#Stoned Virus
25 messages in this thread
Argh! One of my vendors gave me the "Stoned" virus today on a disk. Now
it's in my system. (Un)Luckily, I have never had a virus so I am not sure
what to do. Can anyone give me a suggested procedure?
Ken Loss-Cutler
I had to deal with this about 2 months ago… The Norton anti-virus
software did a good job getting rid of it, but most other innoculators will
deal with it as well. I've heard estimates as high as 35% of all business
PC users are infected with this one.
– G
Gary:
I tried out a bunch of anti-virus programs. You may want to consider a
different program than Norton Anti-Virus. The Norton program creates a
checksum file for every executable file that it checks (ie. EXE, COM, SYS,
BIN, PIF, etc.). Depending on your hard disk's sector size, these files can
be as large as 8KB each. If you've got a large hard disk with lots of
programs, you can easily use up nearly 1MB in checksum files. Some of the
other virus scan programs use one single checksum file. For example, the one
I use (and I can't remember the name of it) requires that you manually add
each program you want scanned in the data file.
David
Thanks for the info, David. I think that the Norton program provides a
switch for turning off the checksum file, but since I only used it once,
I'm pretty unfamiliar with it. I've heard great things about the McAfee
tools, and likewise about the Central Point utilities.
– G
Hi,
Let me put in two cents. McAfee SCAN works!!
One of my clients passed me the stoned recently on a disk and SCAN caught
it before it got in my hard disk plus I was able to eradicate it from the
sick diskette then use the clients files.
Johns number is 408 988-3832 bulletin board is 408 988-4004
will
Ken,
Get yourself over to the VIRUSFORUM on CIS. This is McAfee's forum and has
all their programs on it from their bbs. The big problem will be in
downloading these programs without infecting the downloads. Maybe you can
get temporary access to a clean machine.
I'd take the vendor's head off. There is only one reason a vendor would
infect someone's machine………..stupidity.
Thanks for the advice. I will get onto VIRUSFORUM with my Amiga and DOS
the needed program over to the Everex. I agree, incidently, there is NO
excuse for a service that makes a living exporting files to other people's
machines to export viruses with them.
Ken Loss-Cutler
Ken,
I recommend the McAfee virus scanner & cleaner programs on the
VIRUSFORUM. The command for CLN84.ZIP (the extractor) is CLEAN C:
[STONED]. Note: the virus infects the partition table, so a low-level
format will get rid of it (not useful for those with IDE drives), but not
re-partitioning or a FORMAT. The virus remover *CAN* blow your partition
(losing all data anyway) so back the sucker up, bad as it is. My customer
was lucky, and removal was clean.
Kevin Krell – Computer Support Associates
I would recommend getting McAfee's latest virus utilities SCAN and CLEAN.
These will definately do the job for you.
McAfee Associates (408) 988-3832 Telephone
4423 Cheeney Street (408) 970-9727 FAX
Santa Clara, CA 95054-0253 (408) 988-4004 BBS 2400 bps
U.S.A. (408) 988-5138 BBS HST 9600
(408) 988-5190 BBS v32 9600
CompuServe GO VIRUSFORUM
InterNet mcafee@netcom.com
Good luck,
Ggg
Well, thanks everyone for the good advice. As it stands, I will be
spending the better part of a day (interrupting a heavy work schedule) in
order to backup 200Meg onto tapes, zap the virus, and rebuild the disk. I
know it is naiive to expect the vendor who gave me the virus to compensate
me in any way <g>, but I am irked that there seems to be a lack of
responsibility on the part of organizations who make their living providing
digital data to others but do not "keep a clean house". Frankly, at a
minimum, he should cancel his invoice to me for his "services" (only about
$50, but there IS a principle involved here). I would like to hear from
others, both digital service providers and buyers, on this issue. Do you
think that there needs to be an "ethic" evolved in such matters? What
should it be?
Ken Loss-Cutler
Ken,
handle your backup carefully. Remember that you backed up the virus, too! So
only restore data files – no executables – from the backup.
Dietmar
Dietmar:
I'm glad someone pointed that out to Ken. I've seen people put the virus
right back onto their systems.
David
My understanding was that the Stoned Virus only attacked the partition
table and, as such, did not directly influence the executeables. Is this
wrong?
Ken Loss-Cutler
Ken,
I don't know about this special virus, so you'd better go to the VIRUSFORUM
to ask about that.
In general, there are only two way, a virus can "distribute" itself and that
is either by appending itself to the operating system on the boot disk (so
called boot virus) or by appending itself to any executable file it finds.
Because boot viruses can only infect a machine when the computer is booted
with an infected floppy, most viruses use the other way to copy itself.
Whether the virus attackes and destroyes the partition table, COM files,
EXE files, or just the computer's RAM contents, has nothing to do with the
way it distributes itself.
Dietmar
Ken,
If you're fortunate, you will not need to (and thus should not)
restore after eradicating the Stoned virus. Stoned infects memory and the
partition table, and McAfee SCAN will check if it's in any files. The
backup is in case it cannot be extracted cleanly.
Kevin Krell – Computer Support Associates
Thanks, Kevin, for your prayers <g>. I, too, hope not to have to restore
as I have not backed up all the executeables and some not-so-important
files. I am keeping my digits crossed.
Ken Loss-Cutler
A post-script. James came by today to offer a sympathetic hand. We backed
up everything we could, made some clean disks using the McAfee programs
from the CIS Virusforum, rubbed a few crystals and assorted gemstones, and
typed in the command to clean the partition tables. Not only was "Stoned"
removed, but the Cleanup program found another memory-resident virus,
Azusa, (apparently created after our version of Scan) and removed it too.
Praise St. Silicon, neither 300Meg harddrive required rebuilding. You can
bet that we will have the cleanest house in town from now on. Thanks to
everyone here who offered us moral support during this harrowing
experience.
Ken Loss-Cutler
Ken:
Congrat's on the successful exorcism! <g>
Larry
Ken,
If you have the updated SCAN program, make sure to run that AGAIN
over the drive, and re-check the files. If the CLEAN program found a
memory-resident virus, you need to make sure that no files on your disk put
it there.
Kevin Krell – Computer Support Associates
Thanks, Kevin. We are acquiring the updated SCAN.
Ken Loss-Cutler
Ken,
Glad to read that you got out of a very bad situation.
About a year ago I bought a 386 with a HD from a store and after five days
of going crazy trying to get everything to work (I had intermittant
problems), I finally ran McAfee's SCAN & CLEAN to find and remove a
Jerusalem virus.
When I told the computer store people about it, they said, "Oh, we thought
we had gotten rid of that virus." It had been put onto the HD when they
formatt ed it. I told them how to scan & clean with MacAfee but they told
me that "it was impossible for them to check all their computers and all
their disks." Too much trouble, they said! So, I assume they've just been
continually sellinginfected computers.
They didn't feel any responsibilty for the problem. "The virus comes from
customers who bring it into the store, not from us" they told me. I keep
well away from there. I use VSHIELD as a TSR and I am very aware of the
virus potential now as I'm sure you are. Funny, many people who have not
been hit seem to regard viruses as something in the papers that only "other
people" getwr Keep clean,
Alec Jason
Yes, Alec, the metaphor to human disease is startling. Had I not been
lucky with my treatment, I would probably have gone thru the entire denial-
grief – deals – acceptance sequence experienced by the terminally ill. To
further paraphrase, I am sending money to McAfee for their excellent
product and will continue to fight virues in our workplace with "a checkup
and a check". <g>
Ken Loss-Cutler
Ken, One thing I forget to mention: be sure to SCAN any floppies which
might have been in a drive.
And let's practice "safe computing." <g>
Alec Jason
Thanks, Alec. We are installing a TSR version of McAfee's SCAN program to
check any floppy which comes within 4 feet of our drives <g>. The latest
version also detects staphlococci in proximate users and prescribes the
appropriate dose of penicillin. We ain't takin no chances.
Ken Loss-Cutler