Documente Academic
Documente Profesional
Documente Cultură
6V80
Copyright (C) 1990, 1991 by McAfee Associates.
All rights reserved.
Documentation by Aryeh Goretsky.
McAfee Associates
4423 Cheeney Street
Santa Clara, CA 95054-0253
U.S.A
TABLE OF CONTENTS:
SYNOPSIS . . . . . . . . . . . . . . . . . . . . . . . . . . .2
- What CLEAN-UP is, system requirements
AUTHENTICITY . . . . . . . . . . . . . . . . . . . . . . . . .2
- Verifying the integrity of CLEAN-UP
WHAT'S NEW . . . . . . . . . . . . . . . . . . . . . . . . . .3
- Features, new viruses added in this release
OVERVIEW . . . . . . . . . . . . . . . . . . . . . . . . . . .3
- Detailed description of CLEAN-UP
OPERATION. . . . . . . . . . . . . . . . . . . . . . . . . . .4
- How to use CLEAN-UP
EXAMPLES . . . . . . . . . . . . . . . . . . . . . . . . . . .6
- Samples of frequently-used options
REGISTRATION . . . . . . . . . . . . . . . . . . . . . . . . .6
- How to register CLEAN-UP
TECH SUPPORT . . . . . . . . . . . . . . . . . . . . . . . . .7
- Information you should have ready when calling
Page 1
Page 2
SYNOPSIS
CLEAN-UP (CLEAN) is a virus disinfection program for IBM PC
and compatible computers. CLEAN-UP will search though the
partition table, boot sector, or files of a PC and remove a virus
specified by the user. In most instances CLEAN-UP is able to repair
the infected area of the system and restore it to normal usage.
CLEAN-UP works on all viruses identified by the current version of
the VIRUSCAN (SCAN) program.
CLEAN-UP runs on any PC with 256Kb and DOS 2.00 or above.
AUTHENTICITY
CLEAN-UP runs a self-test when executed. If CLEAN has been
modified in any way, a warning will be displayed. The program will
still continue to remove viruses, though. If CLEAN reports that
it has been damaged, is recommended that a new, clean copy be
obtained.
CLEAN-UP is packaged with the VALIDATE program to ensure the
integrity of the CLEAN.EXE file. The VALIDATE.DOC instructions
tell how to use the VALIDATE program. The VALIDATE program
distributed with CLEAN-UP may be used to check all further versions
of CLEAN.
The validation results for Version 80 should be:
FILE NAME:
SIZE:
DATE:
FILE AUTHENTICATION
Check Method 1:
Check Method 2:
CLEAN.EXE
119,999
06-24-1991
F8AE
05DD
Page 3
WHAT'S NEW
The Empire, Form, Loa Duong, Michaelangelo, Nomenclature,
Tequila and V-801 viruses have been added to the list of viruses
that can be successfully removed.
The /REPORT option now displays version number, options used,
date and time, and cleaning results.
The Loa Duong virus is a memory-resident floppy disk and hard
disk boot sector infector. It is named after a Laotian funeral
dirge that it plays after every 128 disk accesses.
The Michelangelo is a floppy disk boot sector and hard disk
partition table infector based on the Stoned virus. On March 6,
Michelangelo's birthdate, it formats the hard disk of infected
PC's.
The Tequila virus was sent to us from the United Kingdom but
originates in Switzerland. It is a memory-resident multipartite
virus uses stealth techniques and attaches to the boot sector of
floppies, partition table of hard disks, and .EXE files. It
contains messages saying "Welcome to T.TEQUILA's latest
production.", "Loving thoughts to L.I.N.D.A", and "BEER and TEQUILA
forever !"
The V801, Form, Empire and Nomenclature viruses are older
viruses that have been reported with increasing regularity in
Canada and England, respectively.
Please refer to the enclosed VIRLIST.TXT file for a short
description of the new viruses. For a more complete description,
please refer to Patricia Hoffman's VSUM listing.
OVERVIEW
CLEAN-UP searches the system looking for the virus you wish
to remove. When an infected file is found, CLEAN-UP isolates and
removes the virus, and in most cases, repairs the infected file and
restores it to normal operation. If the file is infected with a
less common virus, CLEAN-UP will then display a warning message and
prompt the user, asking whether to overwrite and delete the
infected file. Files erased in such a manner are non-recoverable.
Verify the suspect virus infection with the VIRUSCAN program
before running CLEAN-UP. VIRUSCAN will locate and identify the
virus and provide the I.D. code needed to remove it. The I.D. is
displayed inside the square brackets, "[" and "]." For example,
the I.D. code for the Jerusalem virus is displayed as
"[Jeru]". This I.D. must be used with CLEAN-UP to remove the
virus. The square brackets "[" and "]" MUST be included.
Page 4
1260
Air Cop*
Azusa
Dark Avenger*+
Empire*
Flip*+
Jerusalem*+
Lazy
Mardi Brothers
New Jerusalem+
Ping Pong*
Slow+
Suriv03+
V800
Violator*
15xx*+
Alabama+
Beeper
DataLock+
Fellowship+
Form
Joshi
Liberty+
Michelangelo
Nomenclature
Plastique*+
Stoned*
Taiwan 3+
V-801
Whale*+
disk, run the VIRUSCAN program on any floppies that may have been
inserted into the infected system to determine if they have been
infected.
CLEAN-UP will display the name of the infected file, the virus
found in it, and report a "successful" disinfection when the virus
is removed. If a file has been infected multiple times by a virus
(possible if the virus does not check to see if it has already
attached to a file) than CLEAN-UP will report that the virus has
been removed successfully for each infection.
Page 5
Page 6
EXAMPLES
The following examples are shown as they would be typed in on
the command line.
CLEAN C: D: E: [JERU] /A
To disinfect drives C:, D:, and E: of the Jerusalem
virus, searching all files for the virus in the process
CLEAN A: [STONED]
To disinfect floppy in drive A: of the Stoned virus
CLEAN C:\MORGAN [DAV] /A
To disinfect subdirectory MORGAN on drive C: of the Dark
Avenger, searching all files for the virus in the process
CLEAN B: [DOODLE] /REPORT C:YNKINFCT.TXT
To disinfect floppy in drive B: of the Yankee Doodle
virus, searching all files in the process, and creating
a report of disinfected files named YNKINFCT.TXT on drive
C:
REGISTRATION
A registration fee of $35.00US is required for the use of
VIRUSCAN by individual home users. Registration is for one year
and entitles the holder to unlimited free upgrades off of McAfee
Associates BBS. When registering, a diskette containing the latest
version may be requested. Add $9.00US for diskette mailings. Only
one diskette mailing will be made.
Registration is for home users only and does not apply to
businesses, corporations, organizations, government agencies, or
schools, who must obtain a license for use. Contact McAfee
Associates for more information.
Outside of the United States, registration and support may be
obtained from the Agents listed in the accompanying AGENTS.TXT
file.
Page 7
TECH SUPPORT
In order to facilitate speedy and accurate support, please
have the following information ready when you contact McAfee
Associates:
-