[comp.virus] Original-Equipment Viruses

Sandy=OToole%COMPUTER%UMASS@server2.UMMED.EDU (05/07/91)

I would like to get more information on viruses originating from
manufacturers, such as Packard Bell recently.  Is this widespread with
this particular company? What has been the remedy to this situation?
Should purchasers scan new software for viruses before using?

padgett%tccslr.dnet@mmc.com (A. Padgett Peterson) (05/09/91)

>I would like to get more information on viruses originating from
>manufacturers, such as Packard Bell recently.  Is this widespread with
>this particular company?

Reports concerning infected distribution disks (COMBASE, SVGA, & TVGA)
are still coming in, six months after the first discovery.

>What has been the remedy to this situation?

Floppies: Replace the boot record

Hard Disk:

MusicBug:
a) Format the disk - PB is said to be supplying a special version of DISK
   MANAGER to people with IDE drives. Lose all data
or
b) Replace the boot sector (boot cold from floppy, SYS the HD, correct the
   number of hidden sectors in the BPB)

Azusa:
a) Low level format the hard disk - see a) above
or
b) Boot cold from floppy then rebuild the partition table manually

Note that in every case I have seen, it has been possible to recover nearly
all of the information on a disk and formatting has not been necessary.

>Should purchasers scan new software for viruses before using?

I do & now have quite a collection of "master" disks containing
viruses, most came on distribution disks with hardware, not in
software packages. These include the STONED, AIRCOP, AZUSA, & MUSICBUG
(all so far have been boot sector and partition table infectors). Have
yet to contact a vendor who has shown any concern about distributing
viruses (subjective opinion) beyond offering to replace disks.
                                                   Warmly,
                                                           Padgett