VIRUS-L Digest   Monday, 15 Jan 1990    Volume 3 : Issue 11

Today's Topics:

Possible New Infection (Mac)
Re: Shrink Wrap...still safe?
Re: Shrink Wrap...still safe?
IBM's VIRSCAN and the 1813 virus (PC)
Implied Loading and Accidental Destruction (Mac)
Re: virus scanning
WDEF and Virus Detective 3.0.1 (MAC)
An unfortunate victim (Mac)
Organizational attitudes about virus prevention
WDEF virus (Mac) in southwestern Ohio
RE: Shrink wrap...still safe?
Re: Shrink Wrap...still safe?
Shrink-Wrapped Software
F-PROT clarification (PC)

VIRUS-L is a moderated, digested mail forum for discussing computer
virus issues; comp.virus is a non-digested Usenet counterpart.
Discussions are not limited to any one hardware/software platform -
diversity is welcomed.  Contributions should be relevant, concise,
polite, etc., and sent to [email protected] (that's
LEHIIBM1.BITNET for BITNET folks).  Information on accessing
anti-virus, document, and back-issue archives is distributed
periodically on the list.  Administrative mail (comments, suggestions,
and so forth) should be sent to me at: [email protected].
- Ken van Wyk

---------------------------------------------------------------------------

Date:    Fri, 12 Jan 90 07:49:47 -0500
From:    "Gregory E. Gilbert" <[email protected]>
Subject: Possible New Infection (Mac)

I saw this posted in Vol. 8, Number 6 of the INFO-MAC Digest.  THought is was
worthy of a cross posting.

Date: Tue, 9 Jan 90 15:22 EST
From: [email protected]
Subject: Trojan Horse???? A new one

I recently saw a posting about two new sharewares, JCremote and Mac II
Diagnostic Sound.  After unBinHexing and Unstuffing them, I did what most of
would, I checked for viruses using SAM Virus Clinic 1.3.  No known viruses were
detected.  I tried the Mac II Diagnostic Sound and then installed JCremote.  As
I installed JCremote into my system folder SAM 1.3 warned me about attempts to
modify the system file, however, this is not uncommon with a CDEV or RDEV.
After installing it, I opened the chooser and selected JCremote.  The system
froze.  When I rebooted the computer the computer started to launch, but the
crashed.  There was no bomb or any message, just a blank screen.  After
rebooting with a floppy and checking with Disinfectant 1.5, the system file was
noted as having a damaged resource fork.  This meant I had to install a new one