Next: Inoculation Up: Other Tools Previous: Other Tools

System Utilities

Some viruses can be detected or removed with basic system utilities. For example, most DOS boot sector infectors and some Macintosh viruses can be removed with system utilities. System utilities can also be used to detect viruses by searching for virus signatures. These tools have a rather limited focus, though.

Viruses that can be disinfected ``by hand'' are generally the extremely well-behaved, highly predictable viruses that are well understood. Such viruses are the exception, not the rule. There are many more viruses that cannot be disinfected with these tools.

Where possible, disinfection with system utilities will produce dependable results. A reasonable amount of knowledge is required about the computer system and the virus itself, though. This technique can also be very laborious if a large number of systems are infected.

System utilities are an inefficient means of detection. Generally, only one signature can be handled at a time. This might be a useful technique if a specific virus is to be detected.

Summary

Accurate removal by system utilities is frequently impossible. Certain classes of viruses (e.g., overwriting viruses) always damage the executable beyond all hope of repair. Others modify the executable in rather complicated ways. Only viruses that are extremely well-behaved can be disinfected every time. Similarly, detection with system utilities has limited application.



Next: Inoculation Up: Other Tools Previous: Other Tools


konczal@csrc.ncsl.nist.gov
Fri Mar 11 21:26:02 EST 1994