[comp.virus] WDEF in Toronto

ADAMS@HUMBER.BITNET (Kevin Adams) (02/06/90)

Humber College in Toronto has been hit by the WDEF virus.  We first
detected it when machines began crashing (mouse still moved cursor
around the screen, but no other response).   It had managed to infect
the desktop of our server by the time we caught up with it..
We had resident virus protection in place, but it was too old to
snag WDEF.

We brought it under control with Disinfect 1.5 and Eradicat'Em.  We
tried Gatekeeper Aid prior to Eradicate'Em,  but it seemed not to work
on our IIcx's and SE30's.

We've also survived NVIR A and NVIR B.

>From the reports I've read NVIR and WDEF both have no malicious
intent, and that any damage they cause are 'side effects'.  Is this
accurate?

It seems very strange to me that Virus writers would launch
their missiles with no payload...

Kevin Adams
User Services Group
Humber College of Applied Arts and Technology

woody@rpp386.cactus.org (Woodrow Baker) (02/09/90)

ADAMS@HUMBER.BITNET (Kevin Adams) writes:
>
> >From the reports I've read NVIR and WDEF both have no malicious
> intent, and that any damage they cause are 'side effects'.  Is this
> accurate?
>
> It seems very strange to me that Virus writers would launch
> their missiles with no payload...

Not really,  Perhaps they are
1.	General test cases to see how effective an attack method is
2.	A somewhat responsible virus writer, who likes the chllenge
	but would not want to cause damage.
3.	Someone who stood a chance f getting discovered, and figured
	that if it was a benign virus, the legal troubles would be less.

All of the above would be valid reasons not to make it lethal...
Cheers
Woody