CompuServe Thread

#Stoned Virus

25 messages in this thread
#7909From: Ken Loss-CutlerJan 17, 1992 11:02 PM
Argh! One of my vendors gave me the "Stoned" virus today on a disk. Now it's in my system. (Un)Luckily, I have never had a virus so I am not sure what to do. Can anyone give me a suggested procedure? Ken Loss-Cutler
#7911From: Yost GroupJan 17, 1992 11:10 PM
I had to deal with this about 2 months ago… The Norton anti-virus software did a good job getting rid of it, but most other innoculators will deal with it as well. I've heard estimates as high as 35% of all business PC users are infected with this one. – G
#7935From: David Cohn, CADalystJan 18, 1992 1:45 PM
Gary: I tried out a bunch of anti-virus programs. You may want to consider a different program than Norton Anti-Virus. The Norton program creates a checksum file for every executable file that it checks (ie. EXE, COM, SYS, BIN, PIF, etc.). Depending on your hard disk's sector size, these files can be as large as 8KB each. If you've got a large hard disk with lots of programs, you can easily use up nearly 1MB in checksum files. Some of the other virus scan programs use one single checksum file. For example, the one I use (and I can't remember the name of it) requires that you manually add each program you want scanned in the data file. David
#7962From: Yost GroupJan 18, 1992 7:06 PM
Thanks for the info, David. I think that the Norton program provides a switch for turning off the checksum file, but since I only used it once, I'm pretty unfamiliar with it. I've heard great things about the McAfee tools, and likewise about the Central Point utilities. – G
#7972From: will taitJan 18, 1992 10:06 PM
Hi, Let me put in two cents. McAfee SCAN works!! One of my clients passed me the stoned recently on a disk and SCAN caught it before it got in my hard disk plus I was able to eradicate it from the sick diskette then use the clients files. Johns number is 408 988-3832 bulletin board is 408 988-4004 will
#7920From: Joe MacRaeJan 18, 1992 10:16 AM
Ken, Get yourself over to the VIRUSFORUM on CIS. This is McAfee's forum and has all their programs on it from their bbs. The big problem will be in downloading these programs without infecting the downloads. Maybe you can get temporary access to a clean machine. I'd take the vendor's head off. There is only one reason a vendor would infect someone's machine………..stupidity.
#7929From: Ken Loss-CutlerJan 18, 1992 12:06 PM
Thanks for the advice. I will get onto VIRUSFORUM with my Amiga and DOS the needed program over to the Everex. I agree, incidently, there is NO excuse for a service that makes a living exporting files to other people's machines to export viruses with them. Ken Loss-Cutler
#7943From: CSA/CAJan 18, 1992 2:58 PM
Ken, I recommend the McAfee virus scanner & cleaner programs on the VIRUSFORUM. The command for CLN84.ZIP (the extractor) is CLEAN C: [STONED]. Note: the virus infects the partition table, so a low-level format will get rid of it (not useful for those with IDE drives), but not re-partitioning or a FORMAT. The virus remover *CAN* blow your partition (losing all data anyway) so back the sucker up, bad as it is. My customer was lucky, and removal was clean. Kevin Krell – Computer Support Associates
#7954From: Gregg PlummerJan 18, 1992 4:41 PM
I would recommend getting McAfee's latest virus utilities SCAN and CLEAN. These will definately do the job for you. McAfee Associates (408) 988-3832 Telephone 4423 Cheeney Street (408) 970-9727 FAX Santa Clara, CA 95054-0253 (408) 988-4004 BBS 2400 bps U.S.A. (408) 988-5138 BBS HST 9600 (408) 988-5190 BBS v32 9600 CompuServe GO VIRUSFORUM InterNet mcafee@netcom.com Good luck, Ggg
#7981From: Ken Loss-CutlerJan 19, 1992 12:38 AM
Well, thanks everyone for the good advice. As it stands, I will be spending the better part of a day (interrupting a heavy work schedule) in order to backup 200Meg onto tapes, zap the virus, and rebuild the disk. I know it is naiive to expect the vendor who gave me the virus to compensate me in any way <g>, but I am irked that there seems to be a lack of responsibility on the part of organizations who make their living providing digital data to others but do not "keep a clean house". Frankly, at a minimum, he should cancel his invoice to me for his "services" (only about $50, but there IS a principle involved here). I would like to hear from others, both digital service providers and buyers, on this issue. Do you think that there needs to be an "ethic" evolved in such matters? What should it be? Ken Loss-Cutler
#7988From: Dietmar RudolphJan 19, 1992 3:51 AM
Ken, handle your backup carefully. Remember that you backed up the virus, too! So only restore data files – no executables – from the backup. Dietmar
#7999From: David Cohn, CADalystJan 19, 1992 3:57 PM
Dietmar: I'm glad someone pointed that out to Ken. I've seen people put the virus right back onto their systems. David
#8015From: Ken Loss-CutlerJan 19, 1992 9:38 PM
My understanding was that the Stoned Virus only attacked the partition table and, as such, did not directly influence the executeables. Is this wrong? Ken Loss-Cutler
#8026From: Dietmar RudolphJan 20, 1992 2:02 AM
Ken, I don't know about this special virus, so you'd better go to the VIRUSFORUM to ask about that. In general, there are only two way, a virus can "distribute" itself and that is either by appending itself to the operating system on the boot disk (so called boot virus) or by appending itself to any executable file it finds. Because boot viruses can only infect a machine when the computer is booted with an infected floppy, most viruses use the other way to copy itself. Whether the virus attackes and destroyes the partition table, COM files, EXE files, or just the computer's RAM contents, has nothing to do with the way it distributes itself. Dietmar
#8040From: CSA/CAJan 20, 1992 1:02 PM
Ken, If you're fortunate, you will not need to (and thus should not) restore after eradicating the Stoned virus. Stoned infects memory and the partition table, and McAfee SCAN will check if it's in any files. The backup is in case it cannot be extracted cleanly. Kevin Krell – Computer Support Associates
#8062From: Ken Loss-CutlerJan 20, 1992 9:40 PM
Thanks, Kevin, for your prayers <g>. I, too, hope not to have to restore as I have not backed up all the executeables and some not-so-important files. I am keeping my digits crossed. Ken Loss-Cutler
#8118From: Ken Loss-CutlerJan 22, 1992 12:02 AM
A post-script. James came by today to offer a sympathetic hand. We backed up everything we could, made some clean disks using the McAfee programs from the CIS Virusforum, rubbed a few crystals and assorted gemstones, and typed in the command to clean the partition tables. Not only was "Stoned" removed, but the Cleanup program found another memory-resident virus, Azusa, (apparently created after our version of Scan) and removed it too. Praise St. Silicon, neither 300Meg harddrive required rebuilding. You can bet that we will have the cleanest house in town from now on. Thanks to everyone here who offered us moral support during this harrowing experience. Ken Loss-Cutler
#8127From: Larry Beck [Windows TM]Jan 22, 1992 9:20 AM
Ken: Congrat's on the successful exorcism! <g> Larry
#8139From: CSA/CAJan 22, 1992 12:47 PM
Ken, If you have the updated SCAN program, make sure to run that AGAIN over the drive, and re-check the files. If the CLEAN program found a memory-resident virus, you need to make sure that no files on your disk put it there. Kevin Krell – Computer Support Associates
#8151From: Ken Loss-CutlerJan 22, 1992 9:02 PM
Thanks, Kevin. We are acquiring the updated SCAN. Ken Loss-Cutler
#8141From: alec jasonJan 22, 1992 12:53 PM
Ken, Glad to read that you got out of a very bad situation. About a year ago I bought a 386 with a HD from a store and after five days of going crazy trying to get everything to work (I had intermittant problems), I finally ran McAfee's SCAN & CLEAN to find and remove a Jerusalem virus. When I told the computer store people about it, they said, "Oh, we thought we had gotten rid of that virus." It had been put onto the HD when they formatt ed it. I told them how to scan & clean with MacAfee but they told me that "it was impossible for them to check all their computers and all their disks." Too much trouble, they said! So, I assume they've just been continually sellinginfected computers. They didn't feel any responsibilty for the problem. "The virus comes from customers who bring it into the store, not from us" they told me. I keep well away from there. I use VSHIELD as a TSR and I am very aware of the virus potential now as I'm sure you are. Funny, many people who have not been hit seem to regard viruses as something in the papers that only "other people" getwr Keep clean, Alec Jason
#8152From: Ken Loss-CutlerJan 22, 1992 9:02 PM
Yes, Alec, the metaphor to human disease is startling. Had I not been lucky with my treatment, I would probably have gone thru the entire denial- grief – deals – acceptance sequence experienced by the terminally ill. To further paraphrase, I am sending money to McAfee for their excellent product and will continue to fight virues in our workplace with "a checkup and a check". <g> Ken Loss-Cutler
#8170From: alec jasonJan 23, 1992 1:51 AM
Ken, One thing I forget to mention: be sure to SCAN any floppies which might have been in a drive. And let's practice "safe computing." <g> Alec Jason
#8192From: Ken Loss-CutlerJan 23, 1992 10:51 PM
Thanks, Alec. We are installing a TSR version of McAfee's SCAN program to check any floppy which comes within 4 feet of our drives <g>. The latest version also detects staphlococci in proximate users and prescribes the appropriate dose of penicillin. We ain't takin no chances. Ken Loss-Cutler
#8304From: will taitJan 27, 1992 1:30 AM
Hi Ken, Once is enough aint it? These things seem to get passed around so the ONLY way to deal with it is to do it yourself. Here at turtle moon we scan everything from every customer always. congratulations on a good cleanup. will