C 2/50: Has anyone heard... Name: Lady Danica #237 @5297 Date: Tue Oct 08 07:42:46 1991 From: -=*The BD BORD*=- [DREM] [PH] [512-442-7883] [STATUS:] Reply Wanted. of a new one called DIR-B? Supposedly it's so new that it's not detected by any of the current programs... -----]-- Lady Danica - Renunciate's Guild [ORIGIN] -=THE BAD BOARD AUSTIN=- *WWIVnet @5297* -=64 Msg Subs & 30 Online Games!=- Take The Plunge At (512)442-7883 300/1200/2400 Baud 3/50: homie dont speak that Name: Sunstriker #1 @5297 Date: Tue Oct 08 11:36:37 1991 From: -=*The BD BORD*=- [DREM] [PH] [512-442-7883] [REPLY TO:] Salut [STATUS:] Reply Not Needed. sigh [ORIGIN] -=THE BAD BOARD AUSTIN=- *WWIVnet @5297* -=64 Msg Subs & 30 Online Games!=- Take The Plunge At (512)442-7883 300/1200/2400 Baud 4/50: Dark Avenger Name: The Controller #256 @5297 Date: Tue Oct 08 22:42:44 1991 From: -=*The BD BORD*=- [DREM] [PH] [512-442-7883] [STATUS:] Reply Wanted. Has anyone out there had any experience with the Dark Avenger virus? I think I have two strains of it. One is called Dark Avenger, and the other is Dark Avenger 2000. Problem is, SCANV82 only detects Dark Avenger. So does CLEAN82. I found the other strain using a different scanning program. I finally traced the DA 2000 virus down to one file, but SCAN said that it was clean. But if I ran the file, SCAN detected it in memory, but still not on disk. Needless to say, I deleted the file, but I'm worried about other files that might be infected in the same way. I don't have access to the program that found it anymore. Any suggestions? I need to know where to get other anti-virus programs besides SCAN and CLEAN. I also need to know where the newest version of VSHIELD can be obtained. Anyone? Anyone ? HELP! Thanks, The Controller [ORIGIN] -=THE BAD BOARD AUSTIN=- *WWIVnet @5297* -=64 Msg Subs & 30 Online Games!=- Take The Plunge At (512)442-7883 300/1200/2400 Baud 5/50: Im Beta Testing it, somewhat.. Name: Ghost Wheel #1 @9709 Date: Tue Oct 08 23:38:26 1991 From: The City Of Avalon [907-443-3189] RE: Scan I got a copy of the Beta.. 6/50: About the fake -AV Name: Mark #1 @8868 Date: Tue Oct 08 09:00:59 1991 From: The Radio Control Model Plane BBS [818-919-2879] It's a file called MAKEAV.ZIP that can create the correct code to give a person a "registered" copy of PkWare's PkZip... -=The Radio Control Model Plane BBS 818-919-2879=- 7/50: Joshi Virus Name: Kebin Chung #28 @8868 Date: Tue Oct 08 23:59:49 1991 From: The Radio Control Model Plane BBS [818-919-2879] I just got a "JOSHI" Virus on my HD about a week ago. It did something funny to my boot sector so that I couldn't boot by pressing the "ALT-DEL" process. Anyway, I used "Central Point" and "NORTON VIRUS" scan to detect and get rid of it, only after a week later..... I get a warning again! It warns me that a JOSHI VIRUS is present, and that I should use Central Points Virus Scanner (CPAV.EXE) to clean it. But when I do this, the Scanner doesn't detect anything! The program I run is called NDD (Norton Disk Doctor) which when scanning the HD gives me the warning sign. This is my second computer that the virus is on, and it's got about 200 Meg worth of stuff I don't care to delete. Can anybody tell me why it's giving me these warnings, because when I run the Central Point & Norton Virus scanners, they don't detect anything. I am booting of a "safe" floppy. So it's not like stupid or anything. I also tried putting in a new Command.com and the two system hidden fils, but I still get the message. Apparently, the cleaning process still has left some or all of this virus somewhere in my HD. Any suggestions? I don't even use the comptuer right now. I've written to Central Point, but I don't know how long this is goin to take. Help!!! -=The Radio Control Model Plane BBS 818-919-2879=- 8/50: the latest scan version Name: Loki Trickster #263 @5211 Date: Fri Oct 11 18:19:37 1991 From: Blitzkrieg [502-499-8933] RE: I have not read French in BY: Mesmer #28 @8365 is NOT v. 82. A new version was issued yesterday. I think it's v. 84. Don't know fer sure, but the file date is October 10 (I think) 1991. 9/50: All of the McAfee stuff Name: Mesmer #28 @8365 Date: Sat Oct 12 13:21:40 1991 From: The Coffee Shop [813-840-0217] RE: Dark Avenger BY: The Controller #256 @5297 can be DL'd right from their bbs. I don't have the number at hand, but it is in the docs for SCANV82, etc.... If you don't want to do that, I guess you will have to scout around your area for it. If you don't want to do that, leave me E-Mail and I willgive you my bbs phone number. I always have the very latest McAfee, straight from their bbs. (Cheaper to call them, I am LD, too!) MESMER 10/50: McAfee Assoc. BBS# Name: Mike #34 @8365 Date: Sat Oct 12 18:57:04 1991 From: The Coffee Shop [813-840-0217] The number for McAfee Assoc. BBS, HOMEBASE, is (408) 988-4004. There are also lines for HST and V.32, but I don't have them. They are in the log-on screen. If you are calling just to d/l anti-viral programs, you needn't register, use the "Guest User" account, first name "GUEST", last name "USER", and password "123". This information is also presented in the log-on screen. Later, Mike Sysop: Plain Vanilla (813) 831-5779 GEnie: M.TYSON2 11/50: MAKEAV.ZIP Name: No Beta #23 @8365 Date: Sat Oct 12 21:46:36 1991 From: The Coffee Shop [813-840-0217] RE: About the fake -AV BY: Mark #1 @8868 Thanks for the info! {- o a t -} 12/50: Could be... Name: Mesmer #28 @8365 Date: Sun Oct 13 01:48:39 1991 From: The Coffee Shop [813-840-0217] RE: Joshi Virus BY: Kebin Chung #28 @8868 that the virus is in your boot record, not command.com. Try McAfee... MESMER 13/50: ... Name: Luc Mccarragher #7 @5496 Date: Fri Oct 11 12:32:17 1991 From: Unknown System RE: Non poly vieu francais. BY: Ghost Wheel #1 @9709 What is you question i no you are in alaska but the bbs not say what for you reply Sorry !!! ............. 14/50: Yes... Name: Omen #1 @8365 Date: Sun Oct 13 22:23:56 1991 From: The Coffee Shop [813-840-0217] RE: the latest scan version BY: Loki Trickster #263 @5211 Yes, 84 is out now, and of coarse it is available at the homebase(McAfee's) . Just verifiying a previous post..seee yaa!! Omen 15/50: Techno-Babel will DL from McAfee Name: Mesmer #28 @8365 Date: Mon Oct 14 00:28:41 1991 From: The Coffee Shop [813-840-0217] RE: Yes... BY: Omen #1 @8365 before the end of the week. MESMER 16/50: Scan V 84. Name: Ghost Wheel #1 @9709 Date: Mon Oct 14 04:45:03 1991 From: The City Of Avalon [907-443-3189] RE: the latest scan version Your right, lag time causes some confusion... Scan V 84 is now out.. 17/50: MacAffee BBS Name: Ghost Wheel #1 @9709 Date: Mon Oct 14 04:48:01 1991 From: The City Of Avalon [907-443-3189] RE: Dark Avenger 408-988-4004 18/50: dont use anything but Name: Wolfchild #7 @19961 Date: Mon Oct 14 02:02:20 1991 From: The Gameland BBS [919-542-1841] RE: Joshi Virus BY: Kebin Chung #28 @8868 vscan80 or whatever version is latest... that should get rid of Joshi else you can write the writers of vscan and tell 'em they could probably help... THE GAMELAND BBS 919-542-1841 300/1200/2400 BAUD OPEN 24 HOURS!!! 19/50: hey can anyone out there Name: Mega #22 @2364 Date: Sun Oct 13 18:06:56 1991 From: The Grand Ol Oprey [213-472-0520] in the vast dark hole in the bbs world called net (actually lalala land.heheheh) know anyone a good bbs numbers for atlanta,georgia preferably p/h/a/v/c. thanx off to never never land 012[/\/\dg`[210 20/50: Shit Name: Spermie #171 @5211 Date: Sat Oct 12 09:03:57 1991 From: Blitzkrieg [502-499-8933] RE: the latest scan version BY: Loki Trickster #263 @5211 i still havent got 83.... Although my computer cant catch virus's I wont let it. 21/50: Scan v. 83 Name: Loki Trickster #263 @5211 Date: Sat Oct 12 10:26:47 1991 From: Blitzkrieg [502-499-8933] RE: Shit BY: Spermie #171 @5211 McAfee's skipped v. 83, because some clown on the West Coast circulated a trojan named v. 83. I think the file date is something like October 7, 1991. I KNOW it's October. 22/50: Hello. Looking for a user named Thunder! Name: Wizard #21 @9416 Date: Mon Oct 14 14:19:54 1991 From: Windows of Opportunity [904-733-3719] Hello. If you (thunder) are out there, please respond to this message. I would like to talk to you about your post about your macro and how you used escape codes in it. Sorry for posting here! Wizard 23/50: JOSHI Name: Rambo #1 @8856 Date: Mon Oct 14 03:38:38 1991 From: Rambo-Scan BBS [818-566-7912] RE: Joshi Virus BY: Kebin Chung #28 @8868 This Virus was discovered in India in Mid 1990. This Virus can be hard to remove, if your not careful... From what I have read, you have NDD, if so, then you should have NU (Right?)... It was your HD right? Next fire up NU and take a look at your partition tables first two bytes, and see if they are EB 1F, if so, your infected... This is a Jump Instruction that moves you to Track 0, Sector 2-6 which contains the rest of the Viral Code. To Remove the Joshi Virus: #1 Shut off the system (Wait a Minute or Two) #2 Boot from a KNOWN CLEAN WRITE PROTECTED floppy DOS disk #3 Back-Up your hard drive(s) #4 Perform a LOW LEVEL FORMAT & Re-Partition the HD #5 Restore your Data, and re-check your work for problems. This should do it...... Sorry it isn't that easy, but you have run into a little bugger of a Virus... -*=p|/-\|/-\|RAMBO|/-\|/-\|p=*- SysOp Of Rambo-Scan BBS (818) 566-7912 Burbank California 24/50: vIRUS Name: Kebin Chung #28 @8868 Date: Sun Oct 13 19:25:29 1991 From: The Radio Control Model Plane BBS [818-919-2879] RE: Dark Avenger You can try McAffee at 408-988-5138 or 408-988-4004. These are BBS numbers. You can download the latest version of Vshield, and be "almost" certain that you're getting the original pacakage. But it's in the San Jose Area! It's in California, but it's still San JOse! They have version 84 out. I don't know if it'll help. The new scan 84 I have doesn't detect a "Joshi" virus on my other computer, but the Anti-Virus by Central Point does detect this. So I don't really know if it's that good. -=The Radio Control Model Plane BBS 818-919-2879=- 25/50: West Coast Distribution Site for SCAN Name: Rambo #1 @8856 Date: Tue Oct 15 01:24:46 1991 From: Rambo-Scan BBS [818-566-7912] And about 200 other ANTI VIRUS program. -*=p|/-\|/-\|RAMBO|/-\|/-\|p=*- SysOp Of Rambo-Scan BBS (818) 566-7912 Burbank California 26/50: Joshi Name: Kebin Chung #28 @8868 Date: Tue Oct 15 19:35:59 1991 From: The Radio Control Model Plane BBS [818-919-2879] I tried Vshield 84, Scan, and Clean on my hard disk. Nothing detects this virus. It says its a "JOSHI" virus..... this happens when I put "Central Point's Antivirus" loaded.... and then I run programs like "FDISK, NDD (Norton), and Speedisk" which all checks the boot sectors and "partition tables." Bootsafe comes out with a warning saying "Joshi Virus Present, clean with 'CPAV', but when I run this program, it does not detect this virus. It does not detect "anything"! It scans the whole disk, and says 'no virus found'. This is the same with "McAffee and Norton". Nothing detects this "virus" except "Bootsafe"! I don't think the virus is there, but who knows! My friends still insists that the virus is just what was left after I cleaned out the hard disk about 2 months back. I've since then re-partitioned and reformatted my hard disk. Still, when I run Bootsafe, I get the same results! I need help! Anybody???? -=The Radio Control Model Plane BBS 818-919-2879=- 27/50: I don't know where you are getting SCANV84 Name: Mesmer #28 @8365 Date: Wed Oct 16 10:31:50 1991 From: The Coffee Shop [813-840-0217] RE: Scan V 84. BY: Ghost Wheel #1 @9709 we called McAfee on Monday after hearing about V84. Only thing there was V82. If you have seen V84 one of 2 things is happening: 1. It is a beta test version, nit yet released as fully working, or: 2. It is anothet of those phoneys, a virus spreader itself. Be careful... MESMER 28/50: Scanv84 Name: Yanik Proulx #20 @5496 Date: Tue Oct 15 11:08:08 1991 From: Unknown System Bon, je vais vous uploader Scanv84 et il n`y aura plus de mal entendu. Si j`ai le temps j`enverrai aussi Clean84. Essayez le --- Yanik --- 29/50: Joshi. Name: Riel #28 @2364 Date: Thu Oct 17 23:48:21 1991 From: The Grand Ol Oprey [213-472-0520] According to others, you should use CPAV to scan the entire drive and not just the COMMAND.COM and such. Till the next. Riel Riel Riel PASO 7 ^]PASO 7^] I'm not paying attention to this, just conveying your post to a board. 30/50: Thanks Name: Kebin Chung #28 @8868 Date: Thu Oct 17 22:48:32 1991 From: The Radio Control Model Plane BBS [818-919-2879] RE: dont use anything but Thanks.... I'll do just that. -=The Radio Control Model Plane BBS 818-919-2879=- 31/50: Thanks Name: Kebin Chung #28 @8868 Date: Thu Oct 17 22:55:50 1991 From: The Radio Control Model Plane BBS [818-919-2879] RE: JOSHI Thanks for the advice. I did most of what you said.... except I have an IDE Seagate st144a (125MEG) and a CONNER (MEG) also IDE. The instruction for these HDs says that I "should not" low format my HD. The factory supposedly low formatted it already, and they recommend I don't touch it or I would the "internal" cache? I'm not sure about this.... Help!!!!!! I havent' checked the partition table yet..... it seems to catch it in my D: drive partition which is not the boot drive (Seagate Drive), but not the Conner which is Drive C. I'm at a lost.... Nothing is happening.... I'm not getting any problems at all so far. it's been about a week now. I really need some more advice. Any would be greatly appreciated. -=The Radio Control Model Plane BBS 818-919-2879=- 32/50: There Name: Off Road #92 @8856 Date: Thu Oct 17 22:41:44 1991 From: Rambo-Scan BBS [818-566-7912] RE: Shit BY: Spermie #171 @5211 Was no 83, he skipped from 82 to 84 (prolly a trojan problem or something, people are always trying to make bunk versions of Scan and putting viruses or trojans in them.) Just be careful where you d/l it from, and be sure the person that U/l it wouldn't do such a thing. me 33/50: Thanks Name: Kebin Chung #28 @8868 Date: Thu Oct 17 22:48:32 1991 From: The Radio Control Model Plane BBS [818-919-2879] RE: dont use anything but Thanks.... I'll do just that. -=The Radio Control Model Plane BBS 818-919-2879=- 34/50: Thanks Name: Kebin Chung #28 @8868 Date: Thu Oct 17 22:55:50 1991 From: The Radio Control Model Plane BBS [818-919-2879] RE: JOSHI Thanks for the advice. I did most of what you said.... except I have an IDE Seagate st144a (125MEG) and a CONNER (MEG) also IDE. The instruction for these HDs says that I "should not" low format my HD. The factory supposedly low formatted it already, and they recommend I don't touch it or I would the "internal" cache? I'm not sure about this.... Help!!!!!! I havent' checked the partition table yet..... it seems to catch it in my D: drive partition which is not the boot drive (Seagate Drive), but not the Conner which is Drive C. I'm at a lost.... Nothing is happening.... I'm not getting any problems at all so far. it's been about a week now. I really need some more advice. Any would be greatly appreciated. -=The Radio Control Model Plane BBS 818-919-2879=- 35/50: Where is everybody getting V84? Name: Mesmer #28 @8365 Date: Fri Oct 18 10:17:41 1991 From: The Coffee Shop [813-840-0217] RE: vIRUS BY: Kebin Chung #28 @8868 We are licensed McAfee's users and called their BBS on Tuesday to get the V84 everybody here was talking about. The version they have up for DL is V82! Are you SURE about V84? MESMER 36/50: There is a possibility Name: Mesmer #28 @8365 Date: Fri Oct 18 10:21:20 1991 From: The Coffee Shop [813-840-0217] RE: Joshi BY: Kebin Chung #28 @8868 that you don't even HAVE a virus. Virus detection programs look for certain "signatures" that indicate the presence of a given virus. Sometimes other programs may have a pettern of bytes that is the same as one of these signatures without actually con taining the virus. So your detection program senses this pattern and says "Whoa!" with no problem at all being there. I suggest that you spend the loot to call McAfee's bbs and ask them about it. They are very helpful... MESMER 37/50: Didn't you read my post? Name: Rambo #1 @8856 Date: Fri Oct 18 03:44:55 1991 From: Rambo-Scan BBS [818-566-7912] I posted the SURE FIRE way to determine if you are infected by the Joshi Virus. Go Back a few posts (Right after your first post on the Subject), and you will see how to find it and remove it... If your still having problems, you can E-Mail me.. -*=p|/-\|/-\|RAMBO|/-\|/-\|p=*- SysOp Of Rambo-Scan BBS (818) 566-7912 Burbank California 38/50: Got the Beta Test 84.. Name: Ghost Wheel #1 @9709 Date: Fri Oct 18 18:18:16 1991 From: The City Of Avalon [907-443-3189] RE: I don't know where you are getting SCANV84 Sorry, I got the Beta Test 84.. 39/50: bootsafe Name: Rocker #76 @6457 Date: Sat Oct 19 00:38:34 1991 From: The Fields of Nephilim [614-475-3303] [In Reference] Joshi [Fiend Posted] Kebin Chung #28 @8868 has a bug that it almost always says you have a virus, whether you do or not. I have seen many times that progrma doing this, even on brand spanky new drives out of the box. I wouldn't worry about it too much. If you are THAT worried, call the maker of bootsafe or CP....someone there might be able to help, but they'll probably tell you the same thing (not bootsafe though....) 40/50: Mesmer.. Name: Rambo #1 @8856 Date: Sat Oct 19 02:32:54 1991 From: Rambo-Scan BBS [818-566-7912] Your Behind the times... SCAN V84 has been out for a little time now.. This is a good version of SCAN, it is available from either McAfee or my BBS.. -*=p|/-\|/-\|RAMBO|/-\|/-\|p=*- SysOp Of Rambo-Scan BBS (818) 566-7912 Burbank California 41/50: DO NOT LOW-LEVEL Name: Hank Williams Sr. #1 @2364 Date: Sun Oct 20 08:27:32 1991 From: The Grand Ol Oprey [213-472-0520] Do NOT low-level format an IDE hard drive!! You will ruin the drives. Get the Spinrite program. It will tell you if your drives can be low-level formatted or not. But I can assure you that an IDE drive can NOT be low-level formatted! Hank Williams Sr. 1@2364 The Grand Ole Oprey 42/50: Yes I am. Name: Ghost Wheel #1 @9709 Date: Mon Oct 21 22:51:52 1991 From: The City Of Avalon [907-443-3189] RE: Where is everybody getting V84? Problem is SCANV84 is only in beta test.. Sorry for the confusion.. 43/50: No, Name: Brucelee #14 @8856 Date: Mon Oct 21 22:25:15 1991 From: Rambo-Scan BBS [818-566-7912] RE: Where is everybody getting V84? BY: Mesmer #28 @8365 Scan V84 was definitely out at the time of that post, maybe you should try again. I have all three utils on my HD right now, downloaded from this board. 44/50: Scan - Scan - Scan... Name: No Beta #23 @8365 Date: Tue Oct 22 00:54:12 1991 From: The Coffee Shop [813-840-0217] RE: Thanks BY: Kebin Chung #28 @8868 Just keep looking til you find it. McAfee's scanner will find the Josi virus. I suggest you try: SCAN C:*.* /A SCAN D:*.* /A {- o a t -} 45/50: Forgot something. Name: No Beta #23 @8365 Date: Tue Oct 22 00:55:13 1991 From: The Coffee Shop [813-840-0217] RE: Thanks BY: Kebin Chung #28 @8868 The book you got with your Hard Drive is correct. Do not low level format it! {- o a t -} 46/50: Gawd... Name: Rambo #1 @8856 Date: Tue Oct 22 01:58:59 1991 From: Rambo-Scan BBS [818-566-7912] RE: Got the Beta Test 84.. BY: Ghost Wheel #1 @9709 SCANV84 has been out for quite a while now (I believe since the 9th of this month)... I am a Beta Tester for McAfee, and I did have the Beta Scan V84 since the First of the month.. Now Read This Scan V.84 is the Newest, it isn't a Trojan/Virus/Hack Get it, use it, love it... -*=p|/-\|/-\|RAMBO|/-\|/-\|p=*- SysOp Of Rambo-Scan BBS (818) 566-7912 Burbank California 47/50: Again... Name: Mesmer #28 @8365 Date: Wed Oct 23 01:14:30 1991 From: The Coffee Shop [813-840-0217] RE: Mesmer.. BY: Rambo #1 @8856 the minute we heard of V84 we called McAfee - what was there was V82... We will be calling agin in a day or so... MESMER 48/50: This NET Name: Off Road #92 @8856 Date: Tue Oct 22 21:25:56 1991 From: Rambo-Scan BBS [818-566-7912] RE: Scanv84 BY: Yanik Proulx #20 @5496 thing's gone way out of hand here, we can't be getting FRENCH posts man, come on, I know it's prolly from Canada but even though this is really redicicilous. me 49/50: Jeeze.. Name: Rambo #1 @8856 Date: Wed Oct 23 02:41:03 1991 From: Rambo-Scan BBS [818-566-7912] ScanV84... This is getting OLD.. -*=p|/-\|/-\|RAMBO|/-\|/-\|p=*- 50/50: So has anyone seen this Dir-2 virus that v84 is suposed to Name: Loki #28 @5413 Date: Thu Oct 24 21:36:51 1991 From: The 286 Express PIN [504-282-5187] find??? From the little letter we got from our distributor with our copy of V84 it said that Dir-2 is suposed to be quite a nasty virus, and infects extremely fast and furious with serious Stealth capabilities.... Post on The Dirty Dozen (Trojans & Viruses)?