home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!elroy.jpl.nasa.gov!usc!cs.utexas.edu!qt.cs.utexas.edu!yale.edu!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: riordan@tmxmelb.mhs.oz.au (Roger Riordan)
- Newsgroups: comp.virus
- Subject: Clash between FDISK/MBR and scanners (PC)
- Message-ID: <0007.9301051858.AA13030@barnabas.cert.org>
- Date: 24 Dec 92 01:55:07 GMT
- Sender: virus-l@lehigh.edu
- Lines: 35
- Approved: news@netnews.cc.lehigh.edu
-
- The command FDISK /MBR is often recommended for removing MBR
- infectors (Stoned, etc) from hard disks. However in some
- circumstances this can cause problems with some scanners. It
- appears that some versions of FDISK/MBR rewrite the Master Boot
- Record only as far as the end of the error messages, leaving the all
- important partition information unchanged, but also leaving any
- viral code between the messages and the partition information.
-
- This will cause problems if the user later scans the disk with a
- scanner which uses a string in this area to detect the virus.
-
- In our case VET reported that the MBR of a PC was infected, and the
- recovered copy of the MBR was also infected, but the PC booted OK,
- the top of memory was OK, the virus was not in memory, and the PC
- did not infect floppies. The main part of the MBR seemde normal,
- but code from Stoned followed the messages. It appears that the PC
- had twice been infected with Stoned, and each time it had been
- removed using FDISK/MBR. Thus both the MBR, and the copy saved by
- Stoned, contained viral code, which included the template used by
- VET.
-
- FPROT reported the infected MBR as
- Master boot sector: Possibly a new varient of Stoned.
-
- SCAN, Dr. S Toolkit, did not report any virus.
-
- We understand that FDISK was definitely run on this PC, but we could
- not confirm that FDISK was responsible, as it cleared this part of
- the MBR when we used it to remove Stoned from an experimentally
- infected PC.
-
- Roger Riordan riordan.cybec@tmxmelb.mhs.oz.au
-
- CYBEC Pty Ltd. Tel: +613 521 0655
- PO Box 205, Hampton Vic 3188 AUSTRALIA Fax: +613 521 0727
-