Mail Archives: djgpp/2000/03/15/20:55:58
On Wed, 15 Mar 2000 11:04:21 +0200 (IST), Eli Zaretskii
<eliz AT is DOT elta DOT co DOT il> wrote:
>On Wed, 15 Mar 2000, nimrod a. abing wrote:
>
>> I was just curious about this. If the code
>> segment is not writable, it seems to imply some
>> sort of immunity to viruses for DJGPP programs.
>
>The viruses don't attach themselves to the protected-mode code produced
>by DJGPP, they attach themselves to the short DOS stub prepended to DJGPP
>programs. And since the COFF header follows that short stub, the virus
>has good chances overwriting the COFF magic signature, which will cause
>the startup code refuse to run the infected program.
>
>...
>
>The above-mentioned features do allow an early detection of an
>infection. But more importantly, the viruses have
>all but abandoned DOS programs as their target.
Except the master boot record.
>They now concentrate on Windows programs, so
>any DOS program is probably more safe.
Would the features allow early detection of an infected
RSXNTDJ program?
--
Damian Yerrick http://yerricde.tripod.com/
Comment on story ideas: http://home1.gte.net/frodo/quickjot.html
AOL is sucks! Find out why: http://anti-aol.org/faqs/aas/
View full sig: http://www.rose-hulman.edu/~yerricde/sig.html
This is McAfee VirusScan. Add these two lines to your .sig to
prevent the spread of .sig viruses. http://www.mcafee.com/
- Raw text -