[comp.virus] 639k, detection

RADAI1@HBUNOS.BITNET (Y. Radai) (07/30/90)

  Just a couple of minor comments on Padgett Peterson's posting.  He
writes:

>Though of course it is feasible, I have not yet seen
>a virus that just uses 1k.

There is at least one PC virus which uses only 1K of high RAM: the
Merritt/Alameda/Yale virus.

>simple checksum
>analysis of existing programs is adequate so long as the algorithm used is
>unknown.

Maybe we mean different things by "algorithm", but as far as I'm con-
cerned, the algorithm can be known as long as the checksums depend on
an unknown user-dependent key.

                                     Y. Radai
                                     Hebrew Univ. of Jerusalem, Israel
                                     RADAI1@HBUNOS.BITNET
                                     RADAI@HUJIVMS.BITNET