                             A L E R T !

         This software and documentation are protected under the
         U.S. copyright law, Title 17, USC. Unauthorized
         reproduction by any means, sales, bundling, or any other
         unauthorized distribution other than as stated herein
         are in violation of the copyright law. Persons
         infringing on the author's rights may be prosecuted!

         The author makes no warranties, either expressed or
         implied, with respect to this software or accompanying
         documentation. Under no circumstances shall the author
         be liable for any incidental or consequential damages to
         other software, hardware, loss of data, or loss of
         business opportunity resulting from any defect or misuse
         of this software or documentation. The total responsi-
         bility for its use and performance rests solely with the
         user. This entire package is provided "AS IS."

         This text file is intended to provide documentation for
         using ALERT! and explain the theory of operation and many
         different protection strategies which can be followed
         using ALERT!


         GENERAL THEORY

         ALERT! works by recording the "state" of specified files
         in a "list file." Each time ALERT! is asked to check a
         file or group of files, it compares the current state
         with that recorded in the list. Should a discrepancy be
         found, the user is notified so appropriate action may be
         taken.

         Each "list file" can keep checks on up to 200+ files
         (depending on memory available). There is no limit to
         the number of list files the user may wish to build. You
         may also set up list files which check other list files!
         There is no limit to this type of nesting.

         By protecting system files (e.g., COMMAND.COM,
         AUTOEXEC.BAT, CONFIG.SYS, etc), the user can be secure
         that any changes to them will be spotted on the very
         next ALERT! check. Therefore, checking should be a
         standard part of the power-on sequence. For example,
         place a line such as the following in your AUTOEXEC.BAT
         file;

                ALERT_ME RWR4089

         This calls the command-line version of ALERT! to check
         the list file RWR4089. Of course, in order to tax a
         virus' capability to detect the presence of ALERT!, you
         may rename either or both of the executable programs to
         whatever you please. Finally, you may include any number
         of "dummy" command line parameter switches; e.g., the
         above example could become:

                EDIT /r /l RWR4089 /b /check

         This assumes ALERT_ME.EXE had been renamed to EDIT.EXE.
         Note that the parameter switches ( /r, /l, /b, /check )
         are ignored by ALERT!.  The only valid switchs are /M
         (which forces ALERT! to come up in monochrome mode, even
         if it did not automatically detect mono) and /Q (to quiet
         the sound effects).  Use of the dummy switches simply
         provides additional masking of ALERT! from an intelligent
         virus.


         WHY ANOTHER VIRUS CHECKER?

         I created ALERT! primarily for 2 reasons.  First, I
         wanted to be sure that the virus checker was not itself
         infected.  Second, I wanted something that others could
         use with little difficulty but still provide varying
         levels of protection.

         While there are a number of good checkers out there,
         they all seem to suffer from either being too complex for
         novice users, being memory resident (requiring some of
         the precious 640k), or simply of questionable
         source/nature.

         By controlling the distribution of ALERT! directly, I
         can ensure users will receive only a NONINFECTED
         version.  By presenting ALERT! as shareware, I can offer
         protection to virtually everyone.  There is no need to
         spend $150 to $300 for the commercial programs when all
         you need is reliable protection.  While some of these
         may offer an ability to remove the virus when detected,
         I wouldn't take such a chance.  I'll bet you wouldn't
         either.


         FILES INCLUDED

         The following files should be included in the archive:

                ALERT.EXE      Integrated version
                ALERT_ME.EXE   Command line version
                ALERT.TXT      This text file
                README.!!!     Latest info


         USAGE

         1. Decide upon a name for your list file.  I recommend
         the following: Use your initials followed by the last
         four digits of your social security number; e.g.,
         C:\RWR4089.  This prevents the list file from being
         easily spotted by an intelligent virus while making it
         easy to remember.

         2. Copy the ALERT! programs to your hard drive,
         somewhere on the path.  Rename them if you desire.

         3. Edit your AUTOEXEC.BAT file to include the call for
         the command line version of ALERT!, ALERT_ME (or
         whatever you have renamed it to) and the name of the
         file list you decided upon in step 1.  (The file list
         has not yet been created.) Remember to include the drive
         and path if it will not be stored in the root directory
         as well as any "dummy" switches you wish to use.

         4. Call the interactive version of ALERT!, ALERT (or
         whatever new name you gave it in step 2).

         5. Begin "ADDING" files to be protected.  Please note
         the screen instructions and messages for use of help,
         the directory, and viewing the list.  After a file is
         added you will be asked whether the file should be
         automatically checked.  You definitely should mark all
         system files for auto-check.  These are the files which
         will be checked by the command line version of ALERT! in
         your AUTOEXEC.BAT file.

         6. Continue adding all desired files.  Suggest, as a
         minimum the following be included for auto-check:

                IBMBIO.COM
                IBMDOS.COM
                COMMAND.COM
                AUTOEXEC.BAT
                CONFIG.SYS

         7. Save the file list as the name you decided upon in
         step 1.

         8. Exit ALERT!.

         9. Reboot and watch as each file is checked.

         10. That's it!


         WHAT TO DO WHEN YOU GET AN ERROR

         1. Ask yourself the following question:  Did YOU change
         the file in any way since it was added to the list?
         This is why you placed the ALERT! command line in your
         AUTOEXEC.BAT before creating the list file.  If you are
         the reason for the change, not to fear.  Simply call the
         interactive version of ALERT!, read in the list file,
         update the file (on the protect menu), then resave
         the list. That will cause ALERT! to recompute the
         internal checks.  However, be sure you know the cause
         for the change before doing this.  Otherwise, you might
         be insolating a virus from further detection.

         2. If an error occurs which you are not responsible for
         then there is a good probability your file has become
         infected.  DO NOT TURN OFF YOUR COMPUTER YET!  You still
         need to check the remaining files. Call up the
         interactive version of ALERT!, read in the list file,
         and check ALL files on the list.  Make a note of any
         which generate an error.  Save the list file and exit
         ALERT!.

              I'm sorry to say this, but the only SAFE way to rid
              yourself of the infection is to remove (delete) the
              infected files and restore them from your archive.
              I am assuming you have your original program disks
              in a safe place, only using them to create working
              copies.  Hopefully, you also made a copy of your
              ALERT! file list when it was still clean. This will
              add a measure of reassurance when you recheck your
              files after restoring them.

              If you are truly paranoid, as I would be if I found
              such an infection, you may want to completely
              reformat your hard disk before restoring from your
              archives.  Before you take such a drastic measure
              though, you should copy any DATA files you have not
              previously saved to a clean, non-system floppy
              disk.  Since data files do not execute, they are
              safe from disastrous infection. By copying to a
              non-system disk, you will not transfer any
              infection with them.  Once you have restored your
              hard drive to a clean state, again protect your
              files with ALERT! following the USAGE steps above.
              Finally, copy the data files back.  Now reboot and
              watch ALERT! check your files.  If no errors are
              detected, you are again safe.


         REGISTRATION INFORMATION

         Why register?

         1.  When you register you receive a guaranteed
         uninfected copy of ALERT!.  Although the odds are that
         the version you got from your friend or the bulletin
         board is not infected, the only way to be sure is to
         know the source.  Registered users receive the latest
         version directly from the author.

         2.  This is NOT a free program.  It is provided free for
         evaluation only.  Once you have decided it meets your
         needs, you are required to pay for it.  It IS CHEAP
         protection from otherwise disastrous consequences.
         License Fees are as follows:

                Individual user ......... $ 20.00
                  Use on all computers on which you are the
                  principle user.
                Site License ............ $150.00  < 15 PCs
                                           250.00  unlimited
                  Use on multiple PCs owned by the licensee
                  for non-personal use.
                Government user ......... FREE
                  Use in all government agencies, departments,
                  offices. Contact your MIS department for
                  distribution details.  The author does not
                  provide individual distribution within the
                  government.  You may elect either of the other
                  licenses above, however, if you cannot get a
                  copy through government channels.

         Send check or money order for the proper license fee to:

                ROBERT W. REED
                425 Fairgreen Ave
                Casselberry, Florida  32707
                (407) 695-6837
                Turbo Source Search BBS ... (617) 545-9131

         (c) 1988, Robert W. Reed, all rights reserved.

         ________________________________________________________

         Revision History:

              1.0  - Jun 88, Local beta test
              1.1  - Jul 88, Initial release to shareware
              1.2  - Jul 88, Modified List file value construct
              1.3  - Aug 88, Fixed minor display bugs
                             Added 'UPDATE' option to Protect Menu
                             Modified List file encoding schema
              1.3a - Sep 88, Added complete documentation
                             Modified site license fees
              1.4  - Dec 88, Added sound effects toggle
                             Alt-U macro calls the UPDATE function
                             Misc code simplifications
_________________________________________________________________

APPENDICES:


START WITH A "CLEAN" SYSTEM

In order to protect against a virus, you must capture the "state"
of your files when they are KNOWN to be uninfected. Odds are they
are not infected and protecting them as they exist at the moment
is ok. But what if they were infected? Protecting them in their
infected state simply guarantees they will not be found!
Obviously, the safest procedure would be to clear your disk drive
and start over from the original floppy for each program you want
on your disk. However, that is likely an impractical solution
since so many programs are involved. I suggest a compromise.
Start with clean copies of all SYSTEM files. Since these are the
ones which must be attacked by a virus if it is to propogate
itself, they are the key to everything else. Once they are
protected, any infected program will attempt to infect them.
Then, the next time you run ALERT! the infection will be spotted.
If no infection is detected after you have used all your
programs, then you can assume they were NOT infected and begin
adding them to the list to be protected.

To ensure your system files are clean, go back to the original
system disk and SYS your hard disk according to the
manufacturer's instructions. Then copy the COMMAND.COM file. Edit
your Config.SYS and Autoexec.BAT files to ensure you know
everything they are calling. Any suspicious calls should be
eliminated until you can be sure your starting system is clean.
Once it is, protect the system files with ALERT! and begin adding
the other items back in only after you have determined that they
are pure (drivers in the config.sys file should also be copied
from their original system disk. Run programs from the command
line; recheck system files with ALERT!; if no changes were found,
then the programs did not attempt to infect system files and can
be considered clean.).


LEVELS OF RISK

Just how much risk does your system face? Risk from computer
virus is much the same as risk from standard biological virus.
The more one interacts directly with others, the greater the
risk. Computers which are available to many users are at greater
risk than those of single users. Below is a short table
summarizing my opinion of basic risk. You may disagree. In any
case, it should help you to assess your own level of risk.

                                         Level of Risk
  Activity                              Low   Med   High
  ------------------------------------  ---   ---   ----
  Simple messaging via bulletin boards   x
  PC as bulletin board host              x
    (assuming standard BBS software)
  PC used as remote system host                       x
  Sharing disks with friends                          x
  Multiple professionals on 1 PC               x
  Multiple students on 1 PC                           x
  Commercial software                    x
  Shareware/Freeware NOT from BBS                     x
  Shareware/Freeware VIA BBS                   x
    (However, some SYSOPS specifically protect against
     virus & tojans and thus would be "LOW")


PROTECTION STRATEGIES

Protection can take many forms, based upon the degree of risk and
general "paranoia" felt. At the lowest end, the user exhibits the
"it can't happen to me" attitude and does nothing. At the highest
end, the user allows no one else to use the PC, uses only
commercial software from reputable sources, backs up daily, and
shys from communications.

Obviously, these two extreems are not practical for most of us.
The answer lies in between. While each user must make his own
determination, I suggest the following as a general middle ground
offerring significant protection while encouraging
communications, use of third party software. While companies may
encourage mulitple users of single PCs, I do not. Not only for
safety sake, but for productivity and subjective reasons as well
(but that is another topic). Below is a checklist of activities
which should provide a balance of protection and freedom.

   1. Backup important programs after installation, this includes
      the system & batch files
   2. Backup important data files at least weekly
   3. Use a virus "environment state" protection program to
      watch for infections (like ALERT!)
   4. Download from reputable bulleting boards which check their
      files before making them available (check with the board's
      SysOp, many do this even though they don't mention it)
   5. Never run ANY new program before reading the documentation
      to ensure you know what to expect the program to do.
   6. Run new software from a floppy disk which you booted from.
      This will generally be enough to provide opportunity for
      an infected program to do its work.  If you see your hard
      drive light come on, turn off the PC immediately. If you
      have protected the system files of the floppy, after
      running the new software, you can recheck them to detect
      a virus.  Remember, after running the new software, reboot
      to your hard drive.  Then check the floppies system files.
      This prevents spreading since booting from the hard disk
      executes a different set of system files.
   7. After using any program which seems the least bit
      suspicious, recheck the integrity of your system files.

These ideas are really just common sense, but sometimes just
hearing them helps. Feel free to add any other steps which you
feel are important to your own system.


STRATEGIES FOR ALERT!

There are really an infinite number of implementation strategies
for ALERT!. I will simply mention a few and leave the tailoring
to you.

  1. Keep ALERT! and all list files on a floppy disk.  This is
     the ultimate protection from "smart" virii.
  2. Rename ALERT! and give each list file a unique, deceptive
     name (e.g., Letter.DOC).
  3. Use multiple list files with each protecting the one before.
     Keep the secondary list files on floppy disk.  Also include
     protection for ALERT! in one of these secondary lists.
  4. Protect all *.COM, *.EXE, *.SYS, and *.BAT files.
  5. Protect only system files.
  6. Protect system files with AUTOCHECK, other important files
     without.
  7. Run ALERT! each time the computer boots.
  8. Run ALERT! once each day.
  9. Run ALERT! only when adding new software.
  .
  .
  .


VARIETIES OF VIRII

  A virus will either be infectuous or immediate. Those that act
  immediately are generally known as TROJANS.

  Trojans are normally bits of code buried within an otherwise
  innocent program which are activated whenever the host is
  called. Trojans are found out quickly since the first user to
  get "zapped" by one will usually report it back to the source.
  This allows a warning to be posted before much widespread
  damage can occur. The best method of protection from the Trojan
  is a memory resident "anti-trojan" type of program. One of the
  best I've seen is BOMBSQAD.COM by Andy Hopkins, 526 Walnut
  Lane, Swarthmore, PA 19081 (or via Bob Klahn's Bulletin Board
  at (302) 764-7522, 300/1200/2400 baud). Thus, before trying a
  new piece of software, run BOMBSQAD. It sits in memory waiting
  for a dangerous call and warns of impending write/format
  actions of the running program.

  A Virus, on the other hand, are difficult to detect. They can
  be spread far & wide before anyone even knows of an infection.
  By the time they are detected, determining the source can be
  difficult (at best) or impossible (at worst). This type of
  virus must spread by an executable program, generally the
  system files (via copy, sys, etc.). The best method of
  protection from these is to maintain the "state" of your files
  and periodically check them. Since this type of virus must stay
  dormant in order to spread, regular checking will alert you to
  infection before damage can occur. This is the type of virus
  ALERT! was created to protect against.


