home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Hacker 2
/
HACKER2.mdf
/
virus
/
virusl2
/
virusl2.186
< prev
next >
Wrap
Text File
|
1995-01-03
|
9KB
|
250 lines
VIRUS-L Digest Wednesday, 6 Sep 1989 Volume 2 : Issue 186
VIRUS-L is a moderated, digested mail forum for discussing computer
virus issues; comp.virus is a non-digested Usenet counterpart.
Discussions are not limited to any one hardware/software platform -
diversity is welcomed. Contributions should be relevant, concise,
polite, etc., and sent to VIRUS-L@IBM1.CC.LEHIGH.EDU (that's
LEHIIBM1.BITNET for BITNET folks). Information on accessing
anti-virus, document, and back-issue archives is distributed
periodically on the list. Administrative mail (comments, suggestions,
and so forth) should be sent to me at: krvw@SEI.CMU.EDU.
- Ken van Wyk
Today's Topics:
New Amiga virus ?
Re: Is this a virus? (PC)
Capturing a Mac virus II
Re: VACSINA ... why we called it so (PC)
Killvirus Antivirus Program Inconsistencies
Back-to-school Time
Ping-Pong Virus vector (PC)
Thanks for all the info
---------------------------------------------------------------------------
Date: 04 Sep 89 16:41:39 +0000
From: jwright@atanasoff.cs.iastate.edu (Jim Wright)
Subject: New Amiga virus ?
This was recently posted to comp.sys.amiga...
In article <716@mathrt0.math.chalmers.se> d8forma@dtek.chalmers.se (Martin Fors
sen) writes:
|
| Last night a friend called me, since he suspected he had a virus.
| I gladly grabbed my copy of VirusX (3.20) and drove over, but VirusX
| reported no virus. However I saw the text from the virus myself, and
| a closer look at the diskette showed that the file c/addbuffers had grown,
| furthermore a file with a blank name had appeared in devs.
|
| The main symptom of this virus is that every fourth time you reboots the tex
t:
|
| A Computer virus is a disease
|
| Terrorism is a transgession
|
| Software piracy is a crime
|
|
| this is the cure
|
| BGS9 Bundesgrensschutz sektion 9
| sonderkommando "EDV"
|
|
| On this disk the virus had replaced the file c/addbuffers, the size of this
| new file was 2608 bytes. The above text is encoded in the program, but the
| string graphics.library can be found, maybe it's normal for addbuffers to ca
ll
| graphics.library :-) The orginal addbuffers command was stored in a "blank"
| file in the devs directory.
| The addbuffers command was the second in the startup sequence on this disk.
| I think the virus looks in the startup-sequence for somthing (probably
| files to infect), since I found the string sys:s/startup-sequence coded
| in the virus.
| I don't know if this virus does any damage, but the person first infected
| hasn't noticed anything.
|
|
| The questions I now ask me is:
|
| Is this a known virus?
|
| and if the answer is no,
|
| What is Steve Tibbets mail adress?
|
|
| MaF
|
| Chalmers |USENET:d8forma@dtek.chalmers.se | " Of course I'm not lost,
| University |SNAIL: Martin Forssen | I just haven't pinpointed
| of | Marielundsgatan 9 | exactly where we are at the
| Technology |SWEDEN 431 67 Molndal | moment " (David Eddings)
- --
Jim Wright
jwright@atanasoff.cs.iastate.edu
------------------------------
Date: 05 Sep 89 13:33:44 +0000
From: decvax!bunker!shap@sei.cmu.edu (Joseph D. Shapiro)
Subject: Re: Is this a virus? (PC)
In article <0004.8909011255.AA07043@ge.sei.cmu.edu> 87303012@KRSNUCC1.BITNET wr
ites:
> When I copy some
>files to a floppy but I misput a write protected diskette, I find the
>error massage "retry, ...". At this time, if I answer "r" to the
>massage and puting a non-protected diskette, then the FAT and
>DIRECTORY of the protected diskette is transfered to the second non
>protected diskette(and the files that I copied to). Is this a DOS's
>bug or a virus?
Neither. It is normal behavior, given the circumstances. It is obviously
not what you _want_ to happen, but then again, the proper answer in the
given situation is to _A_bort the operation and start again.
- --
__--__--__--__--__--__--__--__--__--__--__--__--__--__--__--__--__--__--__--__
Joe Shapiro "My other car is a
\cturbo...
ISC-Bunker Ramo ...too."
{decvax,yale,philabs,oliveb}!bunker!shap
------------------------------
Date: Tue, 05 Sep 89 10:37:27 -0400
From: "Gregory E. Gilbert" <C0195@UNIVSCVM>
Subject: Capturing a Mac virus II
Could someone give me a brief description of Fedit+? Freeware? Shareware?
Why might it be better than ResEdit?
Gregory E. Gilbert
Academic Consultant
University of South Carolina
Columbia, South Carolina 29205
(803) 777 - 6015
------------------------------
Date: 05 Sep 89 18:51:56 +0000
From: "Manfred J. Pfluegl" <pfluegl%dream-d@ucsd.edu>
Subject: Re: VACSINA ... why we called it so (PC)
In article <0007.8908311207.AA03884@ge.sei.cmu.edu> RY15%DKAUNI11.BITNET@IBM1.C
C.Lehigh.Edu (Christoph Fischer) writes:
<stuff deleted>
>virus VACSINA. Anyhow nobody will detect a virus by it's name like cascade
>or vienna or whatever. The File length is somewhat ambigous and therefor
<stuff deleted>
Where did the virus "VIENNA" get his name from?? Does anybody know
the answer?
************** MM MMPPPP Manfred J. Pfluegl
***** MM M MP P pfluegl@balboa.eng.uci.edu
***** M M MPPPP pfluegl%balboa.eng.uci.edu@ics.uci.edu
***** M MP
------------------------------
Date: Tue, 05 Sep 89 10:55:03 -0400
From: "Gregory E. Gilbert" <C0195@UNIVSCVM.BITNET>
Subject: Killvirus Antivirus Program Inconsistencies
I was running an old version of virus detective (v. 2.2.1, I think) on
a disk on whick I had downloaded a number of files from "MACSERVE at
PUCC". The program, I belive, found what it identified as a virus in
the KILLLVIRUS software. Upon "resEditing" I noticed what looked like
the following:
- -------------
| . |
| . |
| . |
| kVir |
| nVir |
| |
- -------------
However, when crossed checked with Virus Detective no bells or
whistles were sounded. Could this be a virus? Or is it a bug in the
KILLVIRUS software? Thank you very much for your assistance.
Gregory E. Gilbert
Academic Consultant
University of South Carolina
Columbia, South Carolina 29205
(803) 777 - 6015
------------------------------
Date: Tue, 05 Sep 89 10:22:00 -0400
From: WHMurray@DOCKMASTER.ARPA
Subject: Back-to-school Time
It is back-to-school time. Throughout modern history this has been a
time for viruses to manifest themselves. Students congregating in the
fall spread them like wildfire.
This is going to be particularly bad with computer viruses. Copies
which have been lying dormant for the season on unused diskettes will be
put into use.
Good computer hygiene is going to be particulary important during the
next few weeks. Encouraging good practice now may save you a lot of
grief during the next few weeks.
Regards, Bill
William Hugh Murray, Fellow, Information System Security, Ernst & Young
2000 National City Center Cleveland, Ohio 44114
21 Locust Avenue, Suite 2D, New Canaan, Connecticut 06840
------------------------------
Date: Tue, 05 Sep 89 19:33:00 -0400
From: WHMurray@DOCKMASTER.ARPA
Subject: Ping-Pong Virus vector (PC)
Does the Ping_pong virus travel on 3.5" diskettes?
William Hugh Murray, Fellow, Information System Security, Ernst & Young
2000 National City Center Cleveland, Ohio 44114
21 Locust Avenue, Suite 2D, New Canaan, Connecticut 06840
------------------------------
Date: Wed, 06 Sep 89 14:38:00 +0300
From: <87303012%KRSNUCC1.BITNET@VMA.CC.CMU.EDU>
Subject: Thanks for all the info
Hi everyone.
Thank you, all people having provided me with some helps
directly and via the list.
Here in Korea, nowadays many BBS's come to beings and plenty of
people come to concern Communication. But also some viruses
are reported recently, like some Brain viruses modified in
Korea to change the configuration of AT, Hebru virus( maybe
I misspell ), ANSI bomb and so on.
Kim, YunKi <87303012@KRSNUCC1> BITNET
Seoul NAt'l Univ. Dep. of Physics
------------------------------
End of VIRUS-L Digest
*********************
Downloaded From P-80 International Information Systems 304-744-2253