












	ͻ
	                            
	    C E R E B R O   2.5a    
	                            
	   ANTI-VIRUS  SOFTWARE     
	   SHAREWARE   MANUAL       
	ͼ


























  Programmed by Clyde Meli, B.Sc.
 Cerebro is shareware, and is copyrighted.
 This documentation and all the files in the archive are copyrighted.
 The entire archive may be freely copied for evaluation purposes.

(C) Clyde Meli, B.Sc. 1991-1996.

  P.O Box 51, Msida, Malta.
  E-mail address for anything related to Cerebro: bx413@freenet.uchsc.edu

  Last Update on 25th May 1996.
  This document changes with each version so it is recommended that
  you read it again since there might be some changes you should
  be aware of.

  Please note: The registration fee for Cerebro has gone up from the
  previous versions.










CONTENTS



CHAPTER 1 - Cerebro and How To Use It.


1.1 What Is a Computer Virus?
1.2 What Is Cerebro?
1.3 Why Use Cerebro At All? If I Use It, Why Should I Register?
1.4 How Do I Use Cerebro?

CHAPTER 2 - Registration Benefits.


2.1 How Do I Register?
2.2 Why Should I Register?
2.3 Archive Contents.

CHAPTER 3 - What Viruses Does It Detect?


3.1 Virus List.
3.2 Virus Naming.
3.3 Virus Removal.
3.4 False Positives.
3.5 Variant Checking.
3.6 Memory Deactivation.

CHAPTER 4 - Error Codes.


4.1 Error Codes.

CHAPTER 5 - New Features.



5.1 Summary of New Features in Previous Versions.
5.2 New Features In The Current Version.
5.3 Malta Wildlist.
5.4 The Future of Cerebro.
5.5 Other Utilities by Clyde Meli.


---------------------------------------
CHAPTER 1 - Cerebro and How To Use It.


1.1 What Is a Computer Virus?

A Computer Virus is a security threat to the functionality of computer
systems. It may cause unwanted alterations of programs and data, and
it may result in their being completely lost.
The definition which was originally given for the Computer Virus
(or simply Virus) by Dr. Fred Cohen (the first researcher on viruses) is
the following:

  a program that can "infect" other programs by modifying them to
  include a possibly evolved copy of itself.

It is not required for it to perform malicious actions to be considered as
a virus. Most viruses, however, are malicious and this has given rise
to the denomination malware (malicious software).

Currently, Dr. Alan Solomon & Vesselin Bontchev are using a new term
'Real Computer Virus' which in effect is much closer to what people
have in mind when 'computer viruses' get mentioned: unwanted software
which, without the user's permission, involves itself in various
activities such as spreading itself by altering programs and possibly
damaging data etc. The number of computer viruses in existence today
has increased to around 6000 according to information supplied by
various sources including the F-Prot Bulletins.

A virus usually includes a potentially destructive portion, known as
a payload. This can take the form of a "time-bomb" (on December 25,
display a message), a "logic-bomb" (when a disk write is performed,
it corrupts the disk) or any other action which the virus writer can
design. This variety of payloads confuses some people when they try to
understand the notion of a virus. The term "virus", IBM antivirus
researchers Steve White and David Chess note in a report, is incorrectly
used by some to refer to anything undesirable that may occur to a computer.

Viruses can be split into a number of categories including:
boot sector viruses, companion viruses, file viruses and link viruses.
The last two terms are NOT the same.

A boot sector virus modifies either the DOS boot sector (e.g. Stoned
on floppy disks) or the MBR (Master Boot Record - also known as the
Partition Sector) depending on the virus and the disk. For instance
Stoned.No_INT.A which is very common locally is a DOS boot infector
when infecting floppies and an MBR infector when infecting hard disks.
A PC gets infected when an attempt is made to boot from an infected disk
(it need not be a boot disk). This may be accidental or on purpose.
Increasingly, dropper programs are being used to spread boot viruses.
Their only purpose is to infect PC's and start the infection.
The original bootstrap sector is usually stored somewhere else.
DOS boot infections may be removed manually usually using the
DOS SYS command, while MBR infections can sometimes be removed using
FDISK with an undocumented parameter.

WARNING: The improper use of FDISK may destroy data e.g. with
Stoned.Monkey. It is generally recommended that you contact a
specialist for advice instead of using this command.

IF YOU BOOT FROM A CLEAN WRITE-PROTECTED FLOPPY AND WHEN YOU CHANGE
TO DRIVE C: YOU CANNOT SEE YOUR FILES ON YOUR HARD DISK, DO *NOT* 
USE FDISK.

Companion Viruses exploit the DOS loophole that if two programs exist
with the same name, one is a COM file and the other is an EXE file, then
DOS will execute the COM file and not the EXE file. A companion virus,
e.g. Power Pump, creates a COM file with the same name as the EXE file it
'infects', storing its own code in the COM file. This file will be executed
instead of the other file e.g. WS.COM instead of WS.EXE. The EXE file does
not change at all, and integrity checkers will not detect anything.
The virus code in turn will load and execute the EXE file.
Removal of such viruses involves simply deleting the virus COM files which
usually have the DOS hidden attribute.
HINT: You can see these hidden files yourself by typing DIR /ah under
DOS 5 or later.

File Viruses modify the contents of COM and/or EXE files. They usually
append themselves to the end, leaving the carrier program intact.
The viral code is executed before the host program since the execution
flow has been diverted for this purpose. Some viruses prepend themselves
in front of the file, some both prepend and append themselves while
some insert themselves in the middle of the file. A example of an
appending virus is Casino.B which reached epidemic proportions locally
some years ago.

Link viruses work by linking the first cluster pointer of the directory
entry of every executable file to a single cluster which contains
virus code. The original starting cluster number is saved in an unused
part of the directory entry. For example, DIR-II which was recently
remarkably widespread.

A Trojan Horse is any program written to do things that the user of
the program did not intend to do. For example, a program which simulates
the logon sequence for a network, and rather than logging on, just
makes a copy of the user's password and user id in a file. It steals
the password so that the author of the Horse may log on as the user (this
was not intended by the user). Typically, however most trojan horses only
erase hard disks irrecoverably. In particular if you find a file which is
a trojan, do not run it.

Finally, please do not run *any* software before scanning it WITH MORE THAN
ONE SCANNER. Scan it with Cerebro and with at least another virus scanner.
Scanning is a fast process today thanks to proprietary algorithms which are
very fast, and does not take much time. Don't trust any software, whether
it is on a cover disk, from a BBS or commercial software. By don't trust
I mean test the software by scanning it before you use it, and even if
you use it, it's better to test it on an isolated machine. There have been
cases of commercial software arriving infected e.g. VGA driver disks from
Taiwan were infected with the Form.A virus, and cases of computers arriving
from the manufacturers infected with viruses or carrying harmful trojans (a
recent case occurred in Australia). Even though this has not yet happened
in your country, do not presume that it may not one day.


1.2 What is Cerebro?

Cerebro is primarily a virus scanner for DOS, in other words it is able
to examine executable files and determine whether they are infected 
by known viruses.
It may remove some viruses as listed later in this documentation. If a
virus cannot be removed, it may be renamed to avoid execution.

Cerebro can detect many of the large numbers of viruses which exist
today - from boot sector viruses like Stoned.No_INT.A to multipartite
viruses like Junkie.

Cerebro is able to recognize unknown variants.  It is even now
possible for Cerebro to detect some of these before having analysed them.
For example suppose a file is infected with a new variant of Casino. This
might be detected by Cerebro as a 'NEW VARIANT of Casino.B'.
In such a case this is a completely new virus variant and you are asked to
contact the author so that the new sample may be analysed for the
benefit of everyone else.

Cerebro works on networks as well as under Windows. It is able to
work with compressed drives (e.g. DoubleSpace/DriveSpace under DOS 6.2x
etc) correctly. This was a feature of previous versions from 2.0 onwards
also.  Cerebro performs a quick memory scan which can be bypassed if
wanted at start-up.
It also performs DOS memory deactivation, currently only on the
Stoned.No_INT virus subfamily.
In future this will possibly be extended to include deactivation of other
viruses.

Cerebro is around 600% faster from version 2.2. This is due to
new polyscanning algorithms which have been developed. These
in fact can search a file for 1000 viruses in the same time as
it takes to search for 30 viruses. This will ensure the ability
of Cerebro to scan for more variants and viruses in the future
as well as to incorporate detection of other polymorphic viruses.

Cerebro is the FIRST MALTESE VIRUS SCANNER to incorporate
VARIANT CHECKING, MEMORY DEACTIVATION AND POLYSCANNING
ALGORITHMS. How do you tell if a scanner utilises Polyscanning
algorithms? If the scanner is extremely fast, it probably does.
Otherwise it most probably does not.
Cerebro can clean some viruses which are very common in Malta (as
listed in the VIRUSES.TXT file).
(This is available in the registered version only)
Cerebro is the fastest Maltese virus scanner and it is close to
the very best of foreign scanners with regards to scanning speed.

* SPEED
* A Windows 3.1 directory is scanned by Cerebro in around 1.26 seconds
on a 486DX2, to give you an idea of its speed.

* LONG FILENAMES
* Cerebro is partially Windows 95/DOS 7-aware, today.
This means Cerebro already incorporates partial support for long filenames.
A new scanning system to eliminate the necessity of using search strings
for most viruses has been introduced.

Cerebro can generate a report file listing all the viruses which
it has found.


Memory requirements: 400K conventional memory (approximate).
Note that the requirements have decreased by about 50K since the last
version and they are expected to decrease even further in the next
releases.


1.3 Why Use Cerebro At All? If I Use It, Why Should I Register?

You may be asking right now, given the other foreign scanners around,
why should you register Cerebro?

* IT'S CHEAP
First of all, it is not expensive, and you will get a *personalised*
registered version of Cerebro for DOS. For as little as Lm 1.72 (including
VAT) you can become a registered user with all the benefits that it entails.
Next, Cerebro is almost as fast as the best of foreign antivirus
software, and it is dedicated to the local scene. New viruses
are discovered every day around the world and Cerebro is updated
to detect these. As soon as a user submits a sample, Cerebro can
be updated and a new release issued which detects the new virus.
Imagine the time lag which occurs when a user in Malta submits a
sample to a foreign antivirus producer. It is taking months most of
the time, due to the large number of new viruses which are found daily,
for the software to be updated.

A lot of time and effort went into the writing and production of
this piece of software. It's only fair that you register it if
you intend to use it. If you find it useful you should give the
author an incentive to keep developing it.

* DEDICATED TO THE LOCAL SCENE
Many foreign antivirus programs recognise many more viruses than
Cerebro, yet Cerebro recognizes viruses, trojans and joke programs (jokes)
which are spreading in Malta months before other antivirus software reaches
Malta.  Note that a joke program is harmless - it is just that, a joke.
It is NOT a virus, but it may be annoying.

Some foreign antivirus scanners take as much as three months
before becoming locally available. Others, even the very best of them,
do not get here at all. It has also been the case recently with some
scanners that their new recent releases have a slightly lower
detection rate. For example, a popular scanner did not flag certain
variants which are in the wild in Malta, even though they were over
a year old and available to all major CARO researchers and I.C.A.R.O.
researchers, and most antivirus producers.

It is generally recommended to run anti-virus software from
your own country in addition to well-known foreign ones.
The fact that Cerebro is the only Maltese anti-virus software
being currently updated is another reason to use it and to support it.
Some of the viruses detected by Cerebro are not yet detected by all the
foreign scanners unfortunately even though researchers & AV-producers
have been given samples of them. Do you feel safe running just foreign
antivirus software which do not pay any particular attention to our
virus situation? They can remove the detection of a number of viruses
still common in Malta, since they may consider these viruses as 'extinct'.

No virus scanner can ever really detect ALL the existing viruses.
A few days later, there will be a number of new variants and viruses
which it will not detect. This is unfortunately true even for the very
best of anti-virus software. So it is essential not to depend on just
one anti-virus. Beware of different scanning products which use the same
scanning engine licensed from the same source. That would be the same
as having just one anti-virus.
Cerebro can claim to detecting all the viruses in the Wild in Malta, and
quite a large number of other viruses BEFORE they even arrive. If these
viruses were to be spread to Malta even more rapidly than at present, you
will be covered using Cerebro.

Other than viruses and trojans, Cerebro can detect a number of joke
programs (or simply jokes) including three Maltese joke TSR programs
(Gun, Silverhawk_Worms and Jackpot). The latter was based on the
Casino virus apparently and consists of the Jackpot screen only. It
is incorrectly flagged as a possible Casino variant by some foreign
virus scanners.
Cerebro detects an ever increasing number of viruses including the
Casino family, Italian_Boy, F-You_II, Maltese_Amoeba, the Fax_Free
family, Dark_Avenger (a number of variants), Jerusalem, Akuku
and Cascade.

More virus scan-strings & scan algorithms are added in every new
release as they are reported & submitted by users etc.

For the complete updated list of viruses which are detected check
the file VIRLIST.TXT or run CEREBRO with the -L option.



Another advantage of Cerebro is that it calls viruses by their standard
CARO name, unlike some scanners keep using other denominations.

Remember than Cerebro can now remove a number of viruses including most
of the Stoned family.

Some users have enquired as to why Cerebro does not detect the
'dummy simulated viruses' or scanner fodder created by the
virus simulator virsim.
The reason is obvious: these files are not real viruses since they
do not replicate, so why should Cerebro detect them at all? Most
other scanners do not detect them in fact for the same reason.


1.4 How Do I Use Cerebro?

FIRST OF ALL boot from a clean boot disk. Before running Cerebro,
ensure that you place all the files from the archive into a single
directory. Otherwise Cerebro will complain that it is not able to
find the virus information files VS.BIN and VV.BIN.
I recommend that Cerebro be kept on a safe, clean and
write-protected disk. Registered versions are supplied on a write-protected
disk.

After Cerebro is run, an integrity or sanity check is done to
ensure the executable has not been modified or infected by a
virus. If you start Cerebro and get such a message, you have
been probably infected by a virus. In this case power down and
reboot from a clean diskette (write-protected).

Then use the copy of Cerebro you kept on a safe disk. If you
did not keep a copy, find a clean machine and re-extract
Cerebro's executable from the original archive (assuming your
PKUNZIP is clean).


The CRC sanity check can fail to notice modification in the case of
a stealth file virus which can hide its presence.
That is why  it is recommended  to boot from a clean system diskette
before scanning.


Starting Cerebro is a simple process. The syntax is as follows:

  CEREBRO [options] file_or_pathname1 [file_or_pathname2 ...] [options]

Any number of options may be entered before or after the filenames.
Options are preceded by a '/' or '-', and may be in lower or
uppercase as desired.


The following options are available:

-?,-H                   Displays a help screen.

-S                      System-wide scan of all non-floppy drives.
			Scans all physical or network drives from
			drive C onwards, the equivalent of
			CEREBRO C: D: E: etc.

-O                      Just scan One floppy. The default is to ask the
			user whether more scanning is required.

-N                      No Memory Scan. The default is to scan memory
			when the program is run.

-R                      Rename all infected files. .COM files become .VOM
			files, while .EXE files become .VXE files.

-Q                      Query whether to rename infected files. The -R option
			is implied and is thus not required.

-C                      Clean any infected files if possible with the current
			version. (REGISTERED VERSION ONLY)

-L                      Give a List of Viruses, Trojans and Joke Programs.
			The -P option is not implied automatically. The
			-N option is automatically implied.

-P                      Pause Screen Output Every 22 Lines. The user is
			prompted to press a key to continue every
			22 lines, after which the program continues.

-D                      Display Infected Files Only. This can speed up the
			screen output.

-F                      Generate a virus report file. The default filename
			is 'REPORT.REP', but it can be changed using the
			next option.

-Tfilename.fil          Change the virus report filename. Any DOS-valid
			filename or pathname may be used, up to 39
			characters.

Memory scanning can lead to false positives. This may happen
especially if you have run some other primitive scanner e.g. MSAV
which leaves its scan-strings in memory.
Needless to say, Cerebro does not. In fact, it encrypts its scan-strings
and clears them after the program has finished.

The following are usage examples:

CEREBRO -s -n -p

Scans all the drives on a system. Standard executables are checked,
i.e. files with extensions .COM, .EXE, and .SYS. Memory is not
scanned. Screen output will be paused every 22 lines.

CEREBRO c: -R

Scans drive C:, including the MBR and DOS boot sector, renaming any
infected files.

CEREBRO c:\dos -f

Scans the dos directory on drive C: creating a virus report file.

CEREBRO -c f:\users\comps\msck\ws.exe

Scans & disinfects the specified file on a network.

CEREBRO c:\dos\*.com c:\windows\system\*.dll

Scans all the COM files in the dos directory and all the DLLs
in the windows\system directory.

CEREBRO -R -Q c:\bp      [or just CEREBRO -Q c:\bp]

Scan the bp directory and ask the user whether to rename an
infected file every time one is found.

CEREBRO -o a: -n

Scan a floppy in drive A:, and do not ask for another disk, without
scanning memory.

CEREBRO -l -p

Lists all the viruses and other malware detected by this version
of Cerebro, pausing every 22 lines.




CHAPTER 2 - Registration Benefits.


2.1 How Can I Register?

Cerebro is distributed as shareware. This means that after a limited
trial period of a month, you have to register it with the author if
you intend to keep on using it. You may copy the shareware version and
give it to your friends and colleagues, for evaluation purposes. You
can upload it to other BBS's, ftp sites or other archival areas or give
it to shareware libraries. It may be placed on a CD-ROM software
compilation, but kindly inform the author.





Cerebro is NOT free. You are being given the CHANCE to TRY it BEFORE
you BUY it. That is the reason behind shareware. For new versions
to keep being released and updated, your help is needed.
A Windows version of Cerebro will be yours if you register Cerebro.
Please note this is NOT a Windows shell, it is a proper Windows 3.1
program which does not require the DOS version of Cerebro to operate.
Windows 3.1 is required. The Windows version is not available as
shareware.


Your registration can help the fight against computer viruses.
Your registration is essential to ensure that future versions are
still released as shareware.

Print out the form in the file REGISTER.TXT, fill in the details,
and mail it to the author together with the registration fee.

NOTE: If you do not live in Malta, print the form in the file
FOREIGN.TXT instead.

2.2 Why Should I Register?

Registered users benefit from the following:

- They receive new versions of Cerebro while they are registered.

- They may write in when they need help to deal with infections etc.

- When a registered user gets infected by a new (or modified) and
  unknown virus, sending it on disk to the author entitles him/her
  to a new version of Cerebro able to identify this virus, when this
  becomes available.

- The registered version has the cleaning routines as documented
  in VIRLIST.TXT activated.

2.3 Archive Contents.

CERBRxx.ZIP is the archive for the DOS version of Cerebro.
WCERBRxx.ZIP is the archive for Cerebro for Windows.
CERBRxxR.ZIP and WCERBxxR.ZIP refer to the registered versions, for
DOS and Windows respectively.
Note that if you have a (personalised) registered version, you
should not give it to anyone. Contact the author if you wish
to receive the most up-to-date copy which you can give away
freely.

The following files should be in the archive CERBR25.ZIP.

FILE                    

CEREBRO.EXE             
VS.BIN                  
VV.BIN                  
VIRLIST.TXT             
CERBR25.TXT             
FILE_ID.DIZ             
CEREBRO.ICO             
REGISTER.TXT            
FOREIGN.TXT             

NOTE: The file VS2.BIN is no longer being used by Cerebro.
If you have a copy of it from previous versions, you may
delete it safely.


The above files should not be modified in any way, and any such
modification is a violation of Copyright. All the files of the
shareware version should be distributed together.
The registered version is not to be distributed. Remember, if
you give it away, it will display your name when run and it will
be a violation of copyright.

You can distribute the shareware version which is found on most
BBS's in Malta.

Remember to place all the files belonging to Cerebro in the same
directory. If you do not, Cerebro will complain that it cannot
find its component files.

Cerebro must not be resold for profit, in other words, no disk/shareware
library fee greater than Lm 2 (or $6) must be charged including postage.
However registration fees must still be paid to the author.

To determine the authenticity of the files in the archive, you may 
use PGP. After obtaining the author's PGP public key, type 
'pgp filename.sig filename' for every filename with corresponding
signature file filename.asc. 


You can distribute the shareware version which is found on most
BBS's in Malta, as well as on some ftp sites on the internet.
Visit the Cerebro home page at: 

	http://www.geocities.com/SiliconValley/9433

You will be able to get the latest version, since it is the place where
the latest versions will be released.


CHAPTER 3 - What Viruses Does It Detect?

3.1 Virus List.

Cerebro is able to detect a large number of viruses, trojans
and joke programs(jokes). Please note that jokes are harmless
programs and not viruses. They do not infect any file, but they
can cause distress to innocent users.

The complete list can be found in the file VIRLIST.TXT.
It is able to detect over 250 viruses at present, and the number
increases with every new release.

Amongst them are the Casino family, Maltese_Amoeba, Stoned.No_INT.A,
Form.A, F4 and AntiExe - so you can be certain that these viruses
which are common in Malta get detected.


The list may also be viewed by running Cerebro with the -l option.
The screen will pause after every page if you choose the -p option
also.

If you have found a virus and you wish to know its precise denomination
according to the international CARO standard, you may send a sample
to the author and you will receive the information.
To prevent anyone else from viewing infected samples, you might encrypt
them with PGP 2.6. Get my public key from the internet public keyservers.
With this method, you can be sure no-one else will be able to decrypt and
view the files you send me. PGP uses military-grade encryption. You can
find PGP on various BBS's. Please use PGP Version 2.6 onwards.
The filename to look for is 'PGP261.ZIP'.
If you do not want to use PGP, use PKZIP or ARJ with a password and
mail the password separately.

3.2 Virus Naming Convention.

Cerebro utilises the CARO Naming Convention when possible so as to
eliminate ambiguity.
CARO is the international Computer Anti-Virus Research Organisation.
New variants may be provisionally denoted by Family_Name.New e.g.
Jerusalem.New until a proper name is determined.

HLL is the generic family of parasitic viruses compiled with a high-level
compiler.
HLLO is the generic family of overwriting viruses which are written
using High-Level languages.
Similarly, HLLC is the family of companion viruses written in high-level
languages like Pascal or C.
Tiny is the generic family of viruses which are very small. They are not
related at all.


3.3 Virus Removal.

Virus Removal is available in the registered version of Cerebro only,
as from verison 2.4c, as an incentive for users to register Cerebro.

At present Cerebro removes the following viruses from infected files:
the Casino family, Dalian_China and CSL.517. It also removes a number
of boot sector viruses - see VIRLIST.TXT for the complete up-to-date
information.
Version 2.3c detected and removed the new Dalian_China virus, a doubly
encrypted EXE file infector reported in Hong Kong.

IMPORTANT:
The original infected file is automatically renamed with a '.VIR' suffix,
for any possible subsequent examination or for safety. Should the
disinfected file fail to run correctly, you may wish to submit the original
(.VIR) file for examination.
It is interesting to note that some antivirus products still do not keep
a backup copy of an infected file they are trying to disinfect, and in
some cases (e.g. when faced with a new unknown variant) they mangle the
infected file, which then is unrecoverable.

You are recommended to backup all your important files before attempting
to remove a boot sector virus with any method, whether with FDISK method
or with any antivirus.

DOS Boot sector viruses may be removed using the DOS SYS command.
Registered users may write in to ask about the correct procedures
to be followed for disinfection.
If you are unregistered and you find a new virus, you may submit it on
disk.

Removal of boot sector viruses from floppies only has been implemented.
Removal of such viruses from hard disks will be implemented soon.
Cerebro has been given the ability to successfully deactivate some
viruses in memory starting from version 2.2.
It is able to deactivate the Stoned.No_INT virus if found active in
memory, thus rendering it disabled completely. It will have lost its
replicating ability, and scanning can proceed as normal. 
This cannot be done reliably for unknown variants.
In such a case contact the author for help.

**********************************************************************
 IMPORTANT DISCLAIMER:
 The author of this software is not responsible for any
 liability resulting from the use or misuse of this software,
 or documentation, even though it has been tested thoroughly.
**********************************************************************

3.4 False Positives.

False positives (false alarms) occur when a file is flagged as infected
when in fact it is not. This is especially possible when detecting
polymorphic viruses such as those based on MtE (Dark Avenger's
Mutation Engine) or high-level-language programmed viruses.

This kind of detection may result in some false positives theoretically,
even though this has not been seen in tests. If you find a file which
gives a false positive, kindly inform the author.

To date, no false positives have been found with Cerebro's MtE detection.
Other methods are being investigated with which Cerebro will be able
to detect a larger number of polymorphic viruses effortlessly.

3.5 Variant Checking.

VARIANT CHECKING is a facility by which Cerebro can notice that the
virus detected is actually different from the known one (even though
the virus is partially identical) and will report it as a 'NEW VARIANT'
of the virus. In this case in the interests of anti-virus research
you are urged to give a copy of the infected file to the author for
anti-virus research purposes and an addition to the information database
of Cerebro. The file will then be analysed and later on forwarded to
I.C.A.R.O. (the Italian Computer Antivirus Research Organization) and to
CARO, so that the world's major AV's may be updated.

Cerebro can then be updated accordingly, and the new variant
studied. It may be similar to the known one(s) or radically
different in effect or propagation.


3.6 Memory Deactivation.

A virus which is memory resident can be disabled in some cases.
One of the most common viruses in Malta, Stoned.No_INT.A can be
safely deactivated in memory by Cerebro.
This is a first for Maltese anti-virus software.

You are recommended to exit Windows if this is done under Windows, and
to reboot using a clean system disk. This is because within
a DOS box, you will only deactivate the virtual copy of memory
contained within the DOS box! If you open another DOS box, the
virus might still be active there.

CHAPTER 4 - Error Codes.

4.1 Error Codes.


The following are DOS Errorlevel error codes returned by Cerebro
when it exits:

ERRORLEVEL              MEANING
1                       Insufficient Memory To Run CRC Sanity Check.

2                       Unknown Option Specified.

3                       Cerebro Was Modified or Infected. CRC Sanity Check
			Failed OR Suspicious Tunnelling Suspected.

4                       Escape Pressed, Scanning Interrupted.

5                       Not Enough Memory Available. (Try removing
			any TSRs which you have loaded in your
			AUTOEXEC.BAT, load DOS HIGH, use a third-party
			memory manager like Quaterdeck's QEMM (TM),
			run MEMMAKER if you are running DOS 6,
			OR upgrade to DOS 6.x if you are still
			running a lower version)

6                       Drive Not Ready. (There is no disk in the
			specified drive)

7                       Invalid Drive Specified. (The drive does
			not exist)

8                       System Interrupts May Have Been Hijacked
			By a Stealth Virus  (Suspicious Code Found)

9                       Memory Is Infected By a Virus. (Not Deactivated)


CHAPTER 5 - New Features.

5.1 Summary of New Features in Previous Versions.

The following is a summary of principal new features introduced
in previous versions:

Version 2.0: Totally redesigned and rewritten, new windowed output.
Enhanced searching speed using faster Scanning techniques.
More viruses were detected, and a more flexible scan-string database
file-format was created which allows for fast updates in case of
emergencies.

Version 2.1:  VARIANT CHECKING was introduced. This was the first
time any Maltese antivirus offered such a facility. Other local
scanners do not attempt any such checking.

Version 2.12: New polyscanning algorithm used, speeding up
scanning speed by over 600% according to tests when compared
to version 2.11. Memory scanning was optimized to run faster.

Version 2.3: Memory scanning was optimized dramatically and
has a minimal overhead. New fast methods were utilised.
Cleaning or disinfection of all the known Casino variants was
added. Some extra bytes may be left at the end of cleaned files -
note that this is also done by other programs which disinfect Casino.
It is recommended to clean only in case of emergency and
to restore from clean backups whenever possible. Detection and removal
of the Dalian_China virus (in the wild in Asia) was added from version
2.3c. (This virus is an encrypted (2 level) EXE infector and has not
yet been reported locally.)

Version 2.4 featured an upgraded scanning engine, resulting
in scanning which is more than twice faster than the previous version.
Memory requirements have been slightly reduced also.
Cerebro will no longer run if a year has passed since it
was released. In that case, get a more recent version. In case
of emergency, you can change the system date to an earlier date
to be able to use the program, but this is not recommended.

* NOTE:
  Junkie, the first multipartite virus to be in the Wild in Malta, is
  detected both in the MBR and in COM files.
  It is doubly encrypted in COM files.

  Version 2.4b fixes a bug in the previous version which would not
  allow cleaning to proceed in some cases. Version 2.4b also cleans
  the CSL.517 virus in executables. It also features removal of boot
  sector viruses from floppies, which include the Form.A virus and
  most viruses from the Stoned family. Check the VIRLIST.TXT for all
  the details on which viruses may be removed by the current version.
  The latest feature of this version is removal of the Form.A boot
  sector virus from hard disks. Virus Removal from hard disks is still
  in BETA, but Cerebro has a built-in safety check so that if it does
  not find the original boot sector (or MBR) it does not overwrite your
  hard disk's boot sector (or MBR). Before using it, see that you take
  a backup of your boot or MBR sectors and perhaps take a backup of your
  data.

  Another principal new feature is the reporting facility. Using this
  facility, a report file (with the default filename REPORT.REP) can
  be generated listing all the infected files which were found.
  Another innovation concerns a new parameter (-d) which can be used
  so that only infected files are shown on screen, thus speeding up
  the screen display.
  More fine-tuning was done on the scanning engine, bringing the speed
  of the scanner up to around 20% faster. Now a typical basemark
  multimedia pc Windows 3.1 directory scans in only 2 seconds at most.
  An minor incompatibility with Novell NetWare 3.12 was fixed.
  The sanity check would not proceed if the scanner was run from the
  server's hard disk. This has been now fixed.

  The file VS2.BIN is no longer being used by Cerebro. It has
  been incorporated in the other data files. Old copies of this
  file may be deleted safely.


5.2 New Features In The Current Version.

  Version 2.5 brings up the number of viruses detected to
over 250.
  Version 2.5 is being released late, due to some hard disk problems.
This version has been uploaded to internet ftp sites and to the new
Cerebro web page.


  Version 2.5 detects the standard EICAR "test virus".
  The following viruses were detected as variants by earlier versions
  of Cerebro and now are detected accurately:

  Casino.A
  VCL.511
  VCL.509
  VCL.526
  VCL.604
  VCL.2750
  VCL.Annoyer
  VCL.ByeBye
  VCL.Sorlec


  New viruses detected by this version of Cerebro:

  Cop-com.285
  Cop-com.287
  DM.400.A
  Itti.99.A
  Itti.161
  Itti.Malmsey
  Kiev
  Proto-T.599.A
  Proto-T.631
  PS-MPC.203
  Sandra.1809
  Something
  VCL.Poisoning
  VCS.Manta



  The following viruses have been renamed to conform more closely
  with the CARO standard:

  PS-MPC.Demoexe          ---> PS-MPC.DemoExe.381
  VCL.BEv.516             ---> VCL.BEv.516.A



5.3 Malta Wildlist.

Please refer to the file WILDLIST.TXT


If you know of any virus incidents which you would like to report
(confidentially), contact the author. The scale of the virus problem
in Malta is not completely known since most people would not like
to admit having had virus infections. The Malta Wildlist in this
documentation is an attempt to keep accurate information about
the virus problem in Malta even though this is extremely difficult.
I wish to thank all the users who registered and all those who have sent
in information which was included in the Wildlist as well as other
people who have sent in suggestions, comments and samples.

5.4 The Future of Cerebro.

Cerebro started off as a scanner for a single boot sector virus (CARO
name Stoned.No_INT.A), and ended up becoming a general-purpose
virus scanner. Scanning techniques keep evolving in time, and new methods
will be added as time goes by. New methods are being studied and tested.
The techniques currently used are not comparable to those of other older
local scanners (which were for one virus only) which take longer to scan
for one virus than Cerebro takes for all the viruses it detects. Instead
the methods used are close to those of other quality foreign virus scanners.
Scanning techniques used by Cerebro are continuously improving and
the next versions will be further improved, perhaps offering more advanced
features like selective report-file generation, certainly detecting more
viruses.


As usual each new version will detect more viruses. The windows version
has been put on hold for the moment. It may not be worth developing and
is not in demand as much as the dos versions are. Possibly a 32 bit
protected mode version would be more useful.

Comments on Cerebro are appreciated.

If you would like to BETA test new versions of Cerebro, kindly contact
the author.


Contribute to the fight against computer viruses and other malware by
registering your own copy now.

5.5 Other Utilities by Clyde Meli.

The following are utilities written by Clyde Meli, B.Sc, the author
of Cerebro.

Cerebro         - Virus Scanner for boot & file viruses.
		  Cerebro detects and precisely identifies viruses
		  which are currently in the wild in Malta, giving
		  the general family name and the variant name as
		  required by the CARO standard. Cleaning, Memory-scanning
		  and deactivation implemented for some viruses.
		  Chicago-aware. Windows version available to
		  REGISTERED USERS ONLY (still in beta).

Zipv12          - Zip Verbose Lister v1.2. Lists the contents of ZIP
		  files. (the equivalent of PKUNZIP -vb, but smaller!)
		  Freeware.

------------------------------------------------------------------
		   
