      
  
                                  USER'S MANUAL
  
      
  
                                    DisCoVir
  
                                       the
  
                          DISinfector of COmputer VIRus
  
                                  Version 1.13
  
                Copyright (c) 1997-1999 by Cesar I. Gulmatico Jr.
  
      
  
       16 Agno Street, NIA Village, Tandang Sora, Quezon City, Philippines
  
                                cigjr@hotmail.com
                               
                                February 19, 1999
  
      
  
  CONTENTS
  
  Introduction
  
  Command Line Options
  How The Program Works
  
       Memory Scanning
       Self-check and Self-restoration
       Boot Sector Scanning and Disinfection
       File Scanning and Disinfection
       False Positive
  
  Scanning Reports
  How to Register Your Copy of DisCoVir
  
       Registration Procedure
       Registration Fee
       Benefits
       User Support
  
  Virus List
  How to Handle a Virus Infection
  How to Minimize the Possibility of A Virus Infection
  Disclaimer
  Copyright Notice
  
  
  
  DisCoVir is an antivirus program that can detect and remove known viruses 
  from system memory, infected files, boot sectors, and hard disks' master boot 
  record. DisCoVir has the ability to determine if it has been infected, and, 
  subsequently, restore itself.
  
  DisCoVir will run on any PC with 258 KB free memory using MS-DOS or PC-DOS 
  version 3.0 or later as operating system. 
  
  DisCoVir uses both DOS and BIOS functions for keyboard input and video 
  output. DisCoVir switches to video display mode 3 (color cards) or mode 7 
  (monochrome cards) if the current display is not in 80 x 25 mode. DisCoVir 
  uses display page 0 for BIOS video functions.
  
  DisCoVir recognizes 101 viruses mostly collected from the "wild". DisCoVir 
  can also detect unknown variants of file and boot viruses. Furthermore, 
  DisCoVir uses published virus search strings or signatures to search for 
  viruses in the master boot record, boot sector, and files. 
  
  
  DisCoVir is invoked from the DOS command line with the syntax:     

            DisCoVir drive:[path][filename] [options]

  The drive: refers to the logical drive to be scanned, represented by a letter 
  followed by a colon. A space is required between DisCoVir and the drive 
  specification. The optional [filename] refers to a specific file or group of 
  files that you want to scan. Wild cards (* and ?) may be used in a filename 
  to scan for a group of files. If the file is in a subdirectory, the [path] or 
  name of directories leading to the location of the file, should be specified. 
  The [options] are switches used to configure the way DisCoVir executes. An 
  option is made up of a slash and usually followed by two letters, which may 
  be entered in upper or lower case. The following options or switches may be 
  used when invoking DisCoVir:
  
       /AF       scan all files
       /CH       scan high memory
       /DR       disinfect or remove a virus from files and disks
       /FI       boot virus file image scan
       /MD       multiple floppy disk scan
       /MO       memory scan only
       /NB       suppress beep on prompts
       /RI       registration information 
       /TY       display credit screens
       /VI       virus information
       /VL       display virus list
       /XB       skip boot sector scan
       /XH       skip high memory scan
       /?        display help screen
  
  The /MO, /RI, /TY, /VI, /VL and /? options do not require a specified drive 
  when invoked.
  
  
  
  
  
  
                              
                              COMMAND LINE OPTIONS
                              
  
  
  SCAN ALL FILES [/AF]
  ~~~~~~~~~~~~~~~~~~~~
  By default, DisCoVir only searches for and scans standard programs, files 
  whose extension are either COM, EXE, SYS or OV?. Also, Word for Windows' DOC 
  and DOT files are scanned for known macro viruses. This option will enable 
  DisCoVir to scan a file regardless of its extension.
  
  DISINFECTION OR VIRUS REMOVAL [/DR]
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  This option will enable DisCoVir to remove a known virus from a file, boot 
  sector, and hard disk's master boot record (MBR). 
  
  BOOT VIRUS FILE IMAGE SCAN [/FI]
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  This option will enable DisCoVir to detect file images of a boot infecting 
  virus. A boot virus file image is a copy of the virus codes found in the boot 
  sector or the master boot record. This can either be the complete virus or a 
  fragment of the virus, often called as a loader.
  
  This option is on as a default on registered versions of the program. 
  Invoking this option on the command line will suppress the scanning of boot 
  virus file images.
  
  If the /DR option is enabled, detected boot virus file images are deleted.
  
  MULTIPLE FLOPPY DISK SCAN [/MD]
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  The multiple disk scan option will enable DisCoVir to scan several floppy 
  disks in drive A: or B: only. The /MD switch is ignored in other drive 
  specifications.
  
  SUPPRESS BEEP ON PROMPTS [/NB]
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  This option suppresses the beep on almost all the prompts, except for those 
  that require immediate user action, such as a failed self check. The beep 
  should not be suppressed if screen output is redirected to a file, since this 
  will be the only way you will know if the program detects a virus or 
  encounters a problem. 
  
  REGISTRATION INFORMATION [/RI]
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  When invoked, DisCoVir displays the instructions on how to register. With 
  this option, DiCoVir can create a blank registration form or assist the user 
  in filling up the form. The registration form, DCVREG.FRM, will be created in 
  the current drive and directory.
  
  CREDIT SCREEN [/TY]
  ~~~~~~~~~~~~~~~~~~~
  When invoked, DisCoVir displays the program's "THANK YOU" screens. This 
  option is intended for systems using color cards. It also executes on systems 
  with monochrome cards but the display is not adjusted for that adapter.
  
  USE SCAN ONLY PUBLISHED FILE VIRUS SIGNATURES [/UG]
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  This option enables DisCoVir to search for other file infecting viruses, in 
  addition to known viruses. The signatures used to search for viruses were 
  taken from published sources. This will cause the program to take more time 
  in scanning a file. An asterisk preceeding the virus name means that the 
  detection was made using the published virus search strings. (See Virus List 
  and Submission for listing.)
  
  DISPLAY VIRUS LIST [/VL] 
  ~~~~~~~~~~~~~~~~~~~~~~~~
  This option displays the program's list of known viruses and includes the 
  general characteristics of the virus and DisCoVir's disinfection guide. A 
  virus list with the corresponding CARO names is in the file VIRLIST.DCV.
  
  SKIP BOOT SECTOR SCAN [/XB]
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  This option forces DisCoVir to bypass the scanning of boot sectors and on 
  hard disks, the master boot record as well. 
  
  DISPLAY HELP SCREEN [/?]
  ~~~~~~~~~~~~~~~~~~~~~~~~
  When invoked, DisCoVir displays the program's help screen showing the command 
  syntax and the command line options. The help screen is also displayed if 
  DisCoVir is executed without a specified drive.
  
  
  
  The following options are available to REGISTERED USERS only.
  
  
  SCAN HIGH MEMORY [/CH]  
  ~~~~~~~~~~~~~~~~~~~~~~
  This option forces DisCoVir to scan the memory above the 640 Kb conventional 
  memory (640 Kb to 1088 Kb) on any system. On systems where the High Memory 
  Area (HMA) does not exist, the first segment (0 to 64 Kb) of conventional 
  memory is rescanned. Default on detection of an XMS driver.
  
  SCAN MEMORY ONLY [/MO]  
  ~~~~~~~~~~~~~~~~~~~~~~
  This option forces DisCoVir to terminate after scanning memory. /CH and /XH 
  options are still recognized.
  
  SKIP HIGH MEMORY SCAN [/XH]  
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  This option suppresses the scanning of high memory. This has no effect on 
  systems without an installed XMS driver.
  
  VIRUS INFORMATION [/VI] 
  ~~~~~~~~~~~~~~~~~~~~~~~
  This option executes the program's virus information module. The module 
  contains description of the viruses known to DisCoVir. Refer to DCVIRNFO.DOC 
  for details.
  
  
  
  
  
                              
                              HOW THE PROGRAM WORKS
                              
  
  MEMORY SCANNING
  ~~~~~~~~~~~~~~~
  
  DisCoVir scans the 640 Kb conventional memory (0 Kb to 640 Kb) for known 
  memory resident viruses. High memory (640 Kb to 1088 Kb) is automatically 
  scanned if an XMS driver is detected. 
  
  The inclusion of memory managers in MS-DOS 5.0 brought access of high memory 
  to the mainstream. However, this also gave viruses access to memory above the 
  640 Kb conventional memory, specifically the upper memory blocks (UMB). 
  Although viruses known to DisCoVir do not directly access high memory, these 
  can be installed there if the LOADHIGH and DEVICEHIGH commands are used. 
  
  DOS requires an installed XMS (extended memory) driver, HIMEM.SYS in MS-DOS, 
  before it can be loaded in high memory. Its EMS (expanded memory) driver, 
  EMM386.EXE, which makes available the UMBs, also requires the XMS driver. 
  Although the presence of the XMS driver does not necessarily mean that upper 
  memory is available, DisCoVir makes the presence of the XMS driver a 
  requisite for high memory scanning. The high memory scan configuration can 
  either be suppressed (/XH option) or forced (/CH option).
  
  If a known memory resident virus is detected, DisCoVir automatically disables 
  that virus and, as much as possible, clears the memory it occupies. However, 
  DisCoVir does not release the virus' program memory block nor its 
  environment. DisCoVir also searches for unknown variants of Illusion, June12 
  and Possessed. The user is informed of a detection, but the virus is not 
  disabled. 
  
  
     Ŀ
                                                                  Ŀ
                          I M P O R T A N T                        
                                                                   
      If  you  are using other anti-virus programs  that  disable  
      viruses  in memory but do not clear the virus code, do  not  
      execute  DisCoVir  if  the program/s  removed  a  virus  in  
      memory.  DisCoVir  might still detect  the  disabled  virus  
      and  will  automatically  perform virus  removal.  If  this  
      happens, it is possible that your system will hang.          
                                                                   
      If  you  are  using a RAM disk  installed  in  low  memory,  
      DisCoVir  might  mistake an infected file in the  RAM  disk  
      as  a  memory resident virus. If this happens,  some  files  
      in  your RAM disk might be corrupted.  Although  precaution  
      has  been taken  to prevent this from  happening,  DisCoVir  
      has problems with some infections of Jerusalem.              
                                                                   
      
       
  
  Additional Notes on Memory Scanning:
  
  1. If the Dir-II virus is removed from memory, Dir-II infected programs will 
     not execute and at times will hang the system. This is because the data of 
     the infected program are decrypted and restored by the memory resident 
     virus. Also, the virus will not be able to reinstall itself in memory due 
     to the way it checks memory for residency.
  
  2. Sometimes, the memory block occupied by a virus is marked by DOS as 
     released and therefore available to other programs. If DisCoVir encounters 
     such a case, the user will be warned and advised to reboot the system. It 
     is possible that this memory block will be allocated and will result in 
     system hang. 
  
  3. If your system does not have a hard disk and DisCoVir detected Tequila in 
     memory, means that you executed a Tequila-infected EXE program. What 
     DisCoVir found is the image left by the file virus. Tequila will only 
     become memory resident through a boot from an infected hard disk.
  
  4. Avoid pressing any key while the program is scanning memory. Pressing a 
     key generates an interrupt, which might give rise to complications while 
     DisCoVir is disabling the interrupt handlers of some viruses.
  
  
  
  
  SELF-CHECK AND SELF-RESTORATION
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
  DisCoVir performs a self-check every time it is executed. Because execution 
  is automatic, its presence is only made known when it fails. Should this 
  happen, DisCoVir will attempt to restore itself and terminate. 
  
  If self-restoration is successful, you are requested to execute DisCoVir a 
  second time. By this time, all known viruses should have been removed from 
  memory. Upon reexecution, DisCoVir will verify if an unknown .EXE file 
  infecting virus is active in memory. If DisCoVir fails its self-check on the 
  second execution, the presence of an unknown virus strain or variant is 
  certain.
  
  In case DisCoVir cannot restore itself, an unknown EXE file infecting virus 
  strain/variant is active in memory. DO NOT EXECUTE AN INFECTED DISCOVIR. 
  EXECUTION OF AN INFECTED PROGRAM LOADS THE VIRUS IN MEMORY AND WILL FURTHER 
  SPREAD THE VIRUS. 
  
  When an unknown file virus is detected through the self-check of DisCoVir, 
  you will have to cold boot from a clean system diskette, DO NOT CTRL-ALT-DEL. 
  Power off and then switch on the system or at least press the reset button. 
  
  OVERWRITE THE INFECTED DISCOVIR WITH YOUR BACK-UP COPY and trace the source 
  of infection. 
  
  If DisCoVir removes a known file virus in memory, it is likely that DisCoVir 
  will fail when it performs its self-check; but, it will be able to restore 
  itself. DisCovir will not attempt to restore itself if it is infected by the 
  Dir-II virus. 
  
  DisCoVir's self-check cannot detect the presence of all unknown file viruses 
  in memory. There are viruses that only infect specific programs (like .COM 
  files) or have stealth capability. Also, some viruses are selective of the 
  files they infect. The program's self check is often modified to counter the 
  stealth techniques employed by viruses.
  
  To make full use of the limited protection provided by the program's self-
  check, DisCoVir should be executed from a write-enabled disk which has about 
  4,000 to 6,000 bytes of free space to give the virus enough room to infect 
  DisCoVir. But keep a back-up copy in a write- protected disk in case of a 
  failed self-restoration. It is also advisable to make DisCoVir the first 
  entry of the directory.
  
  
  
  
  BOOT SECTOR SCANNING AND DISINFECTION 
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
  DisCoVir scans for known viruses in a floppy disk's boot sector. On  hard 
  disks, the master boot record (MBR) and the partition's boot sector are 
  scanned. DisCoVir treats a drive designated as C: or above as a hard disk. On 
  device driven drives not mapped to a hard disk (such as RAM disks) DisCoVir 
  will issue an error reading the MBR message.
  
  When no known virus is found, DisCoVir scans the boot sector using boot virus 
  signatures from published sources. Only after that will DisCoVir use its own 
  generic signatures to search for boot viruses. The use of generic signatures 
  is not a guarantee that DisCoVir will be able to detect all boot viruses, but 
  it will be able to catch a lot of unknown boot viruses.
  
  To further help in detection of an unknown boot virus, the boot sector or MBR 
  of the disk being scanned is validated against the actual boot sectors or MBR 
  generated by DOS. The following DOS versions' MBR and boot sector are known 
  to DisCoVir:
  
    Master Boot Record : PC-DOS 3.2 and 3.3
                         MS-DOS 5.0 and 6.0
  
  
    Boot Sector        : PC-DOS 3.2, and 3.3
                         MS-DOS 4.0, 5.0 and 6.0
  
  Other PC-DOS/MS-DOS versions' boot sectors are also recognized. Please note 
  that these boot sectors were lifted from disks that I have personally 
  examined. I have no way to confirm if these are the actual boot sectors 
  created by a particular DOS version. The documented boot sectors were 
  generated by the FORMAT utility and the master boot records by FDISK.EXE. 
  
  If a disk's boot sector or MBR does not match those known to DisCoVir, the 
  disk will be flagged as having an unrecognized boot sector or master boot 
  record. This may mean any of the following:
  
   o  the disk is infected by an unknown boot virus.
  
   o  the disk contains a valid boot sector or MBR created by third party 
      utilities or DOS versions not known to DisCoVir.
  
   o  the disk boot sector or MBR is immunized or changed by security and/or 
      antivirus programs.
  
   o  it is a boot sector of a device driven drive (RAM disks, etc.).
  
  To remove a virus from the boot sector or MBR, DisCoVir reads the virus code 
  for the location of the original sector, except for viruses that relocate the 
  original sector  to a specific sector (like Michelangelo, NoInt, Stoned, 
  etc.). DisCoVir does not clear the sectors occupied by the virus code. It 
  also does not release the bad sectors created by a boot virus to protect its 
  codes.
  
  The saved boot sector or MBR is rescanned and then validated before restoring 
  to disk. 
  
  DisCoVir may not be able to find the original boot sector and remove the 
  virus because of the following reasons:
  
    o  The original floppy boot sector is lost when an infected  diskette is 
       duplicated using DOS' DISKCOPY. This is true for boot viruses that save 
       the floppy disk boot sector at track 40 (360 Kb) or 80 (720 Kb, 1.2 Mb, 
       1.44Mb) like Joshi or Invader.  This extra track is inaccessible in some 
       systems.
  
    o  The original boot sector or  master boot record is lost on disks with 
       multiple boot virus infection. 
  
    o  The virus does not save the original master boot record.
  
    o  The original boot sector or master boot record is overwritten in the 
       normal use of a disk. Some boot viruses (such as Sampo and Quox) do not 
       protect the sector it use.
  
    o  DisCoVir detects an unknown boot virus. DisCoVir searches for 
       instructions commonly used by a boot virus if no known virus has been 
       found. These generic signatures cannot detect all unknown boot viruses, 
       especially a stealth boot virus resident in memory. 
  
    o  DisCoVir does not support the removal of the virus on a particular disk 
       media (like NiceDay on hard disks). 
  
    o  The original boot sector or master boot record saved by the virus is not 
       recognized by DisCoVir. 
  
   o   DisCoVir detects a boot virus using published virus signatures. 
  
  
  
  FILE SCANNING AND DISINFECTION
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  By default, DisCoVir only scans files whose extension are 
  either .COM, .EXE, .SYS or .OV?. (NOTE: DisCoVir cannot scan inside a 
  compressed executable.) Also, WinWord's .DOC and .DOT files are scanned for 
  macro viruses only. This can be overridden by using the /AF option. If only 
  the drive specification is given, DisCoVir will search for files from the 
  root directory and recurses through all subdirectories.
  
  If a path or filename is indicated, DisCoVir uses DOS conventions to 
  interpret the user defined path and file specification. 
  
  If a filename is specified, DisCoVir will search for that filename in the 
  current directory or the specified path. If the specified filename matches 
  that of a directory, Discovir will scan the files of that directory and will 
  recurse through its subdirectories. If a wildcard (* and ?) is used, DisCoVir 
  will search for files matching the wildcard filespec starting from the root 
  directory or the specified path and through its subdirectories.
  
  If the specified filename, with or without wildcard, is not a standard file, 
  the /AF option should be enabled. DisCoVir does not default to scan all files 
  even if a filename is specified. 
  
  DisCoVir will attempt to remove known viruses it detects if the /DR option is 
  enabled. The virus code is read and checked prior to disinfection. DisCoVir 
  takes extra precaution because the method of removal is specific to a virus 
  strain/variant. DisCovir restores the original size of the infected file 
  whenever possible.
  
  
     Ŀ
                                                                  Ŀ
                          I M P O R T A N T                        
                                                                   
      There will be instances when a restored infected program is  
      corrupted   even  if  the  virus  is  completely   removed.  
      COMMAND.COM  and programs with internal overlay are  likely  
      to be damaged by viruses.                                    
                                                                    
      It  is advisable to replace an infected file with  a  clean  
      back-up copy or to reinstall the program from the  original  
      disk.  Disinfection  should  always be taken  as  the  last  
      option.                                                      
                                                                   
      
       
  
  
    DisCoVir can remove almost all known file virus strains/variants with a few 
    exceptions. (Execute with the /VL option for the complete list of viruses 
    that can be disinfected or refer to VIRLIST.DCV.) 
  
    Inability to remove a known virus from a file may be due to the following:
  
    o  The file has multiple infection, particularly when the later infection 
       is by an unknown virus. 
  
    o  DisCoVir detects an unknown variant of a known virus strain.
  
    o  The file has multiple infection. The virus was detected at the end of 
       the file with a later infection located at the beginning of the file. 
       This is true for COM programs. DisCoVir can handle this if all 
       infections are by known viruses. 
  
       NOTE: A virus may be reported as two infections in the scanning summary 
             because of the way the program scans with the /DR option enabled.
  
    o  The file is immunized after an infection. DisCoVir can remove the virus 
       after the file's immunization has been removed by the program that 
       immunized it. 
  
    o  Validation codes or recovery data are attached to an infected file. This 
       is true for some COM infections.
  
    o  The infected file is corrupted.
  
  Although a known virus buried under several layers of unknown viruses can be 
  safely removed, DisCoVir will not do so. The chance of the file being 
  corrupted is higher compared to the method currently used by DisCoVir.
  
  
  
  
  FALSE POSITIVE
  ~~~~~~~~~~~~~~
  DisCoVir will flag the uncompressed version of CHECKVIR.EXE as infected by 
  the E_Bukid and Oggo viruses when using the default scan. The false alarm 
  could not be avoided because of the following reasons:
  
   o The default file virus scanner is a byte-by-byte scanner;
  
   o E_Bukid and Oggo are encrypted viruses with only their decryption 
     instructions remaining constant in all infected files; and
  
   o CHECKVIR uses the entire decryption routine of these viruses as its virus 
     search pattern. It does not hide these from being spotted by other 
     antivirus programs.
  
  
  
  
                        
                        SCANNING SUMMARY REPORT
                        
  
  DisCoVir provides a summary of the program's activity after disk scanning is 
  completed. The report includes the number (n) of:
  
                 n files scanned
                 n files infected
                 n viruses detected on disk
                 n viruses removed from disk
  
  The number of viruses detected and removed from disk is the total number of 
  boot and file viruses detected and removed from disk. If the /MD option is 
  enabled, DisCoVir presents the following report on  termination of multiple 
  disk scanning:
  
                 n disks scanned 
                 n disks infected
                 n files scanned              
                 n files infected             
                 n viruses detected on disk   
                 n viruses removed from disk  
  
  DisCoVir does not support the creation of a logfile. You can use DOS' 
  redirection symbols, ">" and ">>", to write what is displayed on your screen 
  to a file. What will be redirected to the logfile are the reports on virus 
  detection and removal, and errors encountered in accessing memory, disk, and 
  files. DisCoVir's scanning prompts and prompts that require user's response 
  will still appear on screen. Do not enable the no beep (/NB) option when 
  redirecting screen output to file. This will be your means of knowing if a 
  virus is detected or an error is encountered when DisCoVir's screen output is 
  redirected to a file.
  
  
  To create a new logfile or overwrite an existing logfile:
  
                DisCoVir drive: > [drive:][path]filename
  
  
  To add or append to an existing logfile:
  
                DisCoVir drive: >> [drive:][path]filename
  
                 
  
  
  
                      HOW TO REGISTER YOUR COPY OF DISCOVIR
                      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
  DisCoVir is being released as a SHAREWARE program. This means you are free to 
  use it and to let others copy it for evaluation purposes. After trying out 
  the program and you decide to continue to use it, you should register your 
  copy of the DisCoVir. Even if you paid for your copy, this does not 
  automatically mean your copy is registered. No one is authorized to register 
  DisCoVir other than author, Cesar I. Gulmatico Jr.
  
  
  HOW TO REGISTER
  ~~~~~~~~~~~~~~~
  Simply fill up the accompanying registration form, DCVREG.FRM, print it (or 
  print the form and fill up the neccessary information legibly) and send it to 
  me, together with your registration fee. DisCoVir is capable of creating a 
  blank registration form and assisting you in filling up the form.
  
  
  REGISTRATION FEE
  ~~~~~~~~~~~~~~~~
  No specific or minimum amount is requested for registering DisCoVir. I leave 
  it up to you to determine how much the program is worth to you. But please 
  feel free to be generous. YOUR GENEROSITY WILL BE APPRECIATED.
  
  Your registration fee should be sent in the form of money order and by 
  registered mail. Sending cash through the mail is strongly discouraged. Cash 
  can be sent through a legitimate courier that accepts money transfers.
  
  
  WHY REGISTER
  ~~~~~~~~~~~~
  
   o You will become a licensed user of DisCoVir with the legal right to use 
     the program.
  
   o You will receive a serial number that allows you to personalize your copy 
     of DisCoVir.
  
   o Additional features of the program will be available to you.
  
  
  USER SUPPORT
  ~~~~~~~~~~~~
  
  You may write me about problems you encounter in using DisCoVir, as well as 
  any questions, comments or suggestions. I will also try to help you with any 
  virus-related problems. 
  
  I can only accomodate you through correspondence and a self-addressed, 
  stamped-envelope is requested.
  
  
  
  
  
  
  
                            
                            VIRUS LIST AND SUBMISSION
                            
  
  
  KNOWN VIRUSES
  
  The viruses known to DisCoVir are as follows:
  
  File Virus              Boot Virus           Multipartite Virus
  ~~~~~~~~~~              ~~~~~~~~~~           ~~~~~~~~~~~~~~~~~~
  AllSystem               3Nop                 Changsa
  Ambulance               Aircop               Flip.2153
  Barrotes                Angelina             Flip.2343
  BetterWorld             AntiCMOS             Flip.2365
  Burger                  AntiExe              Invader     
  Cara                    AntiTel              Junkie      
  Cascade.1661.A          Baboon               Liberty.2867
  Cascade.1661.B          Bleah                OneHalf.3544
  Cascade.1699            Boot-437             OneHalf.3577
  Cascade.1701.A          Brain                Tequila     
  Cascade.1701.B          Cannabis             
  Cascade.1701.C          DaBoys               
  Cascade.1701.D          Day31                Trojan   
  Cascade.1701.E          Diablo               ~~~~~~   
  Cascade.1701.F          Diskwasher           Bootkill 
  Cascade.1701.Yap.A      Facade               
  Cascade.1701.Yap.B      Flame
  Cascade.1702            HiDos
  Cascade.1703            Ibex
  Cascade.1704.A          J&M
  Cascade.1704.B          Joshi                
  Cascade.1704.C          Jumper               
  Cascade.1704.D          Kilroy
  Cascade.1704.E          Lavot
  Cascade.1704.F          Michelangelo         
  Cascade.1706            Microbe              
  Cascade.Formiche        Monkey.A             
  Catphish                Monkey.B             
  Danao                   NiceDay              
  DanishTiny.Kennedy      Njh-Lbc              
  DarkAvenger             NoInt                
  DieHard2                Nova
  Dir-II                  Nyb                  
  E_Bukid.2000.A          OldSampo             
  E_Bukid.2000.B          ParityBoot           
  Fairz                   Payback
  Fumble                  PingPong             
  Green_Caterpillar       Quaint.A             
  Illusion.1238.A         Quaint.B                  
  Illusion.1238.B         Quaint.C                  
  Jerusalem.Czech         Quaint.D             
  Jerusalem.Standard      Quandary             
  June12.2660.A           Quox                 
  June12.2660.B           RussianFlag          
  June12.2660.C           SailorBoot           
  June12.2695             Sampo                
  Keypress.1216           SaptaWahyu           
  Keypress.Chaos          Sepultura            
  Lehigh                  Stoned               
  LittleRed               Uniform              
  Marauder                WelcomB              
  Matthew.2667            Wxyc                 
  Matthew.3037            X-3a                 
  Matthew.3044            Y-Boot               
  MSU-IIT                 
  MtE.Pogue               
  Necropolis              
  NoFrills                
  November17.800          
  November17.855          
  NRLG                    
  Oggo.3766               
  Oggo.3806               
  Oggo.3813               
  Ontario                 
  Pempe.1811              
  Pempe.1943              
  Phalcon.Cloud           
  Possessed.2167.A        
  Possessed.2167.B        
  Possessed.2367          
  Possessed.2438          
  Possessed.2443          
  Possessed.2446.A        
  Possessed.2446.B        
  PS-G2                   
  PS-G2.Singko            
  PS-MPC                  
  PS-MPC.Shiny            
  Quicky                  
  SayhaWatpu              
  Tadpoles                
  Tai-Pan.438             
  Tai-Pan.666             
  Tanpro                  
  ThreeTunes        
  V2Px                    
  Vienna.Vengeance        
  Vinchuca               
  VLamiX                 
  Werewolf               
  WPC_Bats.2279           
  WPC_Bats.2793           
  WPC_Bats.3072           
  WPC_Bats.3161           
  WPC_Bats.3207           
  Xtac                    
  
  
  Aside from these, a number of viruses are also detected and/or disinfected 
  but for some reasons I felt it is better to leave them out from the list at 
  the moment. Scannning of file images of undocumented boot viruses are 
  enabled.
  
  Names of viruses that originated from other countries are mostly adapted from 
  those being used by F-Prot, which is consistent with the name it assigns 
  viruses. 
  
  
    
  HOW TO SUBMIT A VIRUS SPECIMEN
  
  If you encounter a virus that DisCoVir cannot detect or detects it as an 
  unknown virus strain/variant, I would appreciate receiving a specimen of that 
  virus. A copy of the virus is needed to devise a way to detect/disinfect the 
  virus. 
  
  There are three ways to send a virus specimen:
  
  1. You can log on to BiG BoB's BbS (Tel +63 (2) 735-8319) anytime between 
     9:00 PM to 6:00 AM. You can upload the virus there but please  leave a 
     note to the BBS SysOp, Bobby Forte, that you uploaded a virus. Please do 
     not upload the infected programs as it is but compress it first using the 
     ZIP or ARJ formats.
  
  
  2. You can send it to me as attachment to your e-mail and addressed to my 
     e-mail account at hotmail
  
                                 cigjr@hotmail.com
  
     Archiving the infected file in ZIP or ARJ formats is also requested. 
  
  3. You can send a disk with viruses through the mail. A 3.5" diskette (720kb 
     or 1.44mb) is preferred because it is less likely to be damaged in 
     transit. You will have to use a diskette mailer (or improvise one) for 
     5.25" floppies.
  
  
  
  
  WHAT TO SEND
  
  For file infecting virus, send me working copies of infected executables, 
  such as those with .COM and .EXE file extensions.
  
  For boot viruses, an infected floppy diskette is needed. A file image or a 
  printed hex dump of the infected boot sector/MBR is also acceptable. An 
  infected diskette is preferred. A Teledisk copy of your diskette is also 
  welcome.
  
  For multipartite viruses, either the file or boot version of the virus will 
  suffice. However, sending a specimen of both type of infections is preferred.
  
  
  SOURCES OF DISCOVIR'S VIRUS SAMPLES
  
  The viruses known to DisCoVir either came from my own infected disks/files; 
  were sent to me; my disks were returned to me infected; or I was lent 
  infected disks.
  
  Some of these viruses came from:
  
    Marvin B. Buhain
    Alberto E. Cuaderno Jr.
    Dennis O. Esternon
    Bobby J. Forte
    Jan P. Jurisprudencia
    Jerico B. Lorico
    Allan Levi C. Morales
    Richard Morales
    Melody E. Ocampo
    Jeremaine M. Osia
    Marvin D. Panganiban
    Ronnie Pineda
    Eric Santos
    Mharck Sevilla
    Jason U. Soriano
    Kenneth James S. Yumang
  
  
  
  
                    HOW TO HANDLE A VIRUS INFECTION
                    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
  
  If a virus has unfortunately crept into your computer (or suspect one), you 
  can follow these procedures to rid your system of viruses.
  
  
  A. DETECTION
  
    1. POWER OFF IMMEDIATELY. This will kill all active viruses in your 
       computer's memory.
  
    2. BOOT FROM A CLEAN, VIRUS-FREE, SYSTEM DISKETTE. This ensures that you 
       will be undertaking your anti-viral activity under a clean environment. 
       Do not execute programs in your hard disk.
  
    3. SCAN YOUR DISK FOR VIRUSES. Do not enable the anti-virus' disinfection 
       capability. Include non-executables in the scanning. Take note of the 
       files identified as infected. If your anti-virus program supports 
       creation of a log file, enable that feature.
  
  
  B. RECOVERY OF INFECTED FILES
  
    4. OVERWRITE THE INFECTED FILES WITH YOUR BACK-UP COPY. Replacing infected 
       files with the original or a back-up copy is the easiest, safest, and 
       preferred method of recovery.
  
    5. SAVE A COPY OF AN INFECTED FILE TO A FLOPPY, that is, for those files 
       you do not have extra copies of. This is your insurance against an 
       improper disinfection. (And also for sending me a copy.)
  
    6. DISINFECT BY USING AN ANTI-VIRUS. Disinfection should always be taken as 
       the last option. Although most infected files can be restored, there are 
       viruses that do irreparable damage.
  
    7. TEST THE DISINFECTED PROGRAM if it works as before. Execution of an 
       improperly disinfected file will often hang the system.
  
    8. DELETE THE COPY OF THE INFECTED FILE, if disinfection is successful. 
       Otherwise, try another program.
  
  
  
  C. RECOVERY FROM A BOOT SECTOR/MASTER BOOT RECORD INFECTION
  
    4. BACK UP YOUR DISK. If something goes wrong, you'll have your lifesaver. 
       If you have a previous back up, do not overwrite it.
  
    5. DISINFECT BY USING YOUR ANTIVIRUS. Most anti-virus programs can restore 
       the original boot sector/MBR. Else....
  
    6. USE SYS TO REMOVE THE VIRUS FROM THE BOOT SECTOR. By using SYS, DOS does 
       not only make your disk bootable but also creates a new boot sector. You 
       can also do a reformat if you want to.
  
    7. USE FDISK /MBR TO REMOVE A VIRUS FROM THE MASTER BOOT RECORD. The /MBR 
       is an undocumented feature of FDISK, available starting with MS-DOS 5, 
       and should be used with caution. If you can access all your partitions 
       after booting from a clean floppy, you have a good chance of recovery. 
       Otherwise, STOP. Again, use this with caution.
  
            
  
            HOW TO MINIMIZE THE POSSIBILITY OF A VIRUS INFECTION
            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
  
  
   o SCAN ALL INCOMING FLOPPY DISKS FOR VIRUSES especially those with 
     executables. If possible, test all executables with your hard disk 
     disabled.
  
  
   o MAKE IT A HABIT TO OPEN DRIVE A:'s DOOR, if you have a hard disk, every 
     time you boot your system. This prevents an accidental boot from a floppy 
     and keeps your MBR safe from boot viruses.
  
  
   o ALWAYS BOOT FROM YOUR HARD DISK, if you have one. To force this, change 
     the boot sequence in your CMOS system configuration to C,A. You will be 
     free from accidentally booting from a floppy and infection from about 95% 
     of boot sector infecting viruses. You can always reset it to A,C if 
     needed.
  
  
   o TAKE NOTICE OF ANYTHING UNUSUAL IN YOUR COMPUTER. If you've been using 
     your computer for quite a time, you will become familiar with its quirks. 
     Suspect anything out of the ordinary.
  
  
   o WRITE-PROTECT YOUR FLOPPY DISKS containing executables. Use separate 
     diskettes for your data files.
  
  
   o EXECUTE YOUR ANTI-VIRUS PROGRAM FROM A WRITE-ENABLED DISK. Most antivirus 
     programs implement a self-check or integrity check routine. To take 
     advantage of this feature (check the program's documentation to make sure 
     it implements this), the antivirus program should always be executed from 
     a write-enabled disk with enough free disk space. But, always have a back-
     up copy in a write-protected diskette ready.
  
  
   o DO NOT IGNORE YOUR ANTI-VIRUS PROGRAM. If an anti-virus program says that 
     something is infected or suspicious, listen to it and do something about 
     it. If you ignore it, you might regret it.
  
  
   o BACK UP YOUR HARD DISK REGULARLY.
  
  
  ___________________                             ____________________
  *******************  I  M  P  O  R  T  A  N  T  ********************
  ~~~~~~~~~~~~~~~~~~~                             ~~~~~~~~~~~~~~~~~~~~
  
  If a virus scanner says that it did not find a virus, it simply 
  means that the program did not find any virus that is known to it or 
  something that looks like a virus. There is no guarantee that the 
  file or disk is really not infected. Nothing more, nothing less.
  
  The best thing you can do is to be observant and practice good 
  computing habits.
  
  Also, send specimen of viruses to your anti-virus program's author. 
  By doing this, you will be giving others who may be hit by that 
  virus, a chance to recover their data and files.
  ____________________________________________________________________
  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  
  
  
   
  
                                   DISCLAIMER
                                   ~~~~~~~~~~
  
  This program is provided as-is without warranty of any kind, either expressed 
  or implied. The author will not be held responsible for any damages or lost 
  data that may result directly or indirectly from the use or misuse of this 
  program.
  
  
  
                                COPYRIGHT NOTICE
                                ~~~~~~~~~~~~~~~~
  
  DisCoVir is registered with the Philippine Copyright Office. This program is 
  protected by Philippine copyright laws and international treaties. All rights 
  reserved. 
  
  DisCoVir Copyright (c) 1997-1999 by Cesar I. Gulmatico Jr.
  
  DisCoVir, the DISinfector of COmputer VIRus 
  written by Cesar I. Gulmatico Jr.
  
  
  
  All other programs or products mentioned in this documentation are 
  trademarks, copyrights or works of their respective owners.
  
  F-Prot copyright by Frisk Software International
  MS-DOS is a trademark of Microsoft Corp.
