VIRUS-L Digest Wednesday, 14 Jun 1989 Volume 2 : Issue 137 Today's Topics: Forward of Virus Warning recieved from PCSUPT List It's almost time for a change --------------------------------------------------------------------------- Date: 14 Jun 89 06:30:00 GMT-15:00 From: "DSC T. DEJANE" Subject: Forward of Virus Warning recieved from PCSUPT List We have discovered a PC virus on campus. It is readily apparent in WordPerfect 4.2 applications which refuse to run from the C: drive and display the error: Can't find correct copy of WP.EXE Enter full path and filename (Example: C:\WP\WP.EXE) It appears as though at least one other university campus has a similar problem (see messages below). This virus infects .EXE and .COM files when you run them; it does not appear to infect the IBM*.COM and COMMAND.COM files stored on disk. We are conducting further investigations and hope to have more information in the near future. ==== Begin forwarded messages ==== Original-From: CANDIE@PACEVM.BITNET (Jenny Wirtschafter) Original-Subject: Possible Virus Encountered (PC) Original-Date: 2 Jun 89 15:37:26 GMT Hi- Recently we began noticing a problem on some of our software, specifically WordPerfect. On all of our WordPerfect disks we get the error can not find correct copy of WP.EXE. If an infected disk is used on a machine without rebooting it infects all disks used subsequently. The disks are infected immediatly, there is no latency period. Another symptom we have noticed is the monitor will display snow and start scrolling/clearing the screen at random intervals. When infected disks are reformatted they have numerous bad sectors. We are worried that the virus might be infecting all of our disks. It might be surfacing on the Wordperfect disk, because they must be used without a write protect tab. Or possibly the sectors which the virus first infects are necessary to WordPerfect performing correctly. Has anyone else encountered this problem? Does anyone have any ideas on how we should proceed? Any help would be greatly appreciated. Jenny Wirtschafter Academic Computing Original-From: IA96@PACE.BITNET (IA96000) Original-Subject: Warning New Virus (PC) Original-Date: 8 Jun 89 22:34:00 GMT Just thought you all might like to know the following: There is a new virus floating around, which attacks WP.EXE in particular and almost every other .EXE file it comes in contact with. It is self propogating and trashes files and disks. Some of the things to look for are as follows: 1) Strange blue/green blocks appear on the screen. 2) Running a .EXE you know is on the disk and getting a "File not found" error even though the .EXE is on the disk. 3) After 30 to 45 minutes everything seems to slow down. Doing a DIR takes 30 or 40 seconds for each line to appear. 4) It definitely spreads between .EXE files, although it appears .COM files are immune. [Nope, .COM files aren't immune. - Lance] 5) It will spread to all types (sizes) of floppy disk drives and will jump to a hard drive. More later... ==== End forwarded messages ==== If anyone has further information on (or experiences with) this virus, please post it here, on comp.virus, or directly to us here at Stanford (goodrich@jessica.stanford.edu or gx.tsg@stanford.bitnet) and we'll compile the results and post them. Lance Nakata and Tom Goodrich Academic Information Resources Stanford University ------------------------------ Date: Wed, 14 Jun 89 14:33:50 EDT From: luken@ubu.cc.lehigh.edu (Kenneth R. van Wyk) Subject: It's almost time for a change Hi all, This week is my last week here at Lehigh. Next week, I'll be starting to organize things for my new job out at CMU (which I formally start the following week - June 26). As such, VIRUS-L/comp.virus will be intermittent next week (read: whenever I can get to a machine, I'll send out a digest). Please keep the messages coming, and I'll try to handle them as quickly as possible. The change has made me curious about the future of VIRUS-L/comp.virus. I will, as promised, continue to moderate, but where is the group heading? At the SEI, my project is very Internet related. I'd like to see some of the discussions here on VIRUS-L touch on network security issues. I'd also like to see more discussions on non-microcomputers. (This doesn't mean that we're abandoning micros by any means, merely that I'd like to see the group branch into other areas as well.) Feel free to send comments/suggestions/gripes to me and I'll summarize to the group or send in the individual comments. Finally, thanks to all who sent in their support on my move! Ken P.S. My new e-mail address at CMU is: krvw@sei.cmu.edu. The account is open, so e-mail can be sent there any time. ------------------------------ End of VIRUS-L Digest ********************* Downloaded From P-80 International Information Systems 304-744-2253