Path: utzoo!utgpu!news-server.csri.toronto.edu!cs.utexas.edu!sdd.hp.com!zaphod.mps.ohio-state.edu!unix.cis.pitt.edu!dsinc!netnews.upenn.edu!vax1.cc.lehigh.edu!cert.sei.cmu.edu!krvw From: padgett%tccslr.dnet@uvs1.orl.mmc.com (Padgett Peterson) Newsgroups: comp.virus Subject: Bloody/Beijing Virus (PC) Message-ID: <0007.9012141904.AA27940@ubu.cert.sei.cmu.edu> Date: 13 Dec 90 05:00:00 GMT Sender: Virus Discussion List Lines: 12 Approved: krvw@sei.cmu.edu Since Mr. Glath neglected to include a signature string in his VALERT posting, enclosed is a 16 byte id stringthat a user put on HOMEBASE for use with John's SCAN v71 /ext switch: 37 55 7b 78 78 73 6e 36 37 5d 62 79 39 37 23 3b I have not seen the virus so cannot attest to the string's validity but at least it is more than nothing. If someone has seen the virus please confirm/deny this string's effectiveness. Padgett