This page is a wiki. Please login or create an account to begin editing.


25 posts / 0 new
Last post
Offline
Joined: 2011 Dec 3
Files here that are infected with a virus

The recent discovery (and subsequent removal) of a virus in Logic Audio Platinum 4.7 has prompted me to do a scan of the many files from here that I have uncompressed and archived privately. Below is a list of those files that Virex shows as being infected. The virus strain is given in brackets. Please either beware of these files or, even better, fix the problem and reupload. I have not looked inside any disk images so there may still be the occasional infected file in these.

Carmen Sandiego Math Detective: Installer (666-A)

Abalone:
abalone1.4.2 (nVIR)

Black Box
(BlackBox (nVIR)

Brickles Plus
Brickles Plus v2.0 (MBDF-B)

Cryptogrammer
Cryptogrammer v1.1.1 (nVIR)

HangMan Plus
Hangman plus v2.0 (MBDF-B)

Logic Audio Platinum 4.0.4
Logic Audio Dongle EMU 1.2 (666-D)
Logic Audio Platinum 4.0.4 68k (666-D)
Logic Audio AKAI DR8/16 info (666-D)

Microsoft Excel
Excel 4.0 Folder/TeachText (nVIR)

OmniPage 8.0 LE
Instalar OmniPage Ltd Edition (666-A)
Install OmniPage Ltd Edition (666-A)
Installa OmniPage Ltd Edition (666-A)
Installer OmniPage Ltd Edition (666-A)

Rose Garden (nVIR)

Steinberg Nuendo 1.5.2
1-Nuendo Install (666-D)

Stuffit Deluxe/Stuffit Deluxe.sit
Stuffit 1.5.1/1.5.1 Note (ReadMe) (nVIR)

Tao Te Ching (666-A)

Turbo Pascal 1.0
Turbo (nVIR)

Comments

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Good idea for this list, mrdav. I suggest to the Admins that it also be made a sticky so we can add/subtract to it in the future.

You can scratch "Logic Audio Platinum 4.0.4" & its associated infected files from the list, thanks.

I may replace the infected OmniPage 8.0 LE copy entirely with a clean OmniPage 8.0 Pro too, shortly.

IIGS_User's picture
Offline
Joined: 2009 Apr 8

Good idea for this list, mrdav. I suggest to the Admins that it also be made a sticky so we can add/subtract to it in the future.

Thanks, MikeTomTom, sticked now. Smile

Offline
Joined: 2011 Dec 3

I was a little imprecise about where the virus in Stuffit 1.5.1 was, as there is more than one copy embedded in different places. Now it should be clear

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Stuffit 1.5.1 - This one is confusing. - I had cleaned this and re-uploaded (as seperate DL's) into the Stuffit Deluxe page (back in 2010) - but I left the infected 26.86MB item there, not wanting to offend the original uploader... hoping someone else would deal with it (and its still there). See "[Updated]" & "[Note]" sections in Description on Deluxe page.

There is also a separate Stuffit 1.5.1 page... so, with a little bit more precision, which 1.5.1 exactly are you referring to here?

[Edit] ah saw your amendment. Delete the 26.86MB file & problem solved (I cleaned then uploaded separate as per IIGS_User's request (in comments section) way back in 2010).

[Edit 2] Also in description of Stuffit Deluxe page:

IMPORTANT NOTE:
One of the Packages (The Stuffit App v1.5.1) that comes in this File, is infected with the -nVir A- type Virus, but since that Stuffit version is too old to be used, is pretty much harmless,
Else that virus became itself abandonware, so it is left there for educational purposes (in case someone would like to disassemble it and experiment with that)

Interesting philosophy, no?

Well, I say no. If you want to run old OS's on old hardware and/or emulators (and I do), I don't want them getting effed up by crappy script-kiddy-ware. So I say just get rid of it.

IIGS_User's picture
Offline
Joined: 2009 Apr 8

Better to remove the infected files completely.

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Have removed virus infected archive from Stuffit Deluxe page + updated info in Description field.

I notice that Balrog (original uploader of the Deluxe archive) later adds to Comments field "The nVir A virus probably won't become abandonware -- even its source code is available."

So I'm thinking that it was OK to remove this. Wink

MikeTomTom's picture
Online
Joined: 2009 Dec 7

"Steinberg Nuendo 1.5.2" this one is an easy fix as its a duplicate and a clean installer version of the same software is located on this page. I've put a notice in the Duplicates sticky, so once the dirty copy & page is removed, this can be scratched from the list.

I've also placed alerts in the infected file's DL page, pending its removal.

[Edit] And nuendo has gone. Thanks IIGS_User.

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Scratch "OmniPage 8.0 LE" from the list please, mrdav.
@IIGS_User: had you installed this one previously? If you installed only the German language OmniPage, you may have escaped the 666 contaminant, as only that one appeared to be clean.
All are cleaned now.

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Rose Garden has been cleaned and replaced by Daxeria back in May, 2013. Dax left this comment in the RG page:

Replaced with a clean copy after discovering that the original upload was infected with nVIR A

IIGS_User's picture
Offline
Joined: 2009 Apr 8

Not installed the "OmniPage 8.0 LE" on my systems.

themacmeister's picture
Offline
Joined: 2009 Oct 26

nVir-A was EVERYWHERE, and was pretty harmless. I believe it had a payload for a date back in the 80s/90s??. Anyways, most antivirus will remove it harmlessly. I conservatively guess that >5% of my software backups from that time will be infected. It could attach itself to ANY file I believe, so nothing was safe.

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Abalone, Black Box, Brickles Plus, Cryptogrammer & HangMan Plus now replaced with cleaned copies: Eeps, 4 out of 5 were from a single source...

@mrdav: Can you mount the Disk Copy 6.x images found in the Excel 1.03 & Excel 2.2a folders, inside the main "Microsoft Excel" folder? I cannot. Disk Copy 6 reports that they are all fubar. Was about to replace the infected archive, but it looks like it will be missing those Disk Copy versions too, when I do.

grawlix.computing's picture
Joined: 2009 Jun 1

It looks like that source might have been me--I think I stripped those games off of a salvaged machine. Thanks for cleaning up my rot.

MikeTomTom's picture
Online
Joined: 2009 Dec 7

YW. Did you happen to run any of those, too? I think even Disinfectant will clear nVIR & MBDF-B

grawlix.computing's picture
Joined: 2009 Jun 1

Did you happen to run any of those, too?

The system that those applications were run upon has been wiped clean and rebuilt from read-only media.

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Abalone, Black Box, Brickles Plus, Cryptogrammer, HangMan Plus, Tao Te Ching, Turbo Pascal 1.0 have now been replaced with cleaned copies - Only Microsoft Excel to go:

@mrdav (in case you missed my earlier post): Can you mount the Disk Copy 6.x images found in the Excel 1.03 & Excel 2.2a folders, inside of the main "Microsoft Excel" folder? I cannot. Disk Copy 6 reports that they are all fubar.

The Disk Copy 6 image files inside of this archive will need to be replaced by someone else, as there is no point in leaving broken files in with the cleaned copy.

Offline
Joined: 2011 Dec 3

@MTT

Those Excel disk images certainly do not mount with DiskCopy 6.4, but they do mount just fine in Mini vMac so they can be accessed, and are good to keep. I don't know if we should re-image them so they can be opened by DiskCopy...might be useful.

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Good idea. I'll access them via MvM and re-image. Will test these for virrii too, while at it. Right after dinner Wink

[Edit] Microsoft Excel has been cleaned, repaired and replaced. Thanks for the Mini vMac suggestion.

Interesting exercise with this one. Both Basilisk & Sheepshaver wouldn't mount these images. Mini vMac would. But, Disk Copy 6 and ShrinkWrap wouldn't image the mounted disks (Disk Copy would but offered a ridiculous 35MB filesize to do so). I managed to duplicate these using Disk Dup+ on SSW 6.0.8! From there, I converted the Disk Dup+ files to Disk Copy 4.2 image files using ShrinkWrap 2.1 - Only SW2.1 or earlier can create Disk Copy 4.2 files that are byte compatible with actual Disk Copy 4.2 images (without requiring a hardware floppy disk) and creates Tag checksums, missing in other disk image progs. The results here were, the desktop data/db is intact from their respective 1986 & 1989 originals. The 2.2 Tour disk image even retains its Finder Comments in the Get Info window.

Success.

Offline
Joined: 2011 Dec 3

That is impressive, MikeTomTom! Thank you.

Offline
Joined: 2011 Dec 3

The installer in the disc image of Carmen Sandiego Math Detective is infected with the 666-A virus

MikeTomTom's picture
Online
Joined: 2009 Dec 7

@mrdav: Do you mean the installer on the hybrid Mac/PC CD image has 666-A?

Offline
Joined: 2011 Dec 3

---> Do you mean the installer on the hybrid Mac/PC CD image has 666-A? <---

Yes

MikeTomTom's picture
Online
Joined: 2009 Dec 7

Thats a problem then, whole CD needs de-lousing, rebuilding & re-upping. I have real problems accessing that &^%*$#! 4shared site so I'm unable to help out.

I'll place a heads-up on the CSD page tho'.

[Edit] I've added the link to the clean copy in the CSD page and removed the heads-up from the page. Thanks for finding the good copy and hosting it, mrdav.

themacmeister's picture
Offline
Joined: 2009 Oct 26

MTT & mrdav -> You both RULE !!!