus] Problems removing Azusa

frisk@rhi.hi.is (Fridrik Skulason) (06/15/91)

padgett%tccslr.dnet@mmc.com (A. Padgett Peterson) writes:
>From:    dwe29248@uxa.cso.uiuc.edu (Derek William Ebdon)
>One thing that Mr. Doss forgot to mention is that although Central
>Point Anti-Virus v1.0 can easily romove the Asuza virus from a floppy,
>it cannot remove the virus from a hard drive.  The only way to
>disinfect a hard drive is to redo the low level format because the
>virus infects the boot sector and the dos partition.  A high level
>format will not remove the virus, nor will simply removing the dos
>partition with the fdisk program.

Well, this is of course not correct - a format is never necessary to
get rid of a virus - boot sector or otherwise.  However, Azusa is
rather problematic, as it does not store the original PBR anywhere -
it simply replaces it.  (It is easy to remove Azusa from diskettes)

Suggested solutions:  1) Use NU to zero out the PBR, then use
			 NDD to rebuild it.

		      2) Use a disinfection program which can replace
			 the PBR with a "standard" PBR - such programs
			 exist.

- -frisk