Path: utzoo!attcan!utgpu!utstat!jarvis.csri.toronto.edu!mailrus!tut.cis.ohio-state.edu!ukma!rutgers!netnews.upenn.edu!vax1.cc.lehigh.edu!ubu.cc.lehigh.edu!virus-l From: gutman@manta.nosc.mil (Lewis M. Gutman) Newsgroups: comp.virus Subject: Mac II virus? Message-ID: <0002.8905301959.AA06345@ubu.CC.Lehigh.EDU> Date: 30 May 89 15:34:30 GMT Sender: Virus Discussion List Reply-To: VIRUS-L@IBM1.CC.Lehigh.EDU Lines: 28 Approved: virus-l@ubu.cc.lehigh.edu I'm not sure I'm having a virus problem, but I wanted to check if anyone has had similar experiences. After attending a virus seminar, I went back and checked my Mac II, and noticed that the System file had been modified earlier that day. I ran Interferon 3.1 and it showed a virus type 003 in my TOPS file. The Interferon documentation says that virus type 003 is the "SNEAKS" virus, and that this virus affects the INITs in the System folder. There are only 6 INITs in my System folder, one for each of the three TOPS files: TOPS, SOFTTALK, and SPOOL. EasyAccess has three INITs. I ran ResEdit over all the INITs and couldn't find any strings like "Evil Wizard," or anything else overtly suspicious. Another symptom: I've been running Gatekeeper in Notify Only mode for the past month, and whenever I bring up the machine, it gives warnings for SPOOL and TOPS. I've ignored those messages, thinking that TOPS (and SPOOL) were just performing some misinterpretted, but legal operation. Anyone having similar experiences? Am I infected? Thanks. Lew Gutman Naval Ocean Systems Center San Diego, Ca. (619) 553-4958