Path: utzoo!utgpu!news-server.csri.toronto.edu!rpi!think.com!zaphod.mps.ohio-state.edu!cis.ohio-state.edu!ucbvax!IFI.UIO.NO!larserio From: larserio@IFI.UIO.NO (LarsErikOsterud) Newsgroups: comp.sys.atari.st Subject: Protect6 - New version !! Message-ID: Date: 30 May 91 15:09:44 GMT Sender: daemon@ucbvax.BERKELEY.EDU Reply-To: larserio@ifi.uio.no Lines: 24 Protect6 - The resident bootsector/linkvirus detect/kill program """""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" Well... Uhhh.... Hmmm... OK, so the first version of Protect6 didn't stop all the link- viruses :-( Because of some strange features in the GEMDOS it is possible to WRITE data to a file that i OPENed as READ ONLY. This should give an error from GEMDOS, but it doesn't. Some link- viruses opens the program file from READ ONLY and then use WRITE. (does Atari Corp have a comment on why this is possible !!!????) As the first version of Protect6 checked for OPENing of a program file for READ & WRITE or WRITE ONLY these viruses get passed it. Well, this new version of Protect6 (check your date) uses a completly different way of checking things. I also removed the XBRA stuff. Why? Well, any virus could use the XBRA stuff to un-hook Protect6 from the OS-vectors and disable Protect6 ! Lars-Erik / ABK-BBS +47 2132659 / ____ ______ ________________________ Osterud / larserio@ifi.uio.no / /___ / The norwegian ST __________/ ______________________/ ____/ / Klubben, user association