[comp.virus] Replies to questions about INNOC

MMCCUNE@sctnve.BITNET (03/15/91)

 I have received numerous questions and comments about my program
 INNOC.COM. Rather than answering the same questions several times, I
 will answer them here:

 HOW DOES IT WORK? All boot viruses look for hex strings in the boot
 sectors to determine if the disk is already infected. INNOC simply
 puts several of these strings in the boot sector so that the virus
 thinks the boot sector is already infected. The current version of
 INNOC inoculates against the Stoned, Brain, Ashar and the Ping_Pong
 viruses.

 WHY DID YOU SPELL IT WRONG? I added the extra "n" to distinguish it
 from several other products with similar names (unfortunately I also
 misspelled it in the docs as INNOCULATE.)

 I RAN INNOC ON AN INFECTED DISKETTE AND SCAN SAYS IT IS STILL INFECT-
 ED? INNOC disables the virus but doesn't remove it. The virus will
 still trigger SCAN and F-PROT, although the virus will no longer
 infect. If this is a problem, run CLEAN or F-DISINF (F-PROT) on the
 diskette then run INNOC on the diskette again.

 WHAT IS NEXT? The Joshi or Disk Killer can be added to INNOC without
 changing it's effectiveness against the other viruses. I will proba-
 bly make these separate programs, though. Any suggestions for viruses
 to write inoculation programs for? I have several boot infectors
 (Ashar, Brain, Disk Killer, EDV, Joshi, Mardi Brothers, Microbes,
 Music Bug, Stoned, Stoned II and Yale.) If anybody wants another
 virus inoculator, I will have to get a working copy of the virus.

 ANY OTHER QUESTIONS? Leave me a note on Virus-L or at MMCCUNE@SCTNVE
 on BITNET.  Mike McCune...<MM>.