CODE 252 Virus (25-July-1992) Entry...............: CODE 252 Virus Alias(es)...........: D-Day Virus Virus Strain........: --- Virus detected when.: April 1992 where.: USA Classification......: Application and system file infector Length of Virus.....: Resource fork extension 1916 bytes (application), 1908 bytes (System file) --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All versions (including System 7) Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: 1. CODE 252 Resource 1908 Bytes in applications 2. INIT 34 Resource in System 3. The following strings can be found at offset Hex 3E0 from beginning of both resources: "Ha Ha Ha Ha Ha Ha Ha You have a virus. Now erasing all disks! P.S. Have a nice day (Click to continue!)" Resource pattern....: CODE ID 252 1908 Bytes; INIT ID 34 1908 Bytes Type of infection...: Applications infect the System by adding a INIT 34 Resource. System and Applications infect other applications by adding a CODE 252 Resource and patching the Jumptable to point at it. Infection trigger...: To infect system: Running an infected application. To infect application: Running it by using the Launch trap. Applications affected:System, all applications including the Finder. Traps intercepted...: Launch,AddResource,ChangedResource,WriteResource Damage..............: The Virus opens a window, displays some text (see Easy Identification) and then removes itself. Damage Trigger......: If the internal clock's date is between June 6th (D-Day) and December 31th (included), any year. Peculiarities.......: The virus searches for a file 'Hard Disk:Empty Folder:pf' that includes a 'PROC' ID 42 Resource; if this is found, it will be executed, but the resource hasn't been encountered yet. The virus tries to work around SAM Intercept by getting the addresses of AddResource, ChangedResource and WriteResource out of the code of SAM to call Traps without SAM noticing it; this will go wrong if any other program or recent versions of SAM starts the pathed trap calls with a JSR instruction ($4EFA) or if the patch-address are located at another adress. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct: 1. Removal of INIT 34 from the system file will disinfect the system. 2. Copying saved jump entry from CODE 252 offset Hex 45A to the first entry in CODE 0 jump table entry will disinfect an infected application. Countermeasures/software:1. Use of a commercial anti-viral product or a public domain utility such as Virus Detective, Disinfectant >=2.8 to carry out virus signature scans. 2. Use of a protection INIT such as Vaccine or Gatekeeper to trap resource manager calls. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 20-April-1992 .