
  In case you've missed the news, there's a "new" type of Trojan Horse making 
the rounds that we all need to be aware of. The accompanying file, REPORT.TXT, 
is the original report that's been circulated on the subject. To summarize, it 
tells of a patched version of COMMAND.COM that will copy itself to other disks 
or diskettes that also contain COMMAND.COM. It contains a timebomb that will 
eventually damage your system.

  While I've seen notes on various BBSs around the country, stating that this 
was the most innovative Trojan they've ever heard of, there's probably very 
little innovation here. The thing was first described theoretically in a 
Scientific American article back in the early '80s. The author was not 
discussing DOS specific machines, but simply a software analogy of a true 
virus. I think it was somewhat foolish to describe such a thing, but 
fortunately it sat hidden for all these years. I guess we're fortunate that the 
type of person who writes Trojan Horses is not the type that reads Scientific 
American. 

  In any case, the Trojan Program acts almost exactly as I remember the 
article describing it, except that the article merely suggested that such a 
thing might be turned into a dangerous program. Fortunately, the writer of the 
Trojan didn't think to use various features inherent in the structure of PC 
based systems to make it as subtle and dangerous as it could have been. I 
suspect that the average writer of Trojan programs has only technical saavy, 
but little real creativity or motivation to carry out an extensive project, 
otherwise he (or she) would instead work to make an impact on the computing 
world with something useful, which takes far more effort and thought.

  As such, the patch to COMMAND.COM, which required some sophistication to 
produce, has some sloppy errors, which will make it easy to spot. I caution you 
not to assume that other very sad people will not try to produce craftier 
versions of this, in the future. Versions that do not include copies of 
COMMAND.COM, and are easily uploaded will certainly come in time. These will 
change forever the nature of telecommunications, and will require all of us to 
keep our eyes open. We will become much more interested in cooperating with 
each other, and spreading important news, and this will perhaps be as good a 
change as "virus" Trojans will be bad. All in all, what has happened so far is 
about the best possible scenario for the introduction of this kind of virus. It 
could have been so much worse, but instead its debut has been quickly followed 
with a widespread warning before it could spread too far. We've been very 
lucky, and have this to be thankful for.

  The "innoculation" program that comes with these files is an experimental 
one. It cannot do any harm, but may be a great help, if an infected COMMAND.COM 
comes your way. Basically, when you run INOCULAT.COM, it will change the file 
attribute of the copy of COMMAND.COM in the default file & directory so that it 
is a read only file. As such, it will "innoculate" all your copies of 
COMMAND.COM, so that they cannot be written over, or erased. You will have to 
innoculate all of your copies of COMMAND.COM separately, and if the copy of 
COMMAND.COM is not in the default drive and directory, nothing will be done, 
and you will get a message stating this.

  The program has these limitations for several reasons;
   1). I wanted to get this program out as quickly as possible, and a shorter 
      program could be entirely written using DEBUG.
   2). I'm not doing this for money, and I have many other obligations. I have 
      freely given what I could, but no more.
   3). Most importantly, this program is simple enough that ANYONE with a 
      little bit of knowlege of assembly language programming under DOS can use 
      DEBUG to completely check it out in a few minutes. Wherever you download 
      this from, I'd suggest that you first check it out or wait until one of 
      your local "gurus" check it for you and post a message stating that it's 
      OK. You should never have to worry that this program might be another 
      disguised Trojan, preying on your fears.

  This program has not actually been tested against an infected COMMAND.COM. I 
don't want a copy of that thing anywhere near, which is why I said this program 
is experimental. Note that this program does not offer 100% protection. Just as 
this innoculator can make COMMAND.COM into a read only file, a Trojan can 
change it back before trying to patch it. The fact that the programmer didn't 
even check for the presence of a write protect tab indicates either extreme 
sloppiness or a lack of room in the limited stack space of COMMAND.COM, and 
either case suggests that no attempt will have been made to change the file 
attributes THIS time. However, when you do run this program to innoculate a 
COMMAND.COM, you'll find that you can no longer erase that COMMAND.COM or COPY 
another over it. The program does what it was intended to do. However, I would 
be very glad to hear from anyone who does use it against an infected 
COMMAND.COM.

  This leads to a small problem. Suppose you WANT to get rid of a copy of 
COMMAND.COM on a diskette. As a read only file, DOS won't let you do it. For 
this, you can run UNINNOC.COM, which will remove the read-only marker from the 
file, allowing you once again to erase the thing, or COPY in a newer version. 
Once again, UNINNOC will only affect a copy of COMMAND.COM in the default drive 
and directory.

  Now, you people out there who are using SNATCHIT to upload entire diskettes 
(you know who you are and why you're doing it) are presently more vulnerable to 
this bad COMMAND.COM than most, because you may actually get a copy of an 
infected COMMAND.COM with the rest of your files. You'll need to be more 
cautious than anyone else about the telltale signs of infection, particularly 
the modified date stamp on the COMMAND.COM file.

  If anyone gets a copy of the infected COMMAND.COM, the first thing you should 
do is power down your system. Next, turn it on and boot up with a diskette you 
KNOW is clean. I'd suggest using the original DOS diskette that you should be 
keeping stored away, and ALWAYS with a write protect tab on it. (If you haven't 
yet been infected, make a write protected copy of your DOS diskette NOW, and 
use that instead.) Next, copy the COMMAND.COM from the known good diskette to 
the infected copy. The infection should then be cured on that diskette, but you 
should immediately check all your other disks and diskettes for signs of 
infection. After that, you can breathe easy.

  Future versions of this program may not be as easy to exorcise. I won't go 
into details as to why, but as I said, things could have been SO much worse. It 
would be a good idea to get into the habit of ALWAYS using write protect tabs 
on all your diskettes, except for those that contain data that needs to be 
modified, and NEVER making those data diskettes bootable. This is not possible 
in all cases, but it should make fancier "mutations" of the virus harder to 
spread. Good habits can be developed now, before you have to rely on them.

  DO IT!!!!!!

  These programs are GRATISWARE.  That is, they're really free; I don't want 
anything for them. (Heck, they don't represent all that much effort, anyway.) 
If you like them, share them with a friend. If you need to spend something, 
make a short call to one of the boards below and leave me a message telling me 
you're using them. I'd like that. If you're in a PC Pursuit city, you may see 
me on a local board, let me know you're there. Lastly, please let me know how 
this innoculation program works against a real infected COMMAND.COM, if you 
have the misfortune of getting a copy. We'll all benefit from that knowlege. 
And I'd like to encourage others to look into producing similar tools on the 
off chance that this program does NOT protect from the infected COMMAND.COM. 
It's time to work together on this. May 1988 be a GOOD year for us all.


                                        Wes Brzozowski

I can be reached on the following boards:


(607) 754-3420  Owego Free Academy
(607) 785-6876  PC Plus
(607) 785-2118  TCCS





