home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!olivea!spool.mu.edu!caen!uakari.primate.wisc.edu!ames!pacbell.com!iggy.GW.Vitalink.COM!cs.widener.edu!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: mcampbel@nyx.cs.du.edu (Matthew Campbell 'The Fire Fox')
- Newsgroups: comp.virus
- Subject: Now I know I have something. (PC)
- Message-ID: <0015.9209111901.AA28207@barnabas.cert.org>
- Date: 11 Sep 92 07:24:17 GMT
- Sender: virus-l@lehigh.edu
- Lines: 77
- Approved: news@netnews.cc.lehigh.edu
-
- VIRSTOP was installed as a device driver in Config.Sys right after
- Himem.Sys
-
- Later I tried installing VIRSTOP from the command line and it said:
-
- >VIRSTOP cannot be installed
- >This may be caused by an active virus or an incompatible DOS
- >
- >C:\VIRUS> f-prot.exe
- >Program infected with the [= ] Virus.
- >File access terminated. (A couple weird characters)(Control-Z) and a
- > halted system.
-
- I had just unzipped fp-205.zip from a clean, write-protected floppy
- disk; however, I didn't happen to boot with one. Has this ever
- happened to anyone else before? After killing the power for about a
- minute, I rebooted with a clean, write-protected floppy disk and
- scaned the drive with a different disk on which the scanner files were
- already expanded, (Not Zipped). I also scanned the other disks that
- came in contact, but no viruses were detected. I got my F-PROT from
- wuarchive. Is F-PROT supposed to have -AV with the files when
- unzipped? Mine doesn't.
-
- SCANNING RESULTS:
-
- Scanner used: F-PROT v205
- Infected: 0
- Suspicious: 12 (Mostly .ini and .cnf files)
- Disinfected: 0
- Scanning: Hard Disks
- Method: Heuristics
- Scanning: All files
- Message: This is either a corrupted program or one which contains
- instructions wich do not exist on all 80x86 processors.
- It will crash on some machines.
-
- -- text files were noted as suspicious such as NEW.205, SCAN.DOC,
- LANGUAGE.DOC, CONFIG.SYS, AUTOEXEC.BAT, and all scan.crc files.
- (scan.crc files are files made with McAfee's scanv95b.zip scanner.)
- (/af scan.crc)
-
- Scanner used: SCAN 8.7B95 McAfee
- Options: C: /a /m /chkhi
- Infected: 0
- Suspicious: 0
-
- A disk editor revealed extra garbage added to the ends of the
- suspicious files as named by F-PROT v205. The extra stuff held two
- sectors or less. The file names EMM386.EXE and SMARTDRV.EXE were
- added to the end of LANGUAGE.DOC which were two files that the
- computer uses in the boot up. You should see the end of the
- Config.Sys.... What a mess. Some hex codes include:
-
- 89 97 88 89 99 A8 89 FF CF 89 9D E8 89 9F 08 8A
- A1 28 8A A3 48 8A A5 68 8A A7 88 8A A9 A8 8A AB
- C8 8A AD E8 8A AF 08 8B B1 28 8B B3 48 8B B5 68
- 8B B7 88 8B B9 A8 8B BB C8 8B BD E8 8B BF 08 8C
- C1 28 8C C3 48 8C C5 68 8C C7 88 8C C9 A8 8C CB
- C8 8C CD E8 8C FF FF FF D1 28 8D D3 48 8D D5 68
- 8D D7 88 8D D9 A8 8D DB C8 8D DD E8 8D DF 08 8E
- E1 28 8E E3 48 8E E5 68 8E E7 88 8E E9 F8 FF EB
- F8 FF ED E8 8E EF 08 8F F1 28 8F F3 48 8F F5 68
- 8F F7 88 8F F9 A8 8F FB C8 8F FD E8 8F FF 08 90
- 01 29 90 03 49 90 05 69 90 FF 0F
-
- For the next two sectors it had something that looked like a data file
- containing names of viruses like: Violator, Stoned, Vienna, Hydra, and
- had names of the current scanners, characteristics of viruses, the
- months of the year, and some names of some countries.
-
- What should I do?
-
- - --
- Matthew Campbell 'The Fire Fox'
- Internet: MatthewCal@Ids.Net MCampbel@Nyx.Cs.Du.Edu
- Ugcsmc0084%Mtvms2.Dnet@Terra.Oscs.Montana.Edu
- A thought to remember: "The only way to God is through his son Jesus Christ."
-