"nVIR A" Virus (20-July-1990) Entry...............: "nVIR A" Virus Alias(es)...........: --- Virus Strain........: nVIR Virus Strain Virus detected when.: December 1987 where.: USA Classification......: Application and system file infector Length of Virus.....: Resource fork extension 3658 bytes (application), 3676 bytes (System file) --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: 1. Characteristic nVIR auxiliary resources 2. CODE 0 Jump table entry 1 changed to 0000 3F3C 0100 A9F0 Resource pattern....: System file Application Common to both INIT 32 366b CODE 256 372b nVIR 1 378b nVIR 0 2b nVIR 2 8b nVIR 6 868b nVIR 4 372b nVIR 3 366b nVIR 7 1562b nVIR 5 8b Type of infection...: 1.Infected application copies viral resources to the system file, adding nVIR 3 as an INIT 32 resource. A nVIR 0 counter resource is added and set to 1000, a dummy jump table entry for an infected application is added as nVIR 5. 2.On reboot the INIT 32 resource is executed causing the TEInit trap to be patched. 3.An application subsequently launched which calls this trap will be infected by the addi- tion if viral nVIR resources and a CODE 256 resource. 4.The application entry point in the CODE 0 jump table is saved as nVIR 2. The original entry being replaced by the stored nVIR 5 entry. Launch of the application will now cause the viral CODE 256 resource to be executed, fol- lowing which the viral code will invoke the host application via the stored jump table entry. Infection trigger...: All applications calling the TEInit trap will cause infection to be attempted. Applications affected:All applications which are not locked, have a non-readonly resource fork and an un- protected CODE 0 resource will be infected. Traps intercepted...: TEInit Damage..............: None. Virus occasionally uses MacinTalk to say the words "Don't Panic", if the latter is not installed the virus will beep. Damage Trigger......: The counter nVIR 0 resource is set to 1000 on 1st infection of the system. This counter is de- cremented by 1 on system reboot, and 2 each time an infected application is run. When the counter reaches zero the virus will speak or beep 1 in 16 reboots, and 1 in 8 infected application launches. Peculiarities.......: 1. An nVIR 10 resource in the system file will prevent infection by the virus. 2. Applications calling OpenResFile prior to TEInit will be damaged. 3. The virus will hybridise with other variants of the nVIR strain. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct: 1. Removal of INIT 32 from the system file will disinfect system. 2. Copying saved jump entry from nVIR 2 to first entry in CODE 0 jump table entry will dis- infect an application. Countermeasures/software: 1. Use of a commercial anti-viral product or a public domain utility such as Virus detective, VirusRx, Interferon or Disinfectant to carry out virus signature scans. 2. Use of a protection INIT such as vaccine or gatekeeper to trap resource manager calls. --------------------- Acknowledgement -------------------------------- Location............: Heriot-Watt University, Edinburgh (UK) Classification by...: David Ferbrache Documentation by....: David Ferbrache Date................: 12-March-1990 Information Source..: --- .