Path: utzoo!utgpu!news-server.csri.toronto.edu!cs.utexas.edu!sun-barr!lll-winken!iggy.GW.Vitalink.COM!widener!netnews.upenn.edu!vax1.cc.lehigh.edu!cert.sei.cmu.edu!krvw From: frisk@rhi.hi.is (Fridrik Skulason) Newsgroups: comp.virus Subject: Re: Scanning infected files (PC) Message-ID: <0010.9106201437.AA20289@ubu.cert.sei.cmu.edu> Date: 19 Jun 91 08:26:44 GMT Sender: Virus Discussion List Lines: 7 Approved: krvw@sei.cmu.edu >Good question, but: wouldn't it be possible for the stealthy virus to >trap the sector I/O and "fix" it to also hide its tracks? Not only possible - it has already been done. At least one virus, simply known as INT13 does just this. - -frisk