Path: utzoo!attcan!utgpu!jarvis.csri.toronto.edu!rutgers!netnews.upenn.edu!vax1.cc.lehigh.edu!sei.cmu.edu!krvw From: portal!cup.portal.com!Alan_J_Roberts@Sun.COM Newsgroups: comp.virus Subject: ***WARNING*** VIRUSCAN Trojan (PC) Message-ID: <0006.8907261137.AA08543@ge.sei.cmu.edu> Date: 26 Jul 89 02:47:00 GMT Sender: Virus Discussion List Lines: 42 Approved: krvw@sei.cmu.edu Someone has taken the VIRUSCAN program and hacked it into a trojan. Richard Levey of Shareware Enterprises in Elmont, NY, and J.J. Webb of Lockheed have both submitted copies of a program that they thought was identical to VIRUSCAN version 19 in the way it operated. On analysis, the program turned out to be Viruscan V19 with a number of modifications. No attempt was made to modify the VIRUSCAN program messages, internal data strings or instruction sequences, with the single exception of the copyright notice. The copyright notice was changed to 'Copyright 1989, WileySoft Corporation". The only modification made to the documentation was the change of name and address to: WileySoft 11 Trafalgar Square Nashua, NH 03063 And a request to send $24 to the above address was added. The program was then compressed, a front end loader/decompressor was tacked on, and the final package was infected with what appears to be a modified version of the Jerusalem virus. The final EXE file was named SCAN (the same as the VIRUSCAN executable module) and was 22917 bytes long. A check with the local Nashua phone company found no listing for such a company, and no WileySoft Corporation was registered in the state of New Hampshire. VIRUSCAN users should be aware of this trojan program. Please check that your executable module is exactly 34400 bytes long. All versions of VIRUSCAN have been this length and all future versions are planned to have the same length. Ensure that the McAfee Associates copyright is displayed with the version ID and phone number in the first display line. If there are any questions about the validity of your program, an original copy may be downloaded from HomeBase, 408 988 4004, from SIMTEL20 or some other reliable source. John McAfee ..-....