Path: utzoo!utgpu!news-server.csri.toronto.edu!cs.utexas.edu!wuarchive!zaphod.mps.ohio-state.edu!maverick.ksu.ksu.edu!rutgers!netnews.upenn.edu!vax1.cc.lehigh.edu!cert.sei.cmu.edu!krvw From: NYEVENBA@WEIZMANN.BITNET (Baruch Even) Newsgroups: comp.virus Subject: More (small) info about Saddam Virus (PC) Message-ID: <0007.9010101940.AA05706@ubu.cert.sei.cmu.edu> Date: 7 Oct 90 15:55:47 GMT Sender: Virus Discussion List Lines: 21 Approved: krvw@sei.cmu.edu Hello, recently I posted info about the Saddam Virus on virus-l first an info that I collected from a message on BBS's net in Israel it was posted from VIRUS-L at 4/10, After a day or two I posted another info file to VirAlert this info file is info of my views, And now I'm sending another small info I by mistake didnt placed in the info file. The virus overwrites the first 3 bytes of the file and place there a CALL command to his startup code. - -Baruch Even +-------------------------------------------------------+ | Baruch Even | | | | BitNet - NYEVENBA@WEIZMANN.BITNET | | InterNet - nyevenba%weizmann.bitnet@cunyvm.cuny.edu | | | | Enjoy The Silence - Depeche Mode | +-------------------------------------------------------+