[comp.virus] Posting to VALERT-L re: M-1704

JFORD1%UA1VM.BITNET@VMA.CC.CMU.EDU (James Ford) (10/03/89)

I recently posted a question on VALERT-L about the file M-1704.EXE.
SCAN V36 stated that it was infected.  I now know, from McAfee and
others, that the 1704 virus is encrypted.  Since it is, M-1704 must
have a specific hex search string in it....one that will indeed cause
SCAN to flag it.  This is *normal* (thats as technical as I can
get....I don't know more, and what I just said is probably techincally
wrong).

I hope that my posting of the VALERT-L message does not reflect
negatively on the Wellspring BBS.  The Wellspring BBS is a top-notch
BBS, and its anti-viral file collection is among the best in the
country.  If I gave you a wrong impression of Wellspring, I apologize.
I would post this statement about the Wellspring BBS on VALERT-L, but
have been informed that VALERT-L is not suppost to be carrying such
postings.

                                  JF
Acknowledge-To: <JFORD1@UA1VM>