                  VACCINE -- The (c) Brain Virus Eradicator


         (Except from FASTLINE, by Virginia Tech Computing Center, dated
          February 18, 1988)


          VIRUS INFECTS VIRGINIA TECH PCs                             
                                                                      
          A very contagious virus has infected the local PC community.
          Although  no  cases of data loss have yet been reported, ex-
          treme caution should be exercised: the virus may permanently
          destroy data on diskettes and  harddrives.    The  virus  is
          known to have infested large diskette collections.          
                                                                      
          A  PC  will become a host for the virus if it is booted from
          an infected diskette or harddrive.  A PC will also become  a
          host  for  the  virus if a program that carries the virus is
          executed on the PC.  The identity of the carrier  program(s)
          is not yet known.                                           
                                                                      
          Once  a  PC  becomes a host, it will contaminate any disk it
          has access to.  A disk can become infected by a host PC even
          if the disk is not written to.  A disk can  be  contaminated
          just by looking at its directory for example.               
                                                                      
          A virus infected PC can be detected by a conspicuous loss of
          7  kilobytes of total memory.  Disks infected with the virus
          may have a volume label of "(C) Brain".  However, if a  disk
          does not have this label, it may still be infected.         
                                                                      
          PREVENTION                                                  
                                                                      
          To  insure  that your PC, harddrive and diskettes do not be-
          come infected, carefully observe the following precautions: 
                                                                      
          o   TURN OFF the PC before you begin to use it.  A soft  re-
              set (cntr-alt-del) is NOT sufficient.                   
                                                                      
          o   Boot  from  a  diskette that is known to be clear of the
              virus. (A fresh copy of your original  DOS  diskette  is
              best.)                                                  
                                                                      
          o   Place  a write protect tab on your boot diskette and al-
              ways boot from this same diskette.                      
                                                                      
          o   Place a  write  protect  tab  on  all  diskettes  except
              diskettes that must be written to.                      
                                                                      
          o   DO  NOT execute a program unless you are absolutely sure
              it is safe.                                             
                                                                      
          o   If you do execute a program you are not sure about,  use
              a special test diskette containing only the unknown pro-
              gram.   Remove all other diskettes before the program is
              run.  When the program has completed, TURN  OFF  the  PC
              before  inserting  any  other  diskettes.    Boot from a
              diskette that is known to be clean.   Format or  discard


                                  Page 1





                  VACCINE -- The (c) Brain Virus Eradicator


              the diskette containing the unknown program.  NEVER test
              an unknown program on a system with a harddrive.        
                                                                      
          o   PCs  with  harddrives are especially vulnerable to a vi-
              rus.  In general, harddrive users  should  keep  unknown
              diskettes away from their PC.                           
                                                                      
          DETECTION                                                   
                                                                      
          If  the  directory of a diskette is viewed with the DIR com-
          mand and the first line returned is:                        
                                                                      
            Volume in drive D is  (c) Brain                           
                                                                      
          then the diskette is infected with the virus.  If you do not
          get this message, the diskette could still be infected  with
          the virus.                                                  
                                                                      
          If  you  suspect  a diskette or a PC to be infected with the
          virus, the DOS utility CHKDSK can  be  used  for  diagnostic
          purposes.    (CHKDSK.COM  is  a program on your original DOS
          diskette(s).  A disk containing CHKDSK.COM must  be  in  the
          default  drive before the command can be executed.)  Execute
          CHKDSK giving the drive specifier of the suspected  diskette
          as a parameter.  For example, the command:                  
                                                                      
            chkdsk b:                                                 
                                                                      
          will  analyze  the diskette in drive B and report the amount
          of memory contained in the PC.                              
                                                                      
          If the diskette has bad sectors, it may be infected with the
          virus. Bad sectors on a harddrive  are  not  as  conspicuous
          since harddrives commonly have bad sectors anyway.  However,
          if a diskette or harddrive develops bad sectors that did not
          previously  exist,  the likelihood of viral contamination is
          high.                                                       
                                                                      
          If the PC is infested with the  virus,  CHKDSK  will  report
          7168  bytes  less  memory than that actually in the machine.
          Remember that a machine known to contain 256K  for  example,
          should  actually  contain  256 X 1024 = 262,144 bytes as re-
          ported by CHKDSK.                                           
                                                                      
   * * * End of File * * *


   Consider the following situation:  you are at your PC, formatting some 
   disks, and all of them format fine.  Then, you use these disks for a 
   while, and all of a sudden this happens:







                                  Page 2





                  VACCINE -- The (c) Brain Virus Eradicator


   A>DIR B:

     Volume in drive B is  (c) Brain
     .
     .
     .

   You may think that DOS has gone crazy, but then you run a CHKDSK on 
   this disk:

   A>CHKDSK B:

   Volume  (c) Brain  created Jan 29, 1988 5:52p

      362496 bytes total disk space
       22528 bytes in 3 hidden files
      297984 bytes in 25 user files
        3072 bytes in bad sectors    <--|  Signs to watch out for...
       38912 bytes available on disk    |
                                        |
      254976 bytes total memory      <--|  (for 256K system, should read
      209296 bytes free                 |   262,144)

   Now, you know that your machine has 256K (262,144 bytes of total 
   memory), but that has decreased (by exactly 7168 bytes, or 7K).  Also, 
   there is 3072 bytes in bad sectors that was not there before?!?!  So, 
   you try your favorite disk utilities program to rename the disk to 
   something else...but it DOES NOT work!  The volume label continues to 
   stay on the disk!  

   Now, you are getting worried.  You do the same commands on your other 
   disks, and the same thing happens!  On some of the disks, the 3072 
   bytes in bad sectors is still there, but the  (c) Brain volume label 
   is not!  The only solution, after brooding about it, is to get your 
   master DOS disk, boot with that, then copy all of the files to another 
   disk, reformat the infected disk, and copy your files back.  This will 
   work, but it is very time consuming.  But, what if this virus got on 
   your Volkswriter disk?  Or your Lotus 1-2-3?  or other copy protected 
   program disks?  THIS WILL NOT WORK!  These disks are copy protected, 
   and even if you use a commercial disk copying program on them, the 
   virus will still be copied along with the disk!

   Now, you are getting frantic.  What is causing this problem?  A VIRUS 
   is causing all of your problems.  A computer virus is a program whose 
   only purpose is to spread itself all over (like biological viruses), 
   onto any disk it can get access to, and many are written to do 
   anything like erase files, crash hard drives, or just print a happy 
   face to the screen while doing something malicious at the same time, 
   after so many times you bootup with that disk, or run a certain 
   program x number of times, or on a certain date...the list could be 
   endless.  Then comes along VACCINE...  

   Viruses exist for Personal computers, mini-computers, and mainframe 
   computers.  They lay in wait for some event to happen, and then 
   good-bye data.  The above "virus" program, which has spread to many 


                                  Page 3





                  VACCINE -- The (c) Brain Virus Eradicator


   computer users in the Virginia Tech computing community, has 
   proliferated greatly since its first arrival.  The earliest known case 
   that I have heard is that the virus arriving was around the date of 
   January 20 or so (when I discovered it).  As far as I can tell, the 
   virus has not erased any files, disks, or anything else.  However, it 
   does spread itself like crazy, and it does have the potential to erase 
   entire disks.  However, from what I have seen, it only infected disks 
   formatted for 360K (normal configuration).  I have not seen it infect 
   3 1/2" drives, nor hard disks, but it very well could.  I have done 
   research into the virus, and have found out what basically makes it 
   tick.  Applying this knowledge has resulted in VACCINE, a program in 
   Turbo Pascal 3.02, that runs several checks to determine if the virus 
   has already installed itself in RAM, and tests a disk for the presence 
   of the virus.


   How to Use the Vaccine program:

   Program Requirements:

   An IBM-PC or 100% compatible with 64K of free RAM after DOS is loaded,
   One disk drive (two preferable),
   any graphics card and monitor, and
   DOS 2.0 or later (it might work on earlier versions, but I don't know
                     where to get them to test...)

   Just a note about entering in data:  A carriage return is NOT used 
   after typing in any letter in this program.  At all prompts, uppercase 
   and lowercase letters are equivalent (case is not important).  ONLY  
   5 1/4" disks are readable by this version.  Also, (a flaw that will 
   hopefully be fixed soon) any errors, such as Drive door open, or Disk 
   write protected, unless specifically checked for by the program, are 
   FATAL, and will result in a short message, and the DOS prompt will 
   reappear.  

   To run this program, type VACCINE at the DOS prompt.  Optionally, you 
   can add a drive letter (VACCINE b or VACCINE a:), and that drive will 
   be the default drive.  The program will ask you if you want to use 
   color.  If you are running the program on a composite monitor (like 
   the ones included with the PC Portables), type N.  Otherwise, type Y 
   (This combination works well with monochrome monitors and RGB 
   monitors.)  Then, you will be asked if you want help.  This is a 
   screen of general background information about the virus and the 
   program.  Press any key other than Y to skip it.  Next, the program 
   will detect if the virus has installed in RAM and is active.  If it 
   is, a message is printed to screen, urging you to boot with a clean 
   disk as soon as possible.  Although this program erases the virus from 
   disks, if the virus is in memory, the virus just reduplicates itself 
   after the program has finished.  For this reason, you must boot with a 
   clean disk (a friend's DOS, or the master DOS disk, or a backup to 
   your working disk (you do have one, don't you?  So you don't have to 
   go back to your master disk every time something goes wrong?)).  Then 
   run the program.  When the program tells you that you can safely go on 
   killing viruses, you are ready to do massive viral neutralization!



                                  Page 4





                  VACCINE -- The (c) Brain Virus Eradicator


   Now that you are past the preliminaries, you are the the heart of the 
   program.  The command line says press space bar for drive X (x is the 
   current or DEFAULT drive), a drive letter (A, B, or C if you have an 
   external 5 1/4" drive), or Q to quit.  The default drive is B, if no 
   drive was entered on the command line.  If you entered a valid drive 
   letter on the command line, that is made the default drive.  Whatever 
   drive letter is typed, that becomes the default drive for the next 
   pass.  

   Upon pressing the space bar, or any valid drive letter, you will next 
   see the disk type.  On the screen, you will see the disk description 
   (whether the disk is Single sided or Double sided, 8 or 9 sectors per 
   track, and the disk capacity that it is capable of with this 
   formatting).  Although I have only seen DS DD 9 sectors per track 
   disks with the virus on them, all types of 5 1/4" disk are tested 
   (160K, 180K, 320K, and 360K).  After this, a table will appear, with 
   the type of test on the disk that is being performed.  A summary of 
   the disk tests is shown below:

   1)  Boot sector:  The boot sector is the first program that is run 
       by the computer.  When you turn the computer on, this code is 
       loaded and run.  Normally, all the boot sector code does is load 
       in two hidden files (IBMBIO.COM and IBMDOS.COM) that contain the 
       actual Disk Operating System.  What the virus does is place its 
       own boot sector, which loads up the two hidden files, but it first 
       places its own virus code in memory first, and hides the memory 
       from DOS, so it is not overwritten.  This is where the virus takes 
       away the 7K of memory.

   2)  File Allocation Table:  A good way to think of the FAT is as a 
       pick-a-path adventure, except without the choices.  When you read 
       a page in this book, you look at the bottom of the page for a page 
       number to tell you where to read the next page of the book.  Most of 
       the time, you will just turn to the next page, but sometimes, you 
       may have to go forward or backward many pages.  Think of the disk 
       as the book, and the files as the different chapters.  What the 
       virus does is look for an three consecutive unused "pages" (disk 
       clusters), and marks them as being "bad" or unreadable, and then 
       puts itself in these "bad" clusters.  The virus prefers disk 
       clusters 55, 56, and 57, but it will search for a place for itself 
       if these clusters are not available.  If it does not find three 
       empty clusters on the disk, then it will not install itself.  

   3)  The Directory:  Going back to the book example, the directory is 
       simply the Table of Contents--it lists the name of the chapter 
       (the file name), and where it begins (the starting cluster).  
       There is a special type of file called a volume label, which would 
       correspond to the title of the book.  What the virus does is place 
       its own "title" on the disk if there wasn't one before, and if 
       there is one, don't put it on.  If the third file name entry is 
       available, use that for the volume label, otherwise search upward 
       for an empty or unused directory slot.  





                                  Page 5





                  VACCINE -- The (c) Brain Virus Eradicator


   If the outcome of any one of these test is positive, (YES blinks on
   the screen) the disk has the virus on it.  You are asked if you want 
   to remove the virus.  Type in Y to remove it, any other key to 
   keep it.  Occasionally, you may be asked to insert a valid DOS boot-up 
   disk.  When this happens (it should not be very often), the computer 
   will beep at you (to get your attention), and just follow the 
   directions on the screen, and switch disks when prompted.  That all 
   there is to it.  You have extinguished the virus!  Now, you can switch 
   disks and press the space bar to perform VIRUS ANNIHILATION!

   ======================================================================

   Revision list:

   Version (unnumbered)
   February 16:   
        Distributed to one or two people--works fine, but no color, no 
   docs, bad layout of test results.

   Version 1.01
   February 19, 1988
        Posted to VTBBS, in Blacksburg, Virginia (961-7498)
   Features added:  Optional color, and much improved user interface, user 
   needs to press drive letter every time for each new disk--docs 
   are inconsistent in places.

   Version 1.10
   February 21, 1988
        Posted to VTBBS--Now, only one keypress is needed for each 
   response--added code to detect virus in RAM -- tried to simply re-route 
   interrupt $6d back to $13 (the original contents of the vector), but 
   got General Failure Errors after this patch was done...space bar allows 
   automatic use of the last drive tested--Documentation is now augmented 
   with descriptions of what FAT, Directory, and boot sector are--footers 
   and headers are put on--the "official" release, barring some unknown 
   disaster.
     
   **********************************************************************

   Permission is granted to post this file on Bulletin Board 
   Systems.  Please feel free to give this program out to friends, upload 
   to bulletin boards, or what ever.  If you find this program useful, or 
   have donations/comments/questions/bug reports or whatever, please send 
   them to

   Duane Brown                         Duane Brown
   143 Major Williams         or       100 Pewter Lane
   Virginia Tech                       Stafford, VA 22554
   Blacksburg, VA 24061








                                  Page 6
