home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.compression
- Path: sparky!uunet!mcsun!Germany.EU.net!rzsun2.informatik.uni-hamburg.de!fbihh!bontchev
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Subject: PKZ204C.EXE IS *NOT* INFECTED!!!
- Message-ID: <bontchev.726270248@fbihh>
- Sender: news@informatik.uni-hamburg.de (Mr. News)
- Reply-To: bontchev@fbihh.informatik.uni-hamburg.de
- Organization: Virus Test Center, University of Hamburg
- Date: 5 Jan 93 21:44:08 GMT
- Lines: 77
-
- Hello, everybody!
-
- A kind soul hellped me to get a copy of the much controversial file
- PKZ204C.EXE. This file is NOT on wuarchive, please stop trying. You
- are already exceeding the maximal number of simultaneous anonymous
- users that wuarchive is able to handle.
-
- I analyzed the file carefully. I am a world-wide known computer virus
- expert, specialized in MS-DOS viruses, so I know what I am talking
- about. The executable mentioned above DOES *NOT* CONTAIN ANY VIRUSES!
- Please, stop spreading rumors. It is a self-extractable archive, which
- is further compressed with PKLite 1.20 (unless the new ZIP2EXE puts an
- already PKLited extractor automatically).
-
- The archive indeed contains version 2.04c of PKZIP. I do not know
- whether this version is real, but I guarantee that it is -not- a hack
- of PKZIP 1.93 or Info-ZIP. For more information, contact PKWare. My
- personal oppinion is that the new version is real.
-
- NONE OF THE EXECUTABLES IN THE ARCHIVE IS INFECTED!
-
- The archive can be let to self-extract, but you can also unpack it
- with PKUNZIP 1.93 or unzip 5.0. If you unpack it with PKUNZIP 1.93, it
- reports -AV codes (did you know that the alpha version supports
- authentication?) but at the end it says that the archive fails the
- authentication check. Obviously, the authentication in 2.04c is
- different from that in 1.93, because PKUNZIP 2.04c says that the
- archive PKZ204C.EXE -does- have a correct authentication mark.
-
- F-Prot 2.06a, when run in heuristic scan mode, reports that the files
- PKZ204C.EXE, PKUNZIP.EXE, PKZIPFIX.EXE and ZIPFIX.EXE are "suspicious,
- because they contain a self-modifying program, which may indicate a
- self-encrypting virus or just unusual code". This is PERFECTLY NORMAL,
- because all those EXE files are compressed with PKLite 1.20 and they
- -do- contain a self-modifying (in memory) program - the decompressor
- that unpacks them in memory. People who do not understand the
- capabilities and the limitations of heuristic scanning are STRONGLY
- advised not to use it and not to spread rumors.
-
- No other scanner of those that I tried (about a dozen) reported
- anything else. I finally analyzed the files manually with a debugger
- AND THEY DO NOT CONTAIN ANY VIRUSES, LET ALONE MALTESE AMOEBA.
-
- On the top of that EVEN A RECENT VERSION OF NORTON ANTI-VIRUS *DOES
- NOT* FIND *ANY* VIRUSES IN *ANY* OF THE EXECUTABLES. By "recent
- version" I mean NAV 2.1 with signature updates of December. I am
- afraid that the person who posted the initial alert is using an out-of
- date scanner.
-
- Again, I am stating with my full authority that NONE OF THE
- EXECUTABLES IS INFECTED BY ANY VIRUS.
-
- At last, just to be sure that we are speaking about one and the same
- thing, here are the checksums obtained with McAfee's program VALIDATE
- on the archive I checked. Please, don't pay attention to the date of
- last modification, because it got destroyed during the download.
-
- File Name: PKZ204C.EXE
- Size: 188,818
- Date: 1-5-1993
- File Authentication:
- Check Method 1 - 0DC8
- Check Method 2 - 045E
-
- Well, that's all. The moderator of wuarchive is welcome to put
- PKZ204C.EXE back on-line. If anybody has any other questions, feel
- free to ask. Just have in mind that I probably won't be able to answer
- before tomorrow, because it is almost midnight here, I am still in the
- office and my last bus to home leaves after half an hour... :-)
-
- Regards,
- Vesselin
- --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-