
                               Virus Catch
                               -----------


Contents
--------

   1  Purpose
   2  Caution
   3  Usage
   4  Options
   5  How it works
   6  Errorlevels
   7  If a virus is found
   8  Virus Buster
   9  C:CURE - hardware protection
  10  Final word


1 Purpose
---------
    This program is designed to detect and "trap" all DOS viruses
    including boot sector, companion and stealth viruses.


2 Caution
---------
    This program uses many low-level tricks to circumvent virus
    traps. This program is _not_ designed for use on networks
    and may fail on some exotic versions of DOS.


3 Usage
-------
    Modify the batch file CATCH.BAT to suit your particular needs
    and then run each day during start-up, or as required.


4 Options
---------
    Catch1.exe takes the following options:

       /d    Catch1 will use drive "d" for the execution of its
             "bait" files. Valid values are A,B,C or D. The C:
             drive is used by default. The bait files are executed
             in the root directory of the target drive.

       /nnn  Catch1 will return the errorlevel of exactly "nnn" if
             no viruses are detected. Valid values are between 1 and 128.
             The default is 1.

             Catch1 does not return the de-facto standard errorlevel of 0
             for all OK as it is possible for viruses to "kill" Catch1 and
             return an errorlevel of 0 to DOS. The "OK" errorlevel is
             user-specified to make it impossible for viruses to kill
             Catch1 and return the correct errorlevel.

    Catch2.exe takes the following options:

       /nnn  Catch2 will return the errorlevel of exactly "nnn" if
             it finds that Catch1 has terminated correctly. Valid values
             are between 1 and 128. Default is 1.


5 How it works
--------------
    Viruses can do anything they want to, so it is not possible to
    make a definitive statement as to how they will act in general.
    Here are some of the ways a virus will typically act with Catch.

    When Catch1 runs, it tests for the presence of the following
    virus types:

        - boot sector and MBR viruses
        - COM file infecting viruses
        - EXE file infecting viruses
        - companion viruses

    If Catch1 detects any of these virus types, and it is able to
    continue operating, Catch1 will create "virus data" files in the
    root directory. These files are _not_ viruses, but contain all
    the information we need about the virus. Send these data files
    to us and we can analyse the virus and provide a cure.

    Sometimes the virus will terminate Catch1 before it can complete
    it's tasks. In this case the PC should begin beeping continually.
    As an additional check, the batch file will run Catch2. Catch2
    checks to see if the Catch1 program terminated normally, if not
    then it returns an errorlevel which can be tested for in the
    batch file.


6 Errorlevels
-------------
    Catch1 returns the following errorlevels.

        nnn     the user-specified "OK" value if no virus detected.
        nnn+1   a boot sector virus or MBR virus found
        nnn+2   some sort of program virus is active
        nnn+4   the Catch1 program appears to be infected
        nnn+8   an EXE-infecting virus appears to be active
        nnn+16  a COM-infecting virus appears to be active
        nnn+32  a companion virus appears to be active

    Errorlevels are added together if more than one problem is found.
    E.g. if you specify an "OK" errorlevel of 56 then a returned
    errorlevel of 66 indicates that there is some sort of virus
    active and it is probably an EXE-infector.

    Catch2 returns the following errorlevels.

        nnn     the user-specified "OK" value if no virus detected.
        nnn+1   the Catch1 program terminated abnormally


7 If a virus is found
---------------------
    If Catch reports that a virus is found, or if Catch1 terminates
    abnormally (beeping or Catch2 returns errorlevel) then you should
    assume your PC is infected. You then need to do this:

       1  Switch the machine OFF.
       2  Reboot the machine with a clean, DOS floppy in the A: drive.
       3  Copy the following files to a floppy
            - all files named VIRUS??.DAT in the root directory
              (a "?" means any character)
            - all files named @??????.COM or @???????.EXE in the root
              directory
            - the Catch1.EXE and Catch2.EXE files
       4  Send this floppy to us for analysis
            Leprechaun Software Pty Ltd
            PO Box 826 Capalaba   Q  4157
            Australia
          or upload the files to our BBS on +61 7 823 1229
             (you don't need to be a user to upload files)
       5  Use Virus Buster to clean up your machine and remove the virus.


8 Virus Buster
--------------
    Virus Buster is a complete anti-virus package.

    Virus Buster has been commercially distributed for 6 years, making
    it one of the longest established packages in the business.

    Over that time it has established a number of worldwide firsts
    in anti-virus technology, including:

        + generic virus detection
        + generic virus removal
        + automatic removal of boot and MBR viruses
        + add your own virus cures
        + anti-stealth disk scanning
        + one-pass signature scanning

    Virus Buster now contains another first. The scanner is the first
    in the world to provide "see-through" detection of highly polymorphic
    viruses, such as those that use the Mte and the Trident engines.

    In addition, Virus Buster provides a host of other features,
    including:

       - signature and file integrity virus scans
         (detect all file changes, even change in location on disk!)

       - extended, expanded and upper memory scan
         (and all memory between 640K and 1Mb, just to be safe)

       - TSR/device driver stops viruses before they activate
         (use either version, for generic virus detection and
          real-time signature checking)

       - virus removal, plus automatic removal of boot viruses
         (repair files damaged by most common file infectors and
          automatically check for and remove MBR and boot viruses
          from your hard disk each time you boot)

       - save & restore CMOS settings & critical disk sectors
         (saves entire CMOS, and MBR, boot, root directory and
          FAT to a diskette, for all hard disks)

       - scan disks at network, DOS and BIOS levels
         (use the lowest possible level for your disk to enhance
          your protection from stealth viruses)

       - add your own virus signatures and virus cures!
         (use the provided virus database engine to add new viruses,
          even the cures, and search for viruses by any characteristic)

       - completely configurable, password access control
         (multiple levels of password access control, separate text
          configuration file, user-configurable installation and more)

       - CUA compliant and easy-to-use interface
         (standard DOS-based windowed interface with full mouse support,
          VGA extensions, drop menus, tileable windows etc.)

       - full on-line help, plus much more...
         (context sensitive, with index, contents list and cross
          referencing, in addition to the 200 page user manual)


9 C:CURE - hardware protection
------------------------------
   If you need...

    - to leave your PC where others can access it...  or

    - to have PCs in classroom locations...  or

    - the highest level of virus security possible

   ...then C:CURE could be for you.

   C:CURE is a hardware device (not a card, so no slot is required)
   that fits between the disk drive and the controller card.
   It monitors all! commands issued by the controller and can block
   disk writes and formats to nominated areas of the disk.

   It sounds simple and it;

      - Provides absolute protection from all boot and partition table
        viruses. Even when the PC is booted from a floppy the hard disk
        cannot be infected.

      - Protects against tampering and accidental corruption. You can
        prevent any disk writes to the entire C: drive if required.
        Imagine how easy that makes maintaining a classroom of PCs.

      - Has an in-built audible alarm, it does not need the PC speaker.

      - Does not affect disk performance in any way, all processing is
        done in the C:CURE chips.

      - Installs in basic mode in seconds, standard mode takes 5 minutes.

      - Is free of false alarms.

      - Is fully compatible with all operating systems.

      - Lasts forever, no updates are required.

   C:CURE provides the ultimate virus defence. Even the IC is protected
   against hacking. Used in conjunction with Virus Buster you can have
   a truly virus-proof PC.

   But C:CURE is also essential as a defence against accidental or
   malicious corruption. In particular, PCs in a classroom situation
   will benefit from the security C:CURE provides.


10 Final word
-------------
    Catch is probably more effective at "catching" viruses than most
    similar programs. Nevertheless, the "catch a virus" approach to
    virus detection is not a completely reliable technique.

    For example, the technique cannot detect viruses that do not go TSR
    (there are many of these). A virus could choose to infect only every
    20th program executed. Catch would then only detect it every 7th time
    it is run.

    For complete virus detection you need to use more than a catch program.


