[comp.virus] None other than WDEF

KIP@ALBION.BITNET (Down & Out) (02/13/90)

        I noticed a couple of messages in the list recently that asked
about WDEF and servers. I also noticed talk about programs to defeat
all known viruses. I also noticed that Wayne State reportd being hit.
(I notice alot of things). So let me say this..... 1. Albion could
have possibly gotten WDEF from Wayne State (We are located South
Central MI) 2.Macserve@Pucc has a fairly good listing of virus
protection and some general info on viruses 3.Here is a letter that I
sent to the creator of Eradicate'em, a protection program for WDEF.


<From:  PURPLE::KIP          "Down & Out"  8-FEB-1990 03:47:50.77
<To:    IN%"dplat@coherent.com"
<CC:    KIP
<Subj:  Many thanks
<
<       I am a student at Albion College, Albion, MI. We have a
<computer lab that, along with other machines, contains 10 Macintosh
<Plus computers. The Machines run of of an 800k floppy and a 75meg
<nouvell server (run on an IBM).  The server also connects 10 IBM's.
<Ayway to my point, on 2/4/89 I was working in the lab when a person on
<an IBM had trouble loading a program. Well I am a tried and true Mac
<user so I had a friend look at it. It seemed that there was no memory
<on the server. We usually have about 40megs free. I thought well maybe
<the stupid IBM was reading the memory wrong. Well the Mac's said the
<same. Now I panicked. Scanning the room quick I notice on of the Mac's
<has a note on it saying "this disk infected with WDEF do not use". (we
<are currently running SAM as detection) Well the first thing I did was
<try to free up some memory space by trashing some files we did not
<need. I cleared up about 8k and was looking to see what else i could
<trash. Then all of a sudden the 8k was gone. It had eaten the free
<memory. Well the only thing I could think had happened was that WDEF
<had been transfered somehow from the floppy to the servers desktop. So
<I held down the option and command key on boot and when prompted "do
<you wish to rebuild the desktop on 'albionsys1'" I clicked on "Okay".
<Well it cleared up 75k immediatly. Then I started looking around and
<the other 40megs just seemed to reappear. This was a very strange
<occurance. I don't know if it was WDEF or just a coincidence. In my
<time of need i turned to "macserve@pucc" and began to download virus
<protection material.( the reason being sam is great for the regular
<user but the novice tends to push continue and not tell an assistant)
<In my time of need I found Eradicatem (nice icon by the way). It is
<now loaded on all of our Mac's in the lab and the computer club will
<also be circulating it. We did run tests with the copy of WDEF that we
<captured and were pleased at the actions.  (not that we did not
<believe you but we had to see what it did in a real life test). So
<thank you very much. Any questions you have on the occurance, or copy
<of WDEF (if you are interested) let me know. The lab is in debt to
<you.

Hope this helps anyone that is out there watching the movement and
effects of WDEF.

   ******************************************************************
   * KIP@ALBION.BITNET                          * All comments made *
   * A concerned Mac user and fighter against   * in the above are  *
   * dasterdly virus through the implementation * mine. But who am  *
   * of the brillance of others.                * I ? (disclaimer?) *
   ******************************************************************