home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!gatech!darwin.sura.net!jvnc.net!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: cjkuo@ccmail.norton.com (Jimmy Kuo)
- Newsgroups: comp.virus
- Subject: Re[2]: Stoned Virus (PC)
- Message-ID: <0013.9212221358.AA03720@barnabas.cert.org>
- Date: 21 Dec 92 23:27:59 GMT
- Sender: virus-l@lehigh.edu
- Lines: 30
- Approved: news@netnews.cc.lehigh.edu
-
- mrosen@nyx.cs.du.edu (Michael Rosen) writes:
- >I've encountered what seems to be a new variant of stoned (according
- >to a guy who works in the computer center here) on my diskettes when I
- >use them in our computer labs occassionally. Norton Anti-Virus sees
- >as it as my boot sector being infected by Bloomington, while f-prot
- >says I have stoned. According to f-prot's files in viruses,
- >Bloomington is a cousin to stoned.
-
- What NAV reports as Bloomington is more commonly known as NoInt and has
- since had its name changed in NAV to NoInt. NoInt is a stoned variant.
-
- >The guy I spoke to is sending my diskette to the author of f-prot.
- >It's quite annoying; it creates invisible junk files on my diskettes.
- >I'll get a file name on there with portions of garbage characters and
- >some partial words like "DOS 5.0" or other words. Just recently it
- >destroyed a bunch of files that thankfully I couldn't find again,
- >though it was a major pain.
-
- Your data corruption is likely the result of the virus overwriting one of
- the sectors with its saved copy of the original boot sector. The original
- boot sector looks to have been written over a sector that serves as your
- directory sector thus creating a number of strange looking files. It is
- not that you have invisible junk files on your diskettes but rather the
- directory table is bad. (Garbage in certain fields that get translated as
- file names, garbage in other fields that translated into where the supposed
- file begins...) You can edit the directory to eradicate the bad filenames
- or better yet, copy off the files you know and reformat the diskettes.
-
- Jimmy Kuo cjkuo@ccmail.norton.com
- Norton AntiVirus Research
-