home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.ibm.pc.misc
- Path: sparky!uunet!cs.utexas.edu!uwm.edu!linac!att!cbnewsm!cbnewsl!att-out!walter!qualcom.qualcomm.com!cancun!rdippold
- From: rdippold@cancun.qualcomm.com (Ron Dippold)
- Subject: Re: PKZIP 2.04c Uploaded to wuarchive
- Message-ID: <rdippold.726277941@cancun>
- Sender: news@qualcomm.com
- Nntp-Posting-Host: cancun.qualcomm.com
- Organization: Qualcomm, Inc., San Diego, CA
- References: <rdippold.726230390@cancun> <1993Jan5.173246.4926@netcom.com> <1993Jan5.230148.10970@trl.oz.au>
- Date: Tue, 5 Jan 1993 23:52:21 GMT
- Lines: 92
-
- Okay, here we go, this is not from me, it's from another person who's
- looked at PKZip 2.04c. You'll excuse me if I'm feeling a bit
- defensive right now, you should see my mail! "Hacker playing a silly
- trick to spread a virus..." and all that crap. All because Norton AV
- 2.0 is screwed up (and 2.1 isn't, read on). I will continue to upload
- pkz204c.exe to wuarchive every now and then until whoever is deleting
- it gets the message.
-
- [Start quote]
-
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Subject: PKZ204C.EXE IS *NOT* INFECTED!!!
- Message-ID: <bontchev.726270248@fbihh>
- Organization: Virus Test Center, University of Hamburg
- Date: 5 Jan 93 21:44:08 GMT
-
- Hello, everybody!
-
- A kind soul hellped me to get a copy of the much controversial file
- PKZ204C.EXE. This file is NOT on wuarchive, please stop trying. You
- are already exceeding the maximal number of simultaneous anonymous
- users that wuarchive is able to handle.
-
- I analyzed the file carefully. I am a world-wide known computer virus
- expert, specialized in MS-DOS viruses, so I know what I am talking
- about. The executable mentioned above DOES *NOT* CONTAIN ANY VIRUSES!
- Please, stop spreading rumors. It is a self-extractable archive, which
- is further compressed with PKLite 1.20 (unless the new ZIP2EXE puts an
- already PKLited extractor automatically).
-
- The archive indeed contains version 2.04c of PKZIP. I do not know
- whether this version is real, but I guarantee that it is -not- a hack
- of PKZIP 1.93 or Info-ZIP. For more information, contact PKWare. My
- personal oppinion is that the new version is real.
-
- NONE OF THE EXECUTABLES IN THE ARCHIVE IS INFECTED!
-
- The archive can be let to self-extract, but you can also unpack it
- with PKUNZIP 1.93 or unzip 5.0. If you unpack it with PKUNZIP 1.93, it
- reports -AV codes (did you know that the alpha version supports
- authentication?) but at the end it says that the archive fails the
- authentication check. Obviously, the authentication in 2.04c is
- different from that in 1.93, because PKUNZIP 2.04c says that the
- archive PKZ204C.EXE -does- have a correct authentication mark.
-
- F-Prot 2.06a, when run in heuristic scan mode, reports that the files
- PKZ204C.EXE, PKUNZIP.EXE, PKZIPFIX.EXE and ZIPFIX.EXE are "suspicious,
- because they contain a self-modifying program, which may indicate a
- self-encrypting virus or just unusual code". This is PERFECTLY NORMAL,
- because all those EXE files are compressed with PKLite 1.20 and they
- -do- contain a self-modifying (in memory) program - the decompressor
- that unpacks them in memory. People who do not understand the
- capabilities and the limitations of heuristic scanning are STRONGLY
- advised not to use it and not to spread rumors.
-
- No other scanner of those that I tried (about a dozen) reported
- anything else. I finally analyzed the files manually with a debugger
- AND THEY DO NOT CONTAIN ANY VIRUSES, LET ALONE MALTESE AMOEBA.
-
- On the top of that EVEN A RECENT VERSION OF NORTON ANTI-VIRUS *DOES
- NOT* FIND *ANY* VIRUSES IN *ANY* OF THE EXECUTABLES. By "recent
- version" I mean NAV 2.1 with signature updates of December. I am
- afraid that the person who posted the initial alert is using an out-of
- date scanner.
-
- Again, I am stating with my full authority that NONE OF THE
- EXECUTABLES IS INFECTED BY ANY VIRUS.
-
- At last, just to be sure that we are speaking about one and the same
- thing, here are the checksums obtained with McAfee's program VALIDATE
- on the archive I checked. Please, don't pay attention to the date of
- last modification, because it got destroyed during the download.
-
- File Name: PKZ204C.EXE
- Size: 188,818
- Date: 1-5-1993
- File Authentication:
- Check Method 1 - 0DC8
- Check Method 2 - 045E
-
- Well, that's all. The moderator of wuarchive is welcome to put
- PKZ204C.EXE back on-line. If anybody has any other questions, feel
- free to ask. Just have in mind that I probably won't be able to answer
- before tomorrow, because it is almost midnight here, I am still in the
- office and my last bus to home leaves after half an hour... :-)
-
- Regards,
- Vesselin
-
- [ end quote ]
- --
- A chiseler is a man who goes stag to a wife-swapping party.
-