[comp.sys.ibm.pc] FLUSHOT2.ARC Virus

dbraun@cadev4.intel.com (Doug Braun ~) (01/29/88)

In article <7188@brl-smoke.ARPA> w8sdz@brl.arpa (Keith B. Petersen (WSMR|towson) <w8sdz>) writes:
>
>It was to counter just such a program that the enclosed program,
>called FLU_SHOT, was developed.

This sounds like a really excellent idea.  But this kind of program,
more than any other, deserves to have its source posted as well.
This way, people can be absolutely sure the shot is not also a virus.
Not that it is now, but someone could make one and distribute under
the same name.  Is there any way the source could be made available?


Doug Braun				Intel Corp CAD
					408 496-5939

 / decwrl \
 | hplabs |
-| oliveb |- !intelca!mipos3!cadev4!dbraun
 | amd    |
 \ qantel /

rbhq@nesac2.UUCP (Ron Beck) (02/02/88)

Be careful with Flushot2!!!! I was using MKS Toolkit, doing a cp command
and Flushot2 reapeatedly asked for verification. When all was said and
done I locked up. I couldn't reboot to C drive because command.com was
GONE!!!!!!!!!!!!!!
Just thought I'd let you know.

-- 
Ron Beck		201-234-8494
Bedminster, N.J.	nesac2!rbhq

mollusk@squid.UUCP (02/05/88)

From squid!mollusk Fri Feb 05 00:27 CDT 1988 remote from occrsh
Subject: Re: FLUSHOT2.ARC Virus (Trojan) protection program

>PLEASE! send any replies to: {ihnp4,moss,cbosgd,uokmax}!occrsh!squid!david

=In article <7188@brl-smoke.ARPA> w8sdz@brl.arpa (Keith B. Petersen (WSMR|towson)
=>
=>It was to counter just such a program that the enclosed program,
=>called FLU_SHOT, was developed.
=
=This sounds like a really excellent idea.  But this kind of program,
=more than any other, deserves to have its source posted as well.
=This way, people can be absolutely sure the shot is not also a virus.
=Not that it is now, but someone could make one and distribute under
=the same name.  Is there any way the source could be made available?
=
=
=Doug Braun                              Intel Corp CAD
=                                        408 496-5939

Hear! Hear! Posting a uucoded trojan/virus to comp.sys.ibm.pc while flying
false colors would be a very simple way of trashing a *LOT* of systems, and
getting away with it. There is a newsgroup for binaries, where all of them
are tested before they are released. And why post the binary without the
source, if you wrote it yourself, and the program is pd? Aren't hackers
proud of their code anymore?

And while I've got your attention... The bbs in my signat has *lots* of C
source, and a few binaries (and all the binaries are *tested*), including
UUPC, DCP and Binkley.

 David Drexler
 ______________________________________________________________
 WoofNet:    1:147/1
 Usenet:     {ihnp4,cbosgd,moss,uokmax}!occrsh!squid!david
 SneakerNet: Bethany OK USA 73008-1214
 Direct:     [405] 728-2463 (2.4/1.2/.3 Kbaud) A SourceCode BBS

mollusk@squid.UUCP (02/06/88)

From squid!mollusk Fri Feb 05 18:04 CDT 1988 remote from occrsh
Subject: re: FLUSHOT2

>PLEASE! send any replies to: {ihnp4,moss,cbosgd,uokmax}!occrsh!squid!david

+ From: rbhq@nesac2.UUCP (Ron Beck)
+ Date: 1 Feb 88 16:24:29 GMT
+
+ Be careful with Flushot2!!!! I was using MKS Toolkit, doing a cp command
+ and Flushot2 reapeatedly asked for verification. When all was said and
+ done I locked up. I couldn't reboot to C drive because command.com was
+ GONE!!!!!!!!!!!!!!
+ Just thought I'd let you know.

When it comes to pd/shareware, especially binaries from this newsgroup, or
from bulletin boards where the sysop can't be bothered to test them, you
loads your files, and takes your chances.

If you didn't compile it yourself, or you don't know the author personally,
have faith in the quality of his/her work and can be sure s/he wrote the
version you have, your good faith will eventually be your undoing. Remember
GT-"POWER"COM, the bogus, trojanned version of ARC and Dutchie, and the
supposed virus that is infecting the COMMAND.COM's of the world...

Let 'em eat source!

 David Drexler
 ______________________________________________________________
 WoofNet:    1:147/1
 Usenet:     {ihnp4,cbosgd,moss,uokmax}!occrsh!squid!david
 SneakerNet: Bethany OK USA 73008-1214
 Direct:     [405] 728-2463 (2.4/1.2/.3 Kbaud) A SourceCode BBS