"ALADIN" Virus (14-June-1990) Entry...............: "ALADIN" Virus Alias(es)...........: --- Virus Strain........: "Aladin Emulator Viruses" Virus detected when.: December '87 where.: Hamburg, FRG The virus was detected on a disk containing a document transfer utility for Aladin which was deliberately distributed by the Aladin producer "Proficomp" to protect their Aladin hardware and software by destroying illegal copies. Classification......: Program Virus Length of Virus.....: Varying from 3312 to 3822 Bytes in storage --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS Version/Release.....: Version 2.0 and higher Computer model(s)...: infection: all Apple MacIntosh series computers Aladin (MacIntosh-Emulator on Atari); other emulators not tested (probably, Spectre (Atari) will not be infected); all ROM versions damage: will only occur on ATARI ST computers running a MacIntosh Emulator other than the original ALADIN (Board equipped with ROMs and a PAL chip) --------------------- Attributes ------------------------------------ Easy Identification.: --- Type of infection...: - extending infected programs by virus size - modifying infected program's jump table - patching operating system calls in RAM - upon each launch, the programs "last modified" date entry is updated Infection Trigger...: - program files are infected when copied (when an infected "Finder" is running) - program files are infected when launched (when an infected "Finder" is running) - a running "Finder" is infected when it launches an infected program Storage media affected: all type of media which is not write-protected Interrupts hooked...: System traps OpenRF and SetFileInfo Damage..............: all printing functions are intercepted Damage Trigger......: value of infection counter Particularities.....: Probably, Spectre (MacIntosh emulator) will not be infected (similar to Frankie) as a bug in Spectre's bus error handler may deceive Aladin into thinking that it is not running on an Atari. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures.....: Names of tested products of Category 1-5: Category 1: --- Category 2: Viruskiller (VTC) Category 3: Viruskiller, FrankieKiller (VTC) Category 4: --- Category 5: write protect media Category 6: --- Countermeasures successful: Applying Viruskiller application Standard means......: - check file size, file modification date - open file with ResEdit and check sequence of "CODE" resource entries: if the upper left icon has a higher resource number, be warned; - open "CODE 0" with ResEdit and check byte $15: if it equals the highest available resource number, be warned; - use the INIT "Vaccine" --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, FRG Classification by...: Christian Markus, VTC Documentation by....: Christian Markus/Zbigniew Fiedorowicz Date................: 14-June-90 Information Source..: --- .