[comp.virus] Periodic virus sighting report

krvw@cert.sei.cmu.edu (Kenneth R. van Wyk) (08/01/90)

The following new virus infections were reported recently:

- - First sighting of Slow (PC) virus reported in Australia.  Major
  infection path so far seems to be Taiwan -> Hong Kong -> Phillipines
  -> Malaysia -> New Zealand -> Australia.

- - Joshi (PC) virus reported in Lakeland Florida area.

- - 4096 (PC) virus reported in Spokane/Seattle Washington area.
  Several sites hit.

These sightings were reported to me; they are in addition to the other
reports that have appeared on VALERT-L and/or VIRUS-L.  When possible,
I have phoned at least one contact in the area to verify the
sightings.

Ken van Wyk
August 1, 1990

krvw@cert.sei.cmu.edu (Kenneth R. van Wyk) (08/31/90)

The following new, or otherwise important, virus infections were
reported recently:

- - 4096 (PC) reported in Philadelphia, PA, and Australia.

- - Marijuana (PC) reported in Rio De Janeiro, Brazil.

- - Jerusalem B (PC) reported to be inadvertantly distributed on some
  animation programs sold at flea markets.  Note that these infections
  do NOT necessarily mean that anyone should boycott flea market
  software.  They only serve to illustrate that it is always advisable
  to scan (using your favorite UP-TO-DATE virus scanner) ALL newly
  purchased software.

These sightings were reported to me; they are in addition to the other
reports that have appeared on VALERT-L and/or VIRUS-L.  When possible,
I have phoned at least one contact in the area to verify the
sightings.

Ken van Wyk
August 31, 1990

lexw@idca.tds.philips.nl (Lex Wassenberg) (09/03/90)

krvw@cert.sei.cmu.edu (Kenneth R. van Wyk) writes:
>  ...... it is always advisable
>  to scan (using your favorite UP-TO-DATE virus scanner) ALL newly
>  purchased software.

Then *WHY* is it that I almost NEVER see any virus signature mentioned
here in comp.virus? If that would be the case I could fairly easily
update my virus scanner by just reading this group carefully (I don't
now how to download signature files from any bbs, although it seems to
be possible from the site where I work). If there are new virusses
analyzed, could there *please* be posted a signature to this group
including info like name, length and BOOT/EXE/COM infection? Thanks.
     _ _
    / U |         Lex Wassenberg, Philips TDS, Apeldoorn, the Netherlands
   /__ <                         lexw@idca.tds.philips.nl
  88  |_\         "Since nobody understands me, I speak only for myself."