home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.ibm.pc.misc
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!cs.utexas.edu!convex!constellation!a.cs.okstate.edu!worley
- From: worley@a.cs.okstate.edu (WORLEY LAWRENCE JA)
- Subject: Re: PKZip 3.05 VIRUS WARNING
- References: <1993Jan6.012822.14594@a.cs.okstate.edu>
- Message-ID: <1993Jan6.143545.24272@a.cs.okstate.edu>
- Organization: Oklahoma State University
- Date: Wed, 6 Jan 93 14:35:45 GMT
- Lines: 158
-
- In response to the following letter I received about the Proto-T virus in
- PKZip 3.05, a gentleman from McAfee Assoc. sent the following response,
- saying that PKZip 3.05 is a HACK, but no self-replicating virus is embedded
- in it. I have included the warning letter that he is refering to at the end
- of this post for convenience.
-
- -Jason Worley
-
- -----------------------------------------------------------------------------
- -----------------------------------------------------------------------------
-
- Date: Wed, 6 Jan 93 00:18:29 -0800
- From: McAfee Associates <mcafee@netcom.com>
- Message-Id: <9301060818.AA06457@netcom.netcom.com>
- To: worley@a.cs.okstate.edu
- Subject: Re: PKZip 3.05 VIRUS WARNING
- Newsgroups: comp.sys.ibm.pc.misc
- In-Reply-To: <1993Jan6.012822.14594@a.cs.okstate.edu>
- References: <rdippold.726277941@cancun>
- Organization: McAfee Associates
- Cc:
-
-
- Hello Mr. Worley,
-
- The "PROTO-T" virus is a hoax.
-
- If you carefully read the message about the virus, you'll note that it
- says the virus infects video RAM, hard disk memory and modem buffers.
-
- When you change your video mode, you overwrite (clear) video
- RAM, so any code stored there would get erased. Hard disk memory does
- not exist--unless one refers to caches on the hard disk itself or the
- controller--which are not addressable by the CPU. The same goes for
- modem buffers.
-
- We have looked at numerous copies of the PKZ305.EXE cracked
- version of PKZIP/UNZIP and not found any replicating (viral) code in
- it.
-
- I would recommend that you ignore the message.
-
- Regards,
-
- Aryeh Goretsky
- Technical Support
- --
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- McAfee Associates, Inc. | Voice (408) 988-3832 | INTERNET:
- 3350 Scott Blvd, Bldg 14 | FAX (408) 970-9727 | mcafee@netcom.COM
- Santa Clara, California | BBS (408) 988-4004 | CompuServe ID: 76702,1714
- 95054-3107 USA | USR HST Courier DS | or GO MCAFEE
- Support for SENTRY/SCAN/NETSCAN/VSHIELD/CLEAN/WSCAN/NETSHIELD/TARGET/CONFIG MGR
-
- ------------------------------------------------------------------------------
- The following is the post Mr. Goretsky is refering to:
- ------------------------------------------------------------------------------
-
- This is an exact copy of a "Broadcast" letter sent to all members and
- affiliates of THIEVCO INC; a group located somewhere in the San Francisco Bay
- Area. While I do not support the general theology of Thievco Inc, I must
- applaud thier actions. Thier warnings about a new virus called PROTO-T, will
- potentially save us computer users possibly thousands of dollars - and
- hundreds of man hours.
- Here is a copy of the broadcast letter, as received from a friend
- at Thievco ...
-
- <<*>> <<*>> <<*>> <<*>> <<*>> <<*>> <<*>> <<*>>
-
- Retrieved BLUWAV 6921 / THIEV 00621*420 - Node 1:8 Sent T-Tymnet
-
- Date : 9/24/92 11:14pm
- To : All Thievco Members, and affil.
- Re : PROTO - T
- Class : Confidential (go public 9-26)
-
-
- Dear Members,
-
- At 7:34PM (pst) our attempt to isolate and contain the PROTO - T
- virus failed. As we have discovered, PROTO - T has a *VERY* unique
- feature, to hide in the RAM of VGA cards, hard disks, and possibly,
- in modem buffers. Unfortunaly, we found out the hard way - after it struck.
- At this time, there is no known defence against this virus, save formatting
- your hard/floppy disks - there isn't even a method of detecting it yet...
- untill its too late. [ PROTO - T specs listed later ].
- Unearthly Vision ( Portland, Oregon ), and Chron ( Alameda, Calif )
- were working on isolating the virus when it struck. Over 900 megabytes
- of information was lost, of that about 214 megabytes is probably recoverable.
-
- Action :
-
- Please assist us in implementing this plan, to warn the general public.
- Our first priority is our fellow THIEVCO members. Please distribute this
- letter to all contacts inside the U.S., upon recipt of this letter.
- Please inform the public on 9-26-92. Start warning the elite boards first,
- followed by the P.D. boards. Dont bother telling known SPA locals, they aren't
- worth our time.
-
- Blue Boar - Distribute the warning in Southern California, start
- with L.A. first.
- Chron - Distribute to San Francisco, Sacramento, and south east coast.
-
- Garfield - Distribute to Fido-Net, Vet-Net, Compuserve, and America
- Online.
-
- Unearthly Vision - Distribute to Oregon, and Washington.
-
- Executioner - Distribute to San Jose, Monterey.
-
-
- --=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=
-
- What is known:
-
- Proto - T was just a rumor, untill it was confirmed a few weeks ago.
- Chron, being the most incredible skip-tracer, traced its origins to a
- college campus in California. There, it was placed into two files.
- The first, is a file called "TEMPLE" - which to our knowledge, has no
- legitimate use; it seems to be a dummy file. The other file, was
- placed in an unathorized version of PKZip by PKWare ( versions 3.0, and 3.1 -
- these are not legitimate versions of PKZip! Quite possibly, these versions
- of PKZip were created, for the reason of distributing PROTO - T ).
-
- Proto - T is very elusive. There is no program known to detect it.
- From what we understand, it will only infect your system if certian
- conditions are met. From what we know, it will infect your system only if
- you run TEMPLE, or PKZip 3.x after 6:00pm. Even doing that wont nessaraly
- cause infection - it took 6 days for Chron and Unearthly Vision to become
- infected. Obviously some other criteria must be met.
- Upon infection, the virus is written (as un-attached file chains), On two
- parts of a hard disk - each capable of running independently without the
- other half.
- After infection, the virus seems to be written into the memory or memory
- routines of a VGA or EGA monitor; or is written into the memory of the hard
- drive, or quite possibly, into a modem - or COM port. Thus excaping most or
- any known detection methods.
-
- PROTO - T :
-
- Proto - T when activated, corrupts data on a disk, stops VGA or EGA
- from being used ( Thus either defaulting to CGA, or locking up ), and
- prohibits memory from being used over 512K.
-
- Known to be put into two files : TEMPLE.EXE ( 14,771 Bytes ) and PKZip 3.x
- (Varries always over 100,000 bytes when zipped). If you see these files -
- do not get or use them.
-
- Give this letter to all Thievco members and thier contacts, followed by
- other boards.
- With luck, we can stop the damage before it *REALLY* starts.
-
- THIEVCO INC, San Francisco Bay Area.
-
-
- Special Thanks for Chron, Unearthly Vision, and Blue Boar for all thier
- help with this "Early warning" and tech help.
-
-