INIT M Virus (31-July-1993) Entry...............: INIT M Virus Alias(es)...........: WDEF M = MindCrime Virus Virus Strain........: --- Virus detected when.: April 1993 where.: USA Classification......: Link virus, Applications and System infector Length of Virus.....: WDEF 0: 5,840 bytes INIT (random ID): 2,766 bytes named "MindCrime" --------------------- Preconditions ------------------------------------ Operating System(s).: MacOS proprietary Version/Release.....: System 7 and upwards Computer model(s)...: All. --------------------- Attributes --------------------------------------- Easy Identification.: INIT resource named "MindCrime". A file called "FSV Prefs" in Preferences folder. Resource pattern....: INIT (random ID): 2,766 bytes WDEF 0: 5,840 bytes in applications. Type of infection...: Adding the two resources to any resource file open. Infection trigger...: 1. Executing SystemTask trap with a probability of 11/60. 2. Opening a window with an infected WDEF 0 resource in most recently opened resource file. Applications affected:All resource files except Finder and System. Only INIT's with following names are affected: "File Sharing Extension", "Apple Share", "Apple CD-ROM", "QuickTime", "CD Remote INIT". Traps intercepted...: SystemTask Damage..............: 1. Renames all files to random 8 byte names. 2. Renames folder to random 1..8 character names. 3. Changes Type and Creator to random 4 byte values. 4. Changes creation and modification date to January 1, 1904. 5. Files that can't be renamed will be deleted. 6. Files to be renamed will be choosen in alpha- betical order, so some files will be renamed multiple times and some won't be renamed at all. 7. One file or folder may be renamed to "Virus MindCrime" - if not renamed again. Damage Trigger......: Running system with internal date Friday 13th. (no boot needed!) Peculiarities.......: --- Similarities........: Damage is similar to that one of INIT 1984 virus. --------------------- Agents ------------------------------------------- Countermeasures/direct: 1. Boot from a clean System disk. 2. Remove INIT resource named "MindCrime" from all(!) files that have a resource fork. 3. Remove any WDEF 0 resource with length=5,840 which contains string "MindCrime". 4. Delete "FSV Prefs" file from Preferences folder. Countermeasures/software:Use a commercial, shareware or freeware Anti- Viral product such as VirusDetective or Disinfectant >= 3.2 to scan for viral signatures. --------------------- Acknowledgement ----------------------------------- Location............: Virus Test Center, University Hamburg,Germany Classification by...: Peer Reymann, Ronald Greinke Date................: 31-July-1993 .