[comp.virus] os/2 question

IA96@PACE.BITNET (IA96000) (08/02/89)

does anyone know if any of the major viruses can pass to other
files when running under (in) the dos compatibility box of
os/2 extended edition?

IN other words, the systems boots up under os/2, you enter the
dos box and start to execute dos programs.

i would think it would not be able to pass, but i am open to
comments and conversation on this matter.

kelly@uts.amdahl.com (Kelly Goen) (08/03/89)

none of the com infectors I think would presently pass and none of the exe infe
ctors at present for the strains that homebase has gotten samples of could....b
ut exe header info for dos , windows and os2 is in essence somewhat the same(i.
e. exe hdrs for windows and os2 contain extensions to the regular format...) if
 the exe file from dos will run unchanged in the compatibility box then I think
 you may indeed have a possibility of infection... however os-2 executable woul
d tend to have selective parts of their exe header mashed...ones that I would t
hink would represent a real possibility of infection would be the improved stra
ins of the jerusalem virus(the strains that infects exe hdrs correctly) and oth
er exe infectors that are reasonable well behaved...however the subject of tran
sport viruses has come up before in conversations between john and myself and I
 think at least that it represents a real possibility...(also note that lacking
 a os-2 system at this time I am essentia!
lly winging it...I did however tak
e a look at the various header formats and various exe infectors that homebase
folks have provided disassemblies of in answering in this fashion). If any of t
he os-2 folks have comments negative or positive out there e-mail me and I will
 summarize to the net on this.I am also personally looking into this with respe
ct to 386, Interactives UNIX 5.3 and their DOS under UNIX Option!!
                        cheers
                        kelly

disclaimer: neither AMDAHL Corp. nor ONSITE Consulting take any responsibility
nor  make any warranties for what I say... it is totally and completely the res
ponsibility of Cybernetic Systems Specialists Inc. and myself...
flames>>/dev/nul