VIRUS-L Digest Wednesday, 16 Nov 1994 Volume 7 : Issue 94 Today's Topics: Re: Internet Staging Publishing authentication & validation data Re: Netcom distributing Viruses Virus Laws Newsletters Or Magazines Viruses via usenet! alt.comp.virus Re: Recommendations (?) on OS/2 Scanner/Disinfector (OS/2) Hardware trojan horse (Mac) Softwindows on PowerMac (PC) (Mac) Virus (?) on PC - new user needing help (PC) Virus identification? (PC) InVircible, a new approach to AV (fwd) (PC) Re: KAOS4 (PC) ZIFF Verlag (PC) Re: Forms Virus (PC) Vacsina v 5 ?!? Info wanted!!! (PC) Die_Hard virus, need information (PC) Re: Exebug apparently surviving boot (PC) Differences between McAfee products? (PC) VLamiX.1? (PC) Signalit PT virus maybe ? (PC) Possible Variant of Jumper.B (PC) Re: Virus named Jack Ripper (PC) Re: DOOM II (PC) THANKS!! Re help with FORM (PC) Re: CMOS virus/ answer to questions (PC) Re: stoned - Monkey (PC) Unknown Virus?? (PC) Removing boot sector virus (CANSU/V-Sign) (PC) Natas Virus ? (PC) NATAS (PC) Is Possible eliminate the 1099 (PC) HELP! How do I fix the B1 virus? (PC) birdlike chars in windows (PC) F-Prot Information question (PC) Mouse ports (PC) Looking for NLM scanners (PC) Dr. Solomon Drivers (PC) What can a virus do ? I need HELP! Please (PC) NCSA hasn't heard of Viking virus (PC) FLU-SHOT (PC) Best form of Virus Protection? (PC) INFO WANTED: Junkie.Boot virus... (PC) PC drops out of Windows. Virus? (PC) Memory scanning (PC) invb601a.zip - The InVircible Anti-Virus Expert System v6.01A (PC) VIRUS-L is a moderated, digested mail forum for discussing computer virus issues; comp.virus is a gatewayed and non-digested USENET counterpart. Discussions are not limited to any one hardware/software platform - diversity is welcomed. Contributions should be relevant, concise, polite, etc. (The complete set of posting guidelines is available by FTP on CORSA.UCR.EDU (IP number 138.23.166.133) or upon request.) Please sign submissions with your real name; anonymous postings will not be accepted. Information on accessing anti-virus, documentation, and back-issue archives is distributed periodically on the list. A FAQ (Frequently Asked Questions) document and all of the back-issues are available by anonymous FTP on CORSA.UCR.EDU. Administrative mail (e.g., comments, suggestions, beer recipes) should be sent to me at: krvw@ASSIST.MIL. All submissions should be sent to: VIRUS-L@Lehigh.edu. Ken van Wyk ---------------------------------------------------------------------- Date: Mon, 07 Nov 94 12:44:39 -0500 From: padgett@goat.orl.mmc.com (Padgett 0sirius) Subject: Re: Internet Staging aisg@gate.net (Advanced Information Systems Group) writes: > Is there any software available to scan for viruses as they come >into a Internet gateway machine? Many people are concerned about this but the bottom line is that it is an enormously complex operation. Right now the only way this can happen is via file transfer (FTP/Gopher/Mosaic) which can transfer either binaries or ASCII or E-Mail (typ SMTP) which is generally only reliable for ASCII. The bottom line is that only rarely will a file be transferred as a pure executable - more likely it will be archived. Secondly, the file (unless it is short) is not going to come through in one piece, rather it will be a series of packets that may or may not be interspersed with packets for other destinations or processes on the same platform. So 1) You are going to have to recognize any time a file comes in (and I just received a rather large .UUE by Telnetting to a remote site, reading my mail there, and opening a "capture" file for the .UUE as it displayed). 2) When you recognize a file coming in, you will have to create a buffer to hold the file until you have the whole thing. 3) You will have to determine what the file is. If UUENCODED, it will have to be decoded. If ZIPped, it will have to be unzipped and it can be any combination including those for other platforms e.g. TAR for UNIX boxes (and I have received PC files that were TARred or GZIPped) or STUFFIT for Macs or DIET or ARJ or a complete STACed volume image, or TD0 or SENDDISK or ... Just picture a MAC disk with STUFFIT files that was captured on a PC by MACINDOS, GZIPped, UUENCODED and sent. 4) Once the programs are extracted, you will need to figure out what platform the files are intended for (see above). 5) Now you can invoke a scanner for the appropriate platform. Now 1 & 2 are not too bad and once you get that far, 4 & 5 are straightforward but 3 is a real bear. It *could* be done (and some people may claim to have done so but watch out for the smoke & mirrors). Of course, if you want to limit your search to the likely suspects (assume only uuencode & zip are used, executables will be named .COM or .EXE, and only consider files for the PC) something can be done. Not much IMHO but something. A. Padgett Peterson, P.E. Cybernetic Psychophysicist We also walk dogs PGP 2.7 Public Key Available ------------------------------ Date: Tue, 08 Nov 94 04:37:49 -0500 From: Zvi Netiv Subject: Publishing authentication & validation data Cross-posted from Fidonet. -=> Quoting Bill Lambdin to Jeff Cook <=- BL> Here is why I feel that your decision against CHK-SAFE is wrong. [ ... ] BL> The A-V developers shouldn't be distributing files in archives to BL> verify authenticity. [ ... ] BL> Who should be distributing messages to verify authenticity of A-V BL> software? BL> A: Someone that A-V developers know and send new versions of A-V BL> software to. BL> B. Someone that has access to lots of A-V conferences. [ ... ] BL> 1. 8+ A-V developers or agents for the developer upload A-V software BL> to the Metaverse Anti-Virus BBS. [ ... ] BL> 2. I post CHK-SAFE values to 10+ networks for users. [ ... ] BL> No one is making this information available to the public. So I am. Jeff, It seems that Bill, and quite many posters on this echo, misunderstand the legal aspects of publishing authentication data. Let me say that publishing UNAUTHORIZED authentication data is not only wrong, but is also unlawful, according to national and international laws and treaties on copyright. Authentication data is the legal equivalent of a signature. According to copyright treaties, this right is reserved to the author himself. Publishing unauthorized authenticity data is not only a violation of copyright, but also interferes with authors' freedom and sovereignty on their work. Unauthorized authentication data imposes restrictions on the author, such as the right to freely modify his work. Such published data will imply that perfect and legal material, modified by the author, may be labeled as forged - since it does not fit the "authentication data". As I understand, Bill Lambdin did not obtain authors' permission to publish his CHK-SAFE data for their programs. It would be unlawful to let him continue the publishing of these values. For the record: I didn't grant anybody the right to publish whatever _separate_ authentication data for InVircible. All authentication data for IV should be kept attached to the archived package itself. Best regards, Zvi Netiv, InVircible ------------------------------ Date: Tue, 08 Nov 94 19:51:22 -0500 From: bradleym@netcom.com (Bradley) Subject: Re: Netcom distributing Viruses The Radio Gnome (V2002A@VM.TEMPLE.EDU) wrote: > >From: olpopeye@ix.netcom.com (Walter Murdock) > >And guns aren't dangerous. Unless you do something stupid > >with them. > Neither are idle viruses. What guarantee can Netcom give us that > any downloadable viruses will *remain* idle and unmutated? Netcom takes no responsibility for what is in the /pub area of it's FTP site. It's all user run. But I'm sure if they did run it they would take as much responsibility as most FTP sites... NONE. For all you know that nifty new file you got off of your favorite FTP site is a trojan. And just that happened recently. Did anyone sue the archive? > OK, I'll try a new tack... how would you feel if Netcom made > all the long distance touch tone diagnostic, technician and 'coin drop' > codes available? > The phone providers have enough trouble with phreakers as is, why > make it more difficult for them by spreading knowledge that may be > interesting, but potentially dangerous? Well, actually I also have some phreak and hack stuff as well. So the chances are fairly good that I have some of that stuff. And if I don't have it, I'd be more than willing to carry it. :) Netcom has 30,000 users. There are bound to be people that have ideas and interests that others don't like. But Netcom has made it policy to not let people's opinions accect thier users. There's even a user with Nazi material that is allowed to stay. I'm sure in an Islam country he would be dead by now, and in Germany he'd be in jail. But his network access is in America where it's not illegal. Bradley - -- bradleym@netcom.com finger for PGP public key Hayward, CA ------------------------------ Date: Thu, 10 Nov 94 01:42:24 -0500 From: ncoe7@aol.com (NCOE7) Subject: Virus Laws I am looking for sources of information concerning computer virus laws in the United States. Scott ------------------------------ Date: Thu, 10 Nov 94 06:55:58 -0500 From: Finson Srl Subject: Newsletters Or Magazines We are looking for magazines or newsletter worldwide specialised in Virus and Antivirus arguments. Could anybody help us with adresses of publishers? Thank a lot! Massimo Soncini ------------------------------ Date: Fri, 11 Nov 94 00:36:34 -0500 From: jrice@pluto.pomona.claremont.edu Subject: Viruses via usenet! alt.comp.virus What is the situation with the group alt.comp.virus? Today I have seen the code of no less than 4 viruses posted in the group, with no signs that this will stop. How can this be permitted, being, as it is, illegal in quite a few countries? Let's be honest, these people are not researchers....so great, we've got a virus-exchange center in Usenet. Jeffrey Rice Virus Protection Office of Information Technologies Pomona College [Moderator's note: alt.comp.virus, an unmoderated USENET group, is in no way affiliated with comp.virus or VIRUS-L. I suggest you ask the folks on alt.comp.virus.] ------------------------------ Date: Tue, 08 Nov 94 20:02:45 -0500 From: Bruce Owens Subject: Re: Recommendations (?) on OS/2 Scanner/Disinfector (OS/2) David W. Loveless writes: >Based on your personal experience can you recommend any particular OS/2 virus >scanner and/or disinfector? I've used IBM AntiVirus/2 for OS/2, and it seems to be satisfactory. I think that it will detect but cannot disinfect the Monkey virus, but it does detect and kill a great many others. There's an IBM AntiVirus center, but I don't know the number off the top of my head. You can find it by calling 800-426-3333, I believe. ------------------------------ Date: Wed, 09 Nov 94 16:05:45 -0500 From: fixer@faxcsl.dcrt.nih.gov (Chris Driving in the Rain Tate) Subject: Hardware trojan horse (Mac) I don't see this mentioned in the FAQ, and I don't see any articles about it on the newsgroup, so I think I'll bring up the experience I had this past weekend. Recently I purchased a Macintosh, piecemeal (CPU, monitor, keyboard, CD-ROM drive all separately). I then noticed one day that without any intervention on my part, the phrase "welcome datacomp" appeared in the body of a file I was editing. I did the usual - reboot without any system extensions, etc. - and the problem remained. After a (longish) wait, the words "welcome datacomp" would appear, as though they had been typed on the keyboard. I actually watched this happen. I consulted with John Norstad, the author of the Macintosh "Disinfectant" antiviral program, and he informed me that yes, he and his team had indeed heard of this problem before. It's a practical joke incorporated into the ROMs of some third-party keyboards. !! I noticed this purely by chance; I couldn't figure out why I had gotten a confirmation dialog when closing a file that I *knew* I had saved a while earlier. But I can easily imagine the problem going unnoticed, and the spurious text being incorporated into a "final draft" of some important document, with unfortunate consequences, etc. Unlikely, but certainly possible. My big question at this point is why nobody seems to have documented the problem? My keyboard (since replace with another brand) was made by a company called "Sicon" - at least, that was the name on the invoice from the store where I purchased it. I couldn't find a manufacturer's name on any part of the actual keyboard, its packing materials, or the enclosed documentation! Clearly, this brings up a raft of other questions - are all Sicon keyboards affected? Is it one particular batch of ROMs that are "bad," or all of the ones used by Sicon? Did Sicon develop the keyboard's on-board code, or did they license it? If it's licensed, might other brands have the same Trojan Horse embedded within? And so forth... And what *other* sorts of intelligent peripherals, on what platforms, might be subject to this sort of abuse? Disk controllers? Other Apple Desktop Bus devices, of any description? *Any* add-in card, for any number of platforms? It's bad enough having to worry about software viruses, but how does one approach the problem of having to detect malicious (or even simply "deliberately unreliable") hardware? - -------------------------------------------------------------------- Christopher Tate | "I never thought of surgery as 'editing fixer@faxcsl.dcrt.nih.gov | a person' before...." eWorld: cTate | -- Mark Linton (mhl@icf.hrb.com) ------------------------------ Date: Thu, 10 Nov 94 15:30:53 -0500 From: Bert.Martin@UAlberta.CA (Bert Martin) Subject: Softwindows on PowerMac (PC) (Mac) Is anyone running SoftWindows 6.22 on a PowerMac 7.12? Do you have it setup with F-PROT 2.14? I have the above configuration and would like to know how you have it setup. I get the feeling I need some fine-tune tweaking cause it just reports(falsely) the MONKEY virus. When I restart the system F-PROT doesn't anything. Need any further info? Please ask. Thanks. Bert. ================================= Bert Martin # BOOT HUMOR: # Microsystems # # University of Alberta # keyboard error # (403)-492-5356 # Press F1 to RESUME # ================================= ------------------------------ Date: Mon, 07 Nov 94 02:39:42 -0500 From: ehorlait@ee.uts.edu.au (Eric Horlait) Subject: Virus (?) on PC - new user needing help (PC) I am a user of PC with Linux. I got a problem that seems to be related with viruses. Here is the description: When booting (cold start) with a Linux Hard Disk: Loading Linux.... Uncompressing Linux .... crc error - -- system halted When booting from a Linux Floppy disk, same result. When booting from an Ms-dos floppy disk: Starting MS-DOS . Invalid COMMAN.COM .. This last try was made with a Microsoft distribution disk, write protected. This floppy was working before and after going into my PC, ... but not in it. Is it a known problem. If it is I apologize in advance, but I am new in using PCs. As a complement I can add that two different machines were involved in the same illness EXACTLY at the same time. ------------------------------ Date: Mon, 07 Nov 94 03:43:55 -0500 From: eh@artemis.ibp.fr (Eric Horlait) Subject: Virus identification? (PC) I got a virus on my PC that affect the boot process. It is now impossible to boot either from a HD or a FD, whatever system I use. Using DOS, the message is INVALID COMMAND.COM Using Linux, the message is crc error - -- system halted I tried to use "fresh" disks, for example an official Microsoft distribution disk (write protected) and the result is the same. This disk (the Microsoft one) was running before and after the test on other machines. As a conclusion, I ca add that two machine had the same problem at approximately the same time Nov, 7th, 1994, 1:15pm. Could anybody help? PS: In case of direct answer, please use the e-mail address: Eric.Horlait@masi.ibp.fr ------------------------------ Date: Mon, 07 Nov 94 06:30:42 -0500 From: Zvi Netiv Subject: InVircible, a new approach to AV (fwd) (PC) From: annie To: ila2007@zeus.datasrv.co.il Subject: InVircible 6.01 Hello Martin, > Is InVircible 6.01 able to disinfect files that are infected by a new > polymorphic virus and these files are not secured before virus infection? ZN>Version 6.01 has the new IVX correlator. It will let you spot and ZN>_neutralize_ infected files that were not secured, but of course not to ZN>restore them. Files that were secured, even with in the Sentry mode, can ^^^^^^^^^^^^^^^^^^^^^^^^^ ^^^^^^^^^^^^^^^^^^^^^^^ ZN>be fully recovered by IV. Provided the virus is not an overwriting one, ^^^^^^^^^^^^^^^^^^^^^^^^^ ZN>of course. Do you mean that the file restorations can be done by IV in Sentry mode? > Thank you for your attention. ZN>You are welcomed. Just curious, where from have you heard or seen ZN>InVircible? I D/L the freeware version of IV 6.01 from a mirror site of SimTel and installed it on my hard disks last month. ZN>Is there any particular virus involved? Many times, apparently heavy ZN>polymorphic viurses, such as Natas, are quite easily removed by ZN>algorithmic metods. I'd used IVX to spot some of the infected files ( <3 ) on my HDs. (They were detected by integrity checkers)These files were infected by a polymorphic virus written by a local virus writer. (there are more and more local polymorphic viruses found in Hong Kong)IVX can locate all of them by setting the correlation theshold to 7% (including some non-infected files) I've emailed an uuencoded virus sample to you. Can you tell me whether the file can be disinfected ? BTW, is there any generic cleaning method (and program) to remove non-overwriting file viruses? (the infected files are not secured before virus infection) Regards, Martin Ho From: Zvi Netiv To: annie Subject: Re: InVircible 6.01 Hello Martin, >Do you mean that the file restorations can be done by IV in Sentry mode? No, the restoration needs the registration. But it uses the signatures established with the Sentry. Therefore, any file that was secured before the infection can be restored after registering IV. For the moment, I see that you managed with IVX to clean the system. :-) As you stated, there are now many polymorphic viruses around, and with large scale infections, it may be worth registering IV. Thanks for the sample, I'll have a look at it, as for my curiosity. Just don't expect that I'll make an effort to remove it by the scanner, since as a matter of policy - we prefer that users install IV in Sentry mode, and either manage to clean their system the long way by IVX (free), or the better way, by generic recovery of the affected files by registering IV and using the IVB restore feature. Best regards, Zvi Netiv, InVircible Available for ftp from: ftp.netcom.com/pub/antivir/invircible/invb*.* Simtel mirror: oak.oakland.edu/pub/msdos/virus/invb*.* , Author's ftp: ftp.datasrv.co.il/pub/user/netz/invb*.* ------------------------------ Date: Mon, 07 Nov 94 07:14:35 -0500 From: axelsch@zedat.fu-berlin.de (Axel Schmidt) Subject: Re: KAOS4 (PC) marc@sisyphus.cl-ki.uni-osnabrueck.de (Marc Ronthaler) writes: >From: marc@sisyphus.cl-ki.uni-osnabrueck.de (Marc Ronthaler) >Subject: KAOS4 (PC) >Date: 4 Nov 1994 10:55:06 -0000 >hello! >does anybody know what the KAOS4 virus does to a computer ? >is it harmfull ? i only know that it infects EXEs and COMs. >but what happens when it's getting active ?? >thanks for any information KAOS4 is a non-memory resistant parasitic virus that searches for *.com and *.exe and writes itself at their ends. It contains the internal text string KAOS4 / Kohntark. (information drawn from AVP 2.1) The only thing the virus seems to do is to replicate. regards, Axel ************************************************************** Axel Schmidt - Free University of Berlin axelsch@zedat.fu-berlin.de - FidoNet 2:2410/121.21 CompuServe 100342,3245 send a mail with subject "pgpkey!" to have my pgp-key sent to you automatically ************************************************************** ------------------------------ Date: Mon, 07 Nov 94 08:13:35 -0500 From: claude@bauv111.bauv.unibw-muenchen.de (Claude Frantz) Subject: ZIFF Verlag (PC) I got an information saying that the german ZIFF Verlag has distributed a diskette or CD-ROM including a virus in the boot sector. Is this information true ? Please give me more information on this subject. Thanks. - -- Claude F. (claude@bauv106.bauv.unibw-muenchen.de) This message may contain opinions which are not shared by my employer. The facts can speak for themselves. ------------------------------ Date: Mon, 07 Nov 94 08:29:28 -0500 From: dolson@shore.net (Don Olson) Subject: Re: Forms Virus (PC) hatcher@mn.ecn.purdue.edu (Stephen D Hatcher) wrote: > In addition to other's postings, I too have been effected by > this virus that seems to attack the Windows 32-bit disk controller > device. This is my first virus. I have attempted to remove it > using MSAV to no avail. If somone has information on how to > safely remove the virus, please either post here or e-mail > me with that information. I am greatly appreciative!! > We have had the Form virus meandering around the lab on floppies for months, some pc's with hd symtoms, some without. I have found both MSAV and NAV3.0 both equally able to clean infected floppies and pc's. NAV comes with Norton Desktop and monthly updates are available for NAV at ftp.symantec.com If you can take the memory hit, NAV's tsr is a nice feature and has screamed at dozens of Form infected floppies that have been accessed by my office pc. I also run it home and have never been infected because the NAV tsr complains before infection can occur. - -- So, this is a SIG, eh? | It is better to have a gun and not need it, | than to need a gun and not have it. ------------------------------ Date: Mon, 07 Nov 94 10:45:02 -0500 From: G.F.Vocking@kub.nl (VOCKING G.F.) Subject: Vacsina v 5 ?!? Info wanted!!! (PC) Hi all, Today we encountered the Vacsina virus (v5) on our WAN... All in all it has temporarily infected over 2000 PC's I guess, since it klung to MAP.EXE in the SYS:PUBLIC directory of over 20 Novell Fileservers... After this day of hard and boring work to get rid of it, we wonder: 1. What does it do anyway ? 2. How come it infects files and gets away with it (since some virusscanners recognize the loader of Vacsina but not other files which have been changed by it!?) ? 3. Recommendations for (better) virusshields are wanted ! Greets, Gustaaf **=**-**=**-**=**-**=**-**=**-**=**-**=**-**=**-**=**-**=** ** Gustaaf Vocking ** G.F.Vocking@kub.nl ** ** Systemadministrator IVA ** Voice@Work: +31-13-662443 ** ** Student Econometrie&BIK ** Voice@Home:+31-13-635739 ** **=**-**=**-**=**-**=**-**=**-**=**-**=**-**=**-**=** ------------------------------ Date: Mon, 07 Nov 94 11:50:59 -0500 From: devries@inter.nl.net (J.H.I. de Vries) Subject: Die_Hard virus, need information (PC) Hi World, maybe someone has more information. We recently came across the virus "Die_Hard". This virus that expands the exe files with 4000 bytes, is detected with the latest version of f-prot (2.14) but no further information is available in f-prot. Is there someone out there who has some more information about this virus? Any help would be appreciated. Thanks in advance, Gerard de Jong PowerFax NL. ------------------------------ Date: Mon, 07 Nov 94 14:30:48 -0500 From: jmccarty@spd.dsccc.com (Mike McCarty) Subject: Re: Exebug apparently surviving boot (PC) Iolo Davidson wrote: ) A.APPLEYARD@fs1.mt.umist.ac.uk "ANTHONY APPLEYARD" writes: ) )> mshmis@world.std.com (MSH MIS) wrote in #85 (Subject: Exebug (PC)):- )> )> I have recently found Exebug on a number of computers and it )> seems difficult to eliminate. Yesterday I booted from a clean )> write protected boot diskette which contains Mcafee's latest )> anti-virus software. The message on the screen said that traces )> of exebug were found in memory. How could this be? )> )> > "I booted" hereinabove: warm boot (ctrl-alt-del, or RESET )> > button) or cold boot (switch the PC off and on)? Some viruses )> > can survive warm boot in memory, I suspect, as warm boot is not )> > a complete re-zeroing and reinitializing of everything. And some )> > viruses can trap ctrl-alt-del and fake a warm boot. In finding )> > and removing viruses, always COLD boot. ) )But Exebug can spoof a cold boot. It forces the computer to )start booting from the hard disk even though you think it it )booting from the floppy. Once it has loaded and run the )partition sector (MBR), getting the virus into memory and active, )then it continues the boot from the floppy so you are none the )wiser. For this reason, anti-virus scanners have to be able to )detect Exebug in memory. Are you claiming that if I put a clean bootable floppy in the A drive and power down the computer and then power it up that EXEBUG can survive that? Mike - ---- char *p="char *p=%c%s%c;main(){printf(p,34,p,34);}";main(){printf(p,34,p,34);} ------------------------------ Date: Mon, 07 Nov 94 14:35:12 -0500 From: etate@mcl.bdm.com (C. Emory Tate) Subject: Differences between McAfee products? (PC) Could someone please enlighten me as to the difference between McAfee's VirusScan 117 products and their 2.1.0e products? - -- C. E. Tate snailmail: BDM Federal, Inc. 1501 BDM Way, McLean, VA 22102 ____________________________________________________________ Happiness is a straight yaw string and an 800ft/min thermal. ------------------------------ Date: Mon, 07 Nov 94 14:53:34 -0500 From: jmcgrath@upei.ca (J McGrath) Subject: VLamiX.1? (PC) This weekend I was hit by a virus which seemed to have come from nowhere. I was working along just fine when all of a sudden I couldn't load Windoz and then when I rebooted, VirStop told me that I was infected! I ran F-Prot 2.14c and it told me that I was COMPLETELY infected with the VLamiX.1 virus. It knew what it was, so did McAfee's Scan, but neither of them could save me. It was everywhere on my system, infecting 90-95% of all my EXE files, but not COM files. Does anyone have any information on this virus? Is it time/date activated? Thanks! j - ---------------------------- J McGrath 1 902 566 0552 University of Prince Edward Island Computer Services User Support ------------------------------ Date: Mon, 07 Nov 94 15:07:31 -0500 From: Gary Novay Subject: Signalit PT virus maybe ? (PC) Hello, I recently purchased a Quantex Pentium 90 multimedia system. It consists of 16 meg of ram, 730 meg WD E-IDE drive, a sound card and speakers. fax/modem Colorado 250 tape backup, 5 1/4" and 3 1/2" floppies Double speed Sony CD-ROM DOS V.6.2 and Windows for Workgroups and lots of windows software VSAFE is part of my autoexec.bat file I tested the machine and it's vast selection of pre-installed software for 2 days, with no problems. My son used the a: drive to access a wordperfect document from within windows that he brought from school. The next time the computer was booted vsafe detected a virus and suggested running msav to clean up the problem. Upon running msav, from the dos prompt,an error message is generated that says Disk Error: Cause: Disk is write protected. If a virus is present, called "Signalit PT", How do I eradicate it ? I don't understand how the hard drive can be write protected. I can copy files from directory to directory with no problem. Is there something strange about having a drive > 528 meg. ? Do I really have a virus ? thank you gary novay ------------------------------ Date: Mon, 07 Nov 94 17:08:47 -0500 From: Guest@comm.mgmt.purdue.edu (kcic ) Subject: Possible Variant of Jumper.B (PC) We've run across an apparently new variant of the Jumper.B virus (as named by F-prot v2.14). F-prot comes up with a detection but labels it a new variant and will not clean or the virus. We also run Mcaffee software but it neither detects it or disinfects it. I would greatly appreciate any responses regarding similar events or an AV program that might be able to handle this. We've already been hit hard with Jumper.B once this year. Please any help would be appreciated. Bryan Mattes Krannert Computing Center Purdue University thebear@expert.cc.purdue.edu ------------------------------ Date: Mon, 07 Nov 94 17:17:02 -0500 From: cjkuo@symantec.com (Jimmy Kuo) Subject: Re: Virus named Jack Ripper (PC) Simon_Li@Douglas.BC.CA writes: >Recently my colleagues came back from Hungary and brought back >(accidentally) a virus called Jack Ripper. I don't think NAV can >catch this virus. Once a computer is infected, the drive C is gone. NAV detects this virus since the January 1994 update. Its name is Ripper. >Anyone has any suggestions how to deal with this virus? Also, what >is the latest version of NAV's virus definition file? Updates are available on a monthly basis. Check on each first of the month. Jimmy Norton AntiVirus Research ------------------------------ Date: Mon, 07 Nov 94 17:28:53 -0500 From: cjkuo@symantec.com (Jimmy Kuo) Subject: Re: DOOM II (PC) Steve Midgley writes: >I'm not going to say that doom ii is a 'bad' program, but it doesn't >INHERENTLY have any more to do with viruses than Word Perfect 6.0. >It's just a game. DOOM II is distributed in a shareware package. I believe there have been at least 3 separate incidents of DOOM II packages being infected and redistributed. I am not familiar with how DOOM II is packaged. I wish they would have had some built-in self-checks to prevent this type of attack. Jimmy Norton AntiVirus Research ------------------------------ Date: Mon, 07 Nov 94 23:43:35 -0500 From: hatcher@mn.ecn.purdue.edu (Stephen D Hatcher) Subject: THANKS!! Re help with FORM (PC) I recently posted a request for help with a virus I called "FORMS" The mail I recieved helped a lot. Actually, I used F-Prot to remove it successfully. This AV recognized it as "Stoned.Empire.Monkey.B". This virus is running mad through the PC nets at Purdue University. The Administration are apearently having a hard time stopping it as it has been a problem for over a year-- according to my research. Thanks again!! Steve Hatcher hatcher@mn.ecn.purdue.edu ------------------------------ Date: Mon, 07 Nov 94 23:43:39 -0500 From: Zeppelin@ix.netcom.com (Mr. G) Subject: Re: CMOS virus/ answer to questions (PC) I have seen very many posts requesting information about the CMOS Viruses. So I thought that I would explain several factors that are involved. First of all, the CMOS (Complementary Metal Oxide Semiconductor) is a low power consumption area where information such as equiptment setting, HD type, time and date are stored and maintained. The CMOS in your computer is changed and set every time you run the Setup program that comes with you BIOS, and can be accessed and changed by any program running from DOS. The AT COMS Ram is diveded into three areas. 1.) The clock/calendar bytes 2.) The Control Registers 3.) General purpose RAM To access and change a computers CMOS RAM is very simple! Access is done through ports 70 hex (CMOS control.address) and port 71 hex (CMOS Data). The process is simple! 1.) We specify the CMOS RAM address of the bytes we want to read or write using port 70h IE; mov al,xx where XX= BYTE specefying the address (00h->efh) out 70h,al 2.) We read or write a byte to the address specified in step 1. IE; Read example' in al,71h byte at location XX goes into AL IE; Write Example out 7lh,al byte in AL goes to location XX in the CMOS RAM There is a problem. If you are writing to any of the locations that are checksumemed (10h - 2Dh), you must change the checksum value as well. So you must follow steps 1 and 2 with the checksum vlaues at locations 2Eh and 2Fh, combine the bytes into one register and subtract the current byte value from the register containing the checksum. Then you add the value of the new byte to be put in the CMOS RAM to the register that has the checksum, and you write the checksum, and the new byte to CMOS. Of the many factors and features of the CMOS attaching Viruses, the one that is most dangerous is; - -->> Lack of interaction between software and CMOS, and that the virus is not stopped by common Anti Virus TSR programs ! A good example is the African ExeBug virus, which uses CMOS control to make itself extremly difficult to remove from an infected HD. EXEBug has the ability to change CMOS so that if the machine is booted from a a Floppy, and the virus is NOT in memory, the infected HD is not visible. End Part 1 I will explain the problems created by a CMOS virus in my next post -Zep- ------------------------------ Date: Tue, 08 Nov 94 10:48:16 -0500 From: jjb18@aloha.cc.columbia.edu (Jeremy J. Blumenfeld) Subject: Re: stoned - Monkey (PC) We have had problems with the stoned.empire.monkey.a (according to F-Prot). Using killmonk 3.0 (shareware) generally the virus can be killed without even booting from a clean floppy. ------------------------------ Date: Tue, 08 Nov 94 13:34:33 -0500 From: wbecker@expert.cc.purdue.edu (William Becker) Subject: Unknown Virus?? (PC) My roommate and I suspect that our systems have been infected by a currently uncataloged virus. Neither nav 3 w/ oct defs, msav, or scan 117 can detect anything is wrong but, here's our symptoms: At warm reboot (ctrl-alt-del) the message "I'll be back!" appears. Some keystrokes are lost. Access to the upper memory area is disabled, IE you can load devices high. All *.com files are 1363 bytes longer then usual. It also appears in infect boot sectors. Hopefully some virus gurus can identify this new nasty. Thanx in advance. ------------------------------ Date: Tue, 08 Nov 94 18:10:14 -0500 From: Zvi Netiv Subject: Removing boot sector virus (CANSU/V-Sign) (PC) Russell Owsianski wrote: )Hi all, recently, I found a boot sector virus on a 3.5" floppy. Scan211e )calls it CANSU, fp214 calls it V-sign. Neither scan211e /clean nor )clean117 can remove it. :( ) )I never executed anything from that disk, and the scanners say that the )hard drive is still clean. ) )First question: What can I use to get rid of the virus on the floppy? )(hopefully without losing the data on the floppy)? CANSU, V-Sign and Sigalit are all various names for the same virus. There is a little program I wrote that can be used to clean all floppies from 360 kbyte to 2.88 mbyte, regardless of what infected them. It is called FIXBOOT and is available for ftp through Internet. FIXBOOT will automatically recognize the floppy size and install a fresh boot sector. With most boot viruses, the program will indicate whether the boot sector was infected. There are instances where 3.5" floppies become unreadable in a clean machine, after being infected by a boot infector such as Zharinov. FIXBOOT can then install a fresh boot sector for a selected disk size, and restore readability to the floppy. FIXBOOT will let select between a standard MS-DOS or PC-DOS sector, and the floppy will even be bootable, if necessary. FIXBOOT is public domain and can be downloaded from: ftp.netcom.com/pub/antivir/invircible/fixboot.zip or from the author ftp: ftp.datasrv.co.il/user/netz/fixboot.zip The same program can be used to screen all floppies, in case of doubt. Zvi Netiv, InVircible NetZ Computing Ltd. fax: 972-3-5325325 e-mail:ila2007@datasrv.co.il - --------------------------------------------------------------------- ------------------------------ Date: Tue, 08 Nov 94 23:38:42 -0500 From: kabell@NMSU.Edu (Kathleen Bell) Subject: Natas Virus ? (PC) We recently had an outbreak of the Natas.Boot virus on our machines in our computer lab. Does anyone know what exactly this virus does? Thanks! ------------------------------ Date: Thu, 03 Nov 94 13:49:09 +0200 From: Leo_Verhoeven@f0.n3110.z9.virnet.bad.se (Leo Verhoeven) Subject: NATAS (PC) Hallo Maarten, -=> Quoting Maarten Meijer to All on 10-28-94 14:50 <=- MM> Could anyone please give us information about the Natas MM> virus? Recently we discovered several computers being infected -------> KNIP <----------------------- MM> polymorphic virus code at the end of file). What you've discovered about Natas so far, seems to be correct. It alters MBR and Boot-Sectors, and infects EXE and COM-files. Running CHKDSK will report allocation-errors on the infected files; running these infected files may cause system-hangup. Master Boot Records can be repaired by using the undocumented option /MBR of the FDISK command. This works only in DOS >= 5 and is only safe if you haven't got more than 4 partions and no non-DOS partitions. Boot Sectors can be repaired using the SYS command. Both these methods of course only work after booting from a clean, write-protected disk containing these commands. Infected EXE and COM files: delete 'm and replace by the clean originals. Good luck / succes ermee. Leo. .. If it ain't Dutch..., it ain't much!!! - --- GEcho 1.01+ * Origin: Virus Research Centre Holland (9:3110/0.0) ------------------------------ Date: Wed, 09 Nov 94 07:33:47 -0500 From: SUMMONTE@POLCLU.polito.it (MICHELE CALI) Subject: Is Possible eliminate the 1099 (PC) I'm infected with the 1099 founded only by SCAN177 bat not is possible to disinfect from it by CLEAN117 I have deleted the infected files but the my system not running in the right mode. Is possible that the 1099 is in the my compute yet ? how i may disinfect ? summonte@poldid.polito.it (Walter) ------------------------------ Date: Wed, 09 Nov 94 16:19:45 +0000 From: kat@ritz.mordor.com (Karen Tellefsen) Subject: HELP! How do I fix the B1 virus? (PC) Two of colleagues have the MBR of their hard drives infected with the B1 virus. I found it with Skulason's F-prot, but I can't fix it with this program. Do I have to reformat their hard drives and load-up everything from scratch, or is there an easier way to fix this problem? - -- Karen Tellefsen kat@ritz.mordor.com ------------------------------ Date: Wed, 09 Nov 94 09:49:48 -0500 From: sandyk@vt.edu Subject: birdlike chars in windows (PC) Recently a few people in our dept have been seeing little birdlike charcters in the Windows headers at the top of their screen. (A V that looks like a seagull with the wings turned down. It seems to be spreading daily. F-prot sees no problem. Has anyone seen this and know if I can get rid of it? Thanks Sandy sandyk@vt.edu ------------------------------ Date: Wed, 09 Nov 94 16:37:37 -0500 From: ecrvich@vt.edu (Ernest Crvich) Subject: F-Prot Information question (PC) In the Virus Information list in F-Prot (2.14), two (at least two, I couldn't find any more) viruses had asterisks (*) next to their names : AntiExe and Arusiek. What does this asterisk imply? Typo? I couldn't find anything in the docs about what it might mean. - -- Ernest M. Crvich Programmer (ecrvich@vt.edu) Virginia Tech Computing Center Blacksburg, VA, USA ------------------------------ Date: Thu, 10 Nov 94 03:15:51 -0500 From: ANTHONY APPLEYARD Subject: Mouse ports (PC) I am sorry to waste bandwidth with a matter not directly related to viruses, but: since much in viruses and antivirals is concerned with reading and writing to things directly, perhaps someone might know something that I have looked for in vain through infinity big comprehensive-looking PC books: what port reads and writes would I need to access an ordinary serial Microsoft-type mouse directly by port reads and writes, bypassing the int33 interrupts and the usual mouse handlers? It seems that it should be fairly easy: detect a unit movement in each direction; detect if each button is up or down. ------------------------------ Date: Thu, 10 Nov 94 07:04:51 -0500 From: AMSSXXS@typeb.sita.int Subject: Looking for NLM scanners (PC) L.S> I am looking for info on NLM type scanners. Everything like hit-rate, speed, update intervals, etc is welcome! Thanks, Dries - -------------------------------------------------------------------- Dries Bessels FIDO -> 2:280/202 +31-20-6069147 RIME -> REFLEX SITA Network -> AMSSXXS FAX -> +31-20-6812021 Internet -> AMSSXXS@typeb.sita.int Snailmail -> Heathrowstraat 10, 1043CH Amsterdam, The Netherlands - ------------ Sure, when ... OINK FLAP OINK FLAP ... I'll be damned! ------------------------------ Date: Thu, 10 Nov 94 08:21:51 -0500 From: C.Booth-94@student.lut.ac.uk (C Booth) Subject: Dr. Solomon Drivers (PC) I checked out oak.oakland.edu /simtel/msdos/virus for upto date drivers for Dr. Solomon's AV but according to the readme their not there! Any help would be welcomed! Thanks. ------------------------------ Date: Thu, 10 Nov 94 08:45:33 -0500 From: "Jim Bennett" Subject: What can a virus do ? I need HELP! Please (PC) I have a PC in which a virus has corrupted the boot sector of the Hard Drive. After many attempts of recovering I finally had to resort to formatting the hard drive. This was not too big of issue since all of the data files were backed up to tape and I had all of the original install disks for the PC software. But I have had numerious problems reinstalling the software. Everytime during the install process of WFW311, or DOS 6.2 or even after everything is installed I get some type of error condition which causes the PC to crash. These error conditions are different each time. One time it is a emm386 error condition, the next a bad or no Command.com found message or a GPF error in windows. I have attempted to start over several times (Fdisk, Format, SYS C:) but have had no luck getting everything restored. Also everytime it crashes some clusters get lost or mis allocated and I am not sure if this is due to the abnormal termination (error condition) or is a virus still alive doing damage? My question, can a virus survive a HD reformat or does that remove it from the system entirely? Can a virus infect the electronics of the PC for example live within BIOS or some other location? The PC I am using has flash BIOS which can be written to. I have also considered that maybe my install disks are infected thus doing more harm than good but I have not checked them yet. In addition, what is a good anti virus program to use? Any suggestions? At this point I am lost as to what to do next. I have run diagnosics on the hard drive, mother board and other componients with no errors encountered. ANY feedback would be appreciated. I must get this PC running. ------------------------------ Date: Thu, 10 Nov 94 11:12:12 -0500 From: Richard Bondi Subject: NCSA hasn't heard of Viking virus (PC) The Subject is overly provocative. I read a bit about NCSA, and they told me stuff about ANTICMOS that McAfee didn't tell me, so I assumed what I had read was true: that they have a database of all viruses and are used as a central resource by all virus fighters. If they've not heard of Viking, it can't be true. Is it true of anyone, and if so, of whom? Thanks, Richard Bondi ------------------------------ Date: Thu, 10 Nov 94 16:12:47 -0500 From: dsmith@cusd.eds.com (Darrin Smith) Subject: FLU-SHOT (PC) A few years ago I purchased an anti-virus program known as FLU-SHOT. This product did not scan for viruses, but rather intercepted writes to executable files. Does anyone know if the company that wrote this is still in existance? ------------------------------ Date: Thu, 10 Nov 94 17:02:48 -0500 From: lakhani@wharton.upenn.edu Subject: Best form of Virus Protection? (PC) Does anyone know what the best virus protection available is? I have used and tried F-Prot, McAfee, CPAV, Vi-Spy, NAV... However, with the simple problems that I've had, I couldn't tell the difference.. I would like to know who offers the best service, and upgrades on their products also... As price isn't a limit in this purchase, hardware solutions are an option also... Any help would be greatly appreciated... please send replies to : lakhani@wharton.upenn.edu ------------------------------ Date: Thu, 10 Nov 94 19:26:21 -0500 From: jis@panix.com (Eeyore) Subject: INFO WANTED: Junkie.Boot virus... (PC) Hello, The place I work at has had many machines infected by the JUNKIE virus. I have managed to clean them with SCAN 2.1.1, well at least the ones that are on the MBR (JUNKIE.MBR) and the executable files (JUNKIE). But for some reason, Scan can't remove it from the boot sector of floppies. Does anyone have any idea why? Does an info file on this virus--origin, damage it can do, etc.--exists. I know that once a system gets it it spreads like wildfire troughout the executable files (most noticable *.COM files), but doesn't do much until some point in the future where the machine can't boot off of the hard drive. A cleaning of the MBR corrects the problem, but is there anything else it does? Any and all info would be appreciated.... Thanks, Jack jis@panix.com ------------------------------ Date: Thu, 10 Nov 94 23:43:02 -0500 From: terru@aol.com (Terru) Subject: PC drops out of Windows. Virus? (PC) I've been having trouble with the PC's (80+) at my company. Users have been complaining that they'll be in Windows, and while idle, it will drop out to the DOS prompt. They have not noticed any lost or corrupted files. I occasionally bring files home, and now I seem to have the same problem on my PC at home. MS Anti-virus doesn't find anything. Is this a new virus? If so, how can I get rid of it? I'd appreciate any response! - -Glenn- - -Terru@aol.com- ------------------------------ Date: Fri, 11 Nov 94 01:44:53 -0500 From: "Frans Veldman" Subject: Memory scanning (PC) Iolo Davidson writes: >> As a 'technical editor' you are acting rather unprofessional. > > I have discussed your message with the editor of SECURE > Computing, Paul Robinson, who has said two things of substance: I have discussed your message with him too. > 1- SECURE Computing stands by its review. > 2- He does not want me to get into a public argument with you. I'm not going to repeat literally what he told me, but he understands and agrees with the problems I have with the test, and especially your message. > therefore comes from me personally, and not as a representative > of SECURE Computing. It still affects SECURE computing, in the same way my personal messages affect my company. Anyway, you decided to get into a public argument with me. Fine. I hope it will satisfy you and is worth your time. I have no choice after such an obvious attack. >> It is a good custom to respect a developers' motivation >> about the design of his product. > > In journalism it is the custom to examine issues that the > journalist thinks relevant without paying too much attention to > the excuses of those being examined. Ten products were reviewed, I know the customs of some journalist. There are pretty many of them who test an anti virus product on a set of files collected from Virus Exchange BBSes or Virus Simulators, and they also don't pay too much attention to the excuses of those being examined. That doesn't necessarily mean that it is a good custom. In fact, the good reviews differ from the bad reviews mainly because the good reviews do pay attention to the comments and advises from the experts. > and only Thunderbyte took the position that memory scanning was > not necessary. Thunderbyte was the only product which doesn't rely on DOS to read the files and is therefor less vulnerable to stealth viruses, and thus doesn't have to rely on memory scanning. > SECURE Computing did publish comments from many of the vendors > whose products were tested, including Thunderbyte. Try looking > at pages 38 and 39. You were quoted as saying that the test was > "irrelevant" for your product. You were also quoted as claiming Ok, ok. Nice that just one line of our two page explanation was quoted. It made such an overwhelming impression that I overlooked it. What matters is what your message suggest, and that is that TBAV is a bad product. According to your chief editor this isn't exactly what our product deserves. > that the next version of your product *would* be able to do such > tests. Nope. > The vendor response boxes indicate that when asked if detecting > viruses in memory was important, you responded "Yes and No". You Yes, it is important for most AV products. No, it is not important for OUR product. Yes, it is important for some viruses. No, it is not important for most viruses. > also indicated that you have not conducted your own tests of > memory scanning (doesn't bode well for the new version that is > supposed to offer it). There is no change in new versions regarding to memory scanning, and there won't be. It is not necessary. We may include some more viruses into the memory scanning when we think it is necessary, but we will never include an 'scan for all viruses in all memory' option. > Quote from the review- "Out of the ten anti-virus vendors whose > products we investigated, at least eight seem to have agreed with > us regarding the advisability of looking for Jerusalem in memory > before disk scanning." Maybe their product differs from ours. Maybe their product detects the virus 'automatically' because they search for their entire signature base in memory (including non-resident viruses). Why complain if your product scores well? We think heuristic scanning is necessary. Some other researchers think it isn't. What if I perform a test with all AV products to see how their heuristics performs, including the products that do no have heuristics? I think I should either exclude these products for the test, or quote the full comment of the supplier why he thinks his product doesn't need heuristics. But your opinion: >SECURE Computing are not obliged to publish your excuses for you. They were not excuses. They were answers on questions asked by Secure computing. And we have also sent some comments, which make sense. > As for the excuses themselves, I don't agree with them on the > basis of my professional judgement, not my personal feelings. > > Why, for instance, have you designed your product to hang the > computer with no message when Fish6 or Frodo are in memory? My product doesn't hang the computer. These viruses do. They have probably problems with the anti-stealth techniques of TBAV. It doesn't matter, because we recommend users to boot from a clean diskette before scanning, and they will do that when the machine hangs anyway. > Surely it would be better to give the user some idea of what is > happening? It would be nice, but we decided that the advantage of such a message would not weight against the amount of problems it would cause to the users. I don't know how long you have been around here, but I have not seen many messages like: "My computer hangs when I try to scan after I booted from the harddisk, and after booting from the floppy drive I detect the Frodo virus. Why did the machine hang?". Instead, I have seen many questions like: "When I have scanned my system with scanner XYZ, and scan again after that with scanner ABC, then it finds Frodo in memory. Help! What is going on? Is product XYZ infected?". Or: "When I scan an infected floppy which contains Frodo, the next time I scan, the scanner will detect the virus in memory. Help! Did I infect my system by just scanning an infected diskette?". We decided that memory scanning creates more problems than it solves, and isn't basically necessary for our product anyway. It is not an excuse, but a sensible argument as anyone with some brains can see. But you don't care: > "In journalism it is the custom to examine issues that the > journalist thinks relevant without paying too much attention to > the excuses of those being examined." - -- Thunderbye, Frans Veldman <*** PGP 2.3 public key available on request ***> Frans Veldman Phone (ESaSS) + 31 - 80 787 881 veldman@esass.iaf.nl Fax (ESaSS) + 31 - 80 789 186 2:280/200.0@fidonet Fax (VirLab) + 31 - 59 182 714 ------------------------------ Date: Fri, 11 Nov 94 01:26:36 -0500 From: murphwar@pylon.com (Jeff Murphy) Subject: invb601a.zip - The InVircible Anti-Virus Expert System v6.01A (PC) I have uploaded to SimTel, the Coast to Coast Software Repository (tm), (available by anonymous ftp from the primary mirror site OAK.Oakland.Edu and its mirrors): SimTel/msdos/virus/ invb601a.zip The InVircible Anti-Virus Expert System v6.01A InVircible is a sophisticated and effective anti-virus product. InVircible is the only anti-virus package able to state that every single virus in the three known virus classes (Boot Sector, FAT/Directory, Executables) has been to date detected and removed -- a track record that dates back to the Fall of 1990! InVircible implements a unique layered approach consisting of several virus detection and removal programs combined into an unparalled virus detection and removal system. Once installed, InVircible can absolutely confirm the presence of viruses, repair and remove virus infections, and make your system fully operational with limited virus knowledge and limited time. Utilizing a proprietary Adaptive Expert System, InVircible requires no updates to remain effective, and provides the piece of mind desired in virus control without the the loss of system performance experienced with most TSR/Scanner AV packages. If high performance, lower costs, and total security are what you demand from your AV package, InVircible is the one to choose. Special requirements: None ShareWare. Uploaded by the U.S. Distributor. Jeff Murphy murphwar@futursoft.win.net ------------------------------ End of VIRUS-L Digest [Volume 7 Issue 94] *****************************************