Path: utzoo!attcan!utgpu!jarvis.csri.toronto.edu!mailrus!csd4.csd.uwm.edu!bionet!apple!rutgers!netnews.upenn.edu!vax1.cc.lehigh.edu!sei.cmu.edu!krvw From: portal!cup.portal.com!Alan_J_Roberts@Sun.COM Newsgroups: comp.virus Subject: New PC Virus Message-ID: <0007.8908291156.AA25879@ge.sei.cmu.edu> Date: 29 Aug 89 04:10:56 GMT Sender: Virus Discussion List Lines: 14 Approved: krvw@sei.cmu.edu A new PC virus has been turned over to the CVIA by RAP Systems of San Bruno, CA. RAP Systems discovered the virus at one of their Northern California client sites on August 17. The virus infects COM and EXE files (with the exception of COMMAND.COM) and increases their size by exactly 2500 bytes. The virus seems to have an activation date of Friday 13, and when activated, it destroys both executable and data files in a seemingly random fashion. Of interest is the fact that the infected client was also infected with the Jerusalem Virus version B. Both viruses appeared able to infect the same files. The virus has been temporarily dubbed the RAP virus. More info. will be reported as we take it apart. Alan