[comp.binaries.ibm.pc.d] Friday the thirteenth virus

poffen@lookitthat (Russ Poffenberger) (10/13/89)

Is anybody out there taking this Friday 13 virus seriously? Has anybody
encountered it yet? What was the result?

Just curious, it has been getting media hype the past couple of days, it was
even on ABC news.

Russ Poffenberger               DOMAIN: poffen@sj.ate.slb.com
Schlumberger Technologies       UUCP:   {uunet,decwrl,amdahl}!sjsca4!poffen
1601 Technology Drive		CIS:	72401,276
San Jose, Ca. 95110
(408)437-5254
-------------------------
In a dictatorship, people suffer without complaining.
In a democracy, people complain without suffering.

bobc@attctc.Dallas.TX.US (Bob Calbridge) (10/14/89)

In article <1989Oct13.150324.19152@sj.ate.slb.com>, poffen@lookitthat (Russ Poffenberger) writes:
` Is anybody out there taking this Friday 13 virus seriously? Has anybody
` encountered it yet? What was the result?
` 
` Just curious, it has been getting media hype the past couple of days, it was
` even on ABC news.
` 
` Russ Poffenberger               DOMAIN: poffen@sj.ate.slb.com
` Schlumberger Technologies       UUCP:   {uunet,decwrl,amdahl}!sjsca4!poffen
` 1601 Technology Drive		CIS:	72401,276
` San Jose, Ca. 95110
` (408)437-5254
` -------------------------
` In a dictatorship, people suffer without complaining.
` In a democracy, people complain without suffering.


Not me.  I've run every kind of virus seeking program and O can saye withouyt
any fear that O everything is cleere on my sistum.  I'm going to try to ruuuuuuuuuuuuun it 
regularly to
             prevent it from hpng in  the feature .!23
O recomment 
            th
               a
                 t
                    e
                      adre\ZZ

B
L
a
t
t
!
-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
=             I know it's petty..........                                     =
-                  But I have to justify my salary!                           -
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

gejohann@uokmax.ecn.uoknor.edu (Gene Edward Johannsen) (10/15/89)

In article <1989Oct13.150324.19152@sj.ate.slb.com> poffen@sj.ate.slb.com (Russ Poffenberger) writes:
>Is anybody out there taking this Friday 13 virus seriously? Has anybody
>encountered it yet? What was the result?
>
>Just curious, it has been getting media hype the past couple of days, it was
>even on ABC news.

The University of Oklahoma took it seriouisly.  Our PC lab was recently beseiged
by the Friday the 13th virus, and all out war was declared.  After we were done,
though, our machines were clean and protected long before the 13th.  We still
held our breath, but everything came out okay.

Gene

mj@hpihoah.HP.COM (Marlin Jones) (10/16/89)

My sister works at a school around here which I probably shouldn't name.
Their PC lab was infected by the virus - but they weren't sure that the
students didn't put the virus there intentionally just to see the "fun".

Marlin Jones    hplabs!hpda!mj

willemk@nijmeg.UUCP (willem kutschruiter) (10/16/89)

In article <1989Oct13.150324.19152@sj.ate.slb.com> poffen@sj.ate.slb.com (Russ Poffenberger) writes:
>Is anybody out there taking this Friday 13 virus seriously? Has anybody
>encountered it yet? What was the result?
>
>Just curious, it has been getting media hype the past couple of days, it was
>even on ABC news.
>
>Russ Poffenberger               DOMAIN: poffen@sj.ate.slb.com
>Schlumberger Technologies       UUCP:   {uunet,decwrl,amdahl}!sjsca4!poffen
>1601 Technology Drive		CIS:	72401,276
>San Jose, Ca. 95110
>(408)437-5254


The "DATACRIME I" virus is discovered in the Netherland firstime
somewhere in March 1989 on a BBS system.
There are two version speed out.
I do not know the difference between the versions.
I will breifly describe what it should do.
	- released on the 1st of March 1989
	- It will notify not when activated as follows
		- "DATACRIME VIRUS RELASED 1 MARCH 1989"
		- text is decoded in the program
	- It starts infecting other programs after the 1st of April
	- It infects on .COM files.
	- On and after Friday the 13th October it will format a couple
	  cylinders on the hard disk and destroy the FAT.

Due to the early discovery of the virus it did not spread out widely.
There was also a delete and detection program developed onder the name
" No-Crime"
Unfortunally the author of datacrime I got also a copy of this No-Crime program
and wrote an other virus called "DATACRIME II".

The difference between "I " and "II" are not that much.
Datacrime II starts a day earlier and is more complex so therefor more difficult
to detect.
Datacrime II infects  both .COM and .EXE files.
There is no starting date which kick off the infection.

Here are the signatures for the Datacrime virussen.
DATACRIME Ia	8b36010183ee038bc63d00007503e9fe00
DATACRIME Ib	8b36010183ee038bc63d00007503e90201

DATACRIME II	5e81ee030183fe00742a2e8a9403018dbc29018d8cea
		068d9c38012bcb

You can search your disk for the Hex strings to find out if you have an
an infected disk.

This is only interesting if you put back your system clock or if your 
system is not booted after the 12th of October.

Good Luck.
				Regards,


				Willem Kutschruiter.
				Intergraph EM B.V.
	 			P.O. Box 6552
				6503 GB Nijmegen, The Netherlands.
				Mp ingr!nijmeg!willemk

Hardware = software

wozniak@utkux1.utk.edu (Bryon Lape) (10/17/89)

	It more or less sneezed here in the US, but in the UK, a couple
of places got files wiped out.


-bryon-