home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!caen!spool.mu.edu!agate!usenet.ins.cwru.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: riordan.cybec@tmx.mhs.oz.au (Roger Riordan)
- Newsgroups: comp.virus
- Subject: PC Viruses "protected" by CPAV (PC)
- Message-ID: <0014.9212181845.AA00632@barnabas.cert.org>
- Date: 17 Dec 92 22:16:35 GMT
- Sender: virus-l@lehigh.edu
- Lines: 51
- Approved: news@netnews.cc.lehigh.edu
-
- > MC1980@mclink.it (Luca Parisi) reports
-
- > " I' ve had some random problems on my PC and wondered if some
- > virus could be responsible for this. ... I also poked around with
- > PCTools, and find a strange repeating pattern in the slack space
- > of many .EXE files. It contains something like 'Carmel SW' and a
- > copy of the 'MZ' signature, not the usual garbage...
-
- This tail is a form of integrity checker, and is added to the file
- (in exactly the same way as a virus) by part of the CPAV/CARMEL
- anti-virus software. When you run the program it is run first, and
- warns you if the start of the file, or the length, has been changed.
-
- This is a nice idea, but unfortunately this product has caused a
- number of users a lot of problems by protecting pre-existing viruses
- it has failed to detect. "Intelligent" scanners will generally fail
- to find viruses protected in this way, as the initial entry point
- goes to the CPAV software, instead of the virus. Logically "dumb"
- scanners ought to find the virus, but may not do so in practise.
-
- We have just received a new strain of Zerotime (or Slow) in which
- the decryption procedure has been patched to avoid detection. The
- sample disk we received had many files in which the virus was
- protected in this way. Because the CPAV software overwrites the
- start of the file (after saving it elsewhere) it has split the
- encryption procedure in two. Neither part is long enough to detect
- reliably, without causing many false alarms, and so it is not
- possible to detect the virus unless the CPAV software is removed.
-
- The virus will emerge, and make itself obvious by infecting new
- files (and also the ones with the "protected" virus), in the normal
- way immediately you run an infected file, but the source will remain
- hidden. If you are having trouble getting rid of a virus you should
- treat any files "protected" by this product with extreme suspicion.
-
- In investigating this we re-examined samples we had collected from a
- shop having virus like problems. At the time we did not know about
- this product (which had been added by the proprietors son, without
- permission), and assumed it was causing the problems. However when
- we looked at the files again we found that Padded virus was hiding
- behind the Carmel software. Neither McAfee Scan nor Dr. Solomon's
- Toolkit can find the virus in these files.
-
- We know of two strains of this product, and have added signatures
- for them to VET 7.11. This will flag affected files as "Packed with
- CPAV anti-virus."
-
- Roger Riordan riordan.cybec@tmxmelb.mhs.oz.au
-
- CYBEC Pty Ltd. Tel: +613 521 0655
- PO Box 205, Hampton Vic 3188 AUSTRALIA Fax: +613 521 0727
-