Recent outbreak of viruses on campus


by Debbie Dexter - CCC Computer Trainer

If you haven't already heard during the student break, there had been a discovery of fourteen different viruses on campus. These viruses are:

Little Red.A
Little Red.B
Little Red.1439
Little Red
Monkey_b
Form_A
NYB
Stealth-C
Gen_B
Bananna
Israeli Boot Virus
Ohio Boot Virus
Michaelangelo
AntiExec

Unfortunately, three versions of Little Red infected different servers. The September version of McAfee VirusScan on the network did not detect these viruses so they were able to pass to the server. When running the network drivers, the viruses were spread to some computers across campus. Security precautions have been put in place to avoid further infections of the server. As computers across campus were scanned for these viruses, many other viruses were discovered that were spread through the conventional method of disks to hard drives.

The Little Red viruses that were spread to the server were compressed. These particular compressed viruses lay dormant, attached to *.exe, *.com and *.dll files. When these filed were opened the virus became active and could then attack other files on the hard drive, rendering programs like Windows or even the automenu inoperable. Fortunately, the servers have been "cleaned" of these viruses so no further infection can occur through a server. Infected computers/floppies that have not been "cleaned" can still spread Little Red from computer to computer.

Most importantly, how do you know if you have a virus on your computer and if so how do you get rid of it? Well, if you were like almost every other student on break, you didn't log in when the viruses had not yet been detected on the server so you survived. This doesn't mean you don't have a virus on your computer, it simply means you didn't get the Little Red virus from the server. When in doubt scan!, scan!, scan!!!! The new version of McAfee's VirusScan that does identify Little Red is available at ftp.mcafee.com in the /pub/antivirus directory (consult the 00-index.txt file for further details) or from any of the WPI Novell Servers in the o:\sharewar\scan directory.

If you do find a virus on your computer, please e-mail pc-questions@wpi and they will get to you as soon as possible. Most of the viruses can be cleaned through the clean command. The only completely successful method we have discovered for cleaning Little Red has been to FDISK and FORMAT the infected hard drive. BE SURE TO BACK UP YOUR DATA FIRST! After removing viruses with "clean", some of the files are left unusable. It is possible to backup up any important data files you might have before wiping out your hard drive. We aren't recommending you back up any applications, instead re-install them all (with no exceptions, including DOS) with write protected disks. If you are going to make a back up, please boot your computer with a clean bootable floppy disk.

If you are not sure whether you have a virus and do not want to risk infection please come to the CCC Shop and they will supply you with a clean, bootable floppy disk with the latest version of McAfee VirusScan program on it.

The fact that large number of viruses were found alerts WPI users that we are not taking all the necessary precautions to prevent the spread of viruses. Always scan any new disk you introduce to your computer as well a periodically scanning your hard drive. The scan program is constantly updated to find new viruses. Be sure to keep up to date with the newest version. WPI is licensed to distribute the latest version of McAfee VirusScan to all WPI users without a registration fee. We will continue to keep you updated on viruses as well as any other new information from the CCC.



WPI Community Newspeak This Issue
Give feedback: newspeak@wpi.wpi.edu
Maintained by: Troy Thompson