[comp.virus] Compucilina

eldar@lomi.spb.su (Eldar A. Musaev) (02/28/91)

Adding to the note of Fridrik Skulason (v.4 i.31) This 'compucilina'
will not prevent infection either you'll boot from floppy or hard
disk. Most of the resident viruses infect a victim before execution at
int 21/4B as a simple file which can be modified (read: infected), and
only after that the victim (and compucilina) would get a control and
found many problems. I beleive that compucilina could restore the
victim in some cases, but not in ALL cases. E.g. the virus can be so
purely written, that it simply spoils file sometimes instead of
infecting it.

And how does compucilina fight with spawning (in terms of Patricia
Hoffman) viruses ? These viruses does not modify the exe-file, but
make a COM-twin of the file with viral code.  If you execute such
infected program, MS-DOS loads COM-file.  It does the viral work and
after that loads and execute the host program, which cannot determine
any traces of the virus in itself.

At the end, such a trick is well-known. I know at least 3 analogs of
compucilina in the SU with the first one dated at least at 1989.

Sorry, but I'm tired of commercial advertisments here in the SU, maybe
let us a little rest ?

Eldar A. Musaev, Ph.D., Researcher,          eldar@lomi.spb.su
Mathematical Institute of Academy of Sciences, Leningrad, USSR