home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!spool.mu.edu!howland.reston.ans.net!zaphod.mps.ohio-state.edu!cis.ohio-state.edu!news.sei.cmu.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: Jerusalem (Israeli) Virus (PC)
- Message-ID: <0014.9301121242.AA22066@barnabas.cert.org>
- Date: 7 Jan 93 13:22:52 GMT
- Sender: virus-l@lehigh.edu
- Lines: 46
- Approved: news@netnews.cc.lehigh.edu
-
- bill.lambdin%acc1bbs@ssr.com (Bill Lambdin) writes:
-
- > Jerusalem B is a file infector. It runs as a TSR, and will infect every
- > executable file you run except for .COM files larger than 62K. I believe
- > the virus is around 1800 bytes long.
-
- First, there is not such thing as "Jerusalem B". Even SCAN does not
- call any virus like that anymore... The Jerusalem family of viruses
- contains many variants. You are probably speaking about the most
- widespread one, which is 1808+5 bytes long and infects EXE files
- multiple times (until they get too big to fit in memory).
-
- > McAfee's Clean can remove this virus fairly easy to remove. It would be a
-
- Due to the infection method that this virus employs, it destroys EXE
- files with internal overlay structure (e.g., WordPerfect). Such files
- will crash when executed. They will still crash after disinfection,
- although McAfee's Clean does not warn you about that. If you have an
- outbreak of this virus, the best solution is to delete all infected
- files and to replace them with clean copies.
-
- > very good idea to re-boot the computer from a known clean bootable
- > diskette. If you don't have a clean bootable diskette, go ahead and type
- > the following on the command line.
- >
- > CLEAN C: [JERU]
- >
- > after Clean gets finished, turn your computer off for a few seconds, then
- > back on. The reason for this is that since Jerusalem-B runs as TSR. After
- > the computer is clean, make a bootable diskette, then place a write
- > protect tab on the notch. Then the next time you have another virus, you
- > will be ready.
-
- If he follows your advise literally, the "next time" he will run a
- CLEAN.EXE infected with the virus and will spread the infection again.
- The correct advice is to emphasize that at least the program CLEAN
- must be run from a write-protected diskette, if you are unable to boot
- from a clean environment...
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-