home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!sun-barr!ames!pacbell.com!iggy.GW.Vitalink.COM!cs.widener.edu!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: KDC@ccm.UManitoba.CA (Ken De Cruyenaere 204-474-8340)
- Newsgroups: comp.virus
- Subject: "New" 1530 virus ? (PC)
- Message-ID: <0002.9209102038.AA25851@barnabas.cert.org>
- Date: 8 Sep 92 21:42:36 GMT
- Sender: virus-l@lehigh.edu
- Lines: 25
- Approved: news@netnews.cc.lehigh.edu
-
-
- A new virus has turned up on our campus.
-
- McAfee v95 identifies it as "1530" but will not clean it.
-
- CPAV (1.2) does not detect it.
-
- F-PROT (V2.05) does not detect it (even in HEURISTICS) (!)
- When infected, VIRSTOP does note that it has been changed and tells
- one to boot from a clean diskette, but VIRSTOP doesn't stop the boot
- at that point (?!).
-
- It appears to infect .EXEs and .COMs. It seems to go for
- COMMAND.COM first. Infected files increase in size (by apprx 1960)
- but the date doesn't change.
-
- The following search string seems to be unique to the virus:
- 06 56 57 50 53 51 52 8C DE
- (but hasn't been tested very thoroughly at this point)
-
- - Ken
- - ---------------------------------------------------------------------
- Ken De Cruyenaere - Computer Security Coordinator - Computer Services
- University of Manitoba - Winnipeg, Manitoba, Canada, R3T 2N2
- Bitnet: KDC@CCM.UManitoba.CA Voice:(204)474-8340 FAX:(204)275-5420
-