[comp.virus] Virus detection via crcs

john.blakeney@f1701.n713.z3.fido.oz.au (John Blakeney) (05/22/91)

crd check is only effective way of looking for viral activity unless
search strings are known for the viruses listed in letters. trhere is
no known virus(to my knowledge which does not alter crc check. the
only way to dodge this check would be to alter files so that there is
no change in crc. there has been a rumour of a virus which was written
in a command.com file and the alteration of the crc was only by one
bit! even in this case the truncating of the command com files to
accomodate the virus was unsuccessful in hiding it.  There havew even
been rumours ofscan being infected because another viral check found a
string which resembled that of a known virus.(sorry about lousy
typing!)

- --- TMail v1.21j
 * Origin: Prophet BBS (3:713/1701)