"nVIR C" Virus (15-July-1991) Entry...............: "nVIR C" Virus Alias(es)...........: --- Virus Strain........: nVIR Virus Strain Virus detected when.: July 1991 where.: USA Classification......: Application and System file infector Length of Virus.....: Resource fork extension: 3916 bytes (Application) 3934 bytes (System file) --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------- Easy Identification.: 1. Characteristic nVIR auxiliary resources 2. CODE 0 Jump table entry 1 changed to 0000 3F3C 0100 A9F0 Resource pattern....: System File Application Common to both INIT 32 416b CODE 256 788b nVIR 1 428b nVIR 0 2b nVIR 2 8b nVIR 6 66b nVIR 4 788b nVIR 3 416b nVIR 7 2106b nVIR 5 8b Type of infection...: 1. Infected application copies viral resources to the system file, adding nVIR 3 as an INIT 32 resource; an nVIR 0 counter resource is added and set to 1000; a dummy jump table entry for an infected application is added as nVIR 5. 2. On reboot, the INIT 32 resource is executed causing the TEInit trap to be patched. 3. Any application launched subsequently which calls this trap will be infected by the addi- tion of viral nVIR resources and a CODE 256 resource. 4. The application entry point in the CODE 0 jump table is saved as nVIR 2; the original entry is replaced by the stored nVIR 5 entry. Launching the application will then cause the viral CODE 256 resource to be executed, fol- lowing which the viral code will invoke the host application via the stored jump table entry. Infection trigger...: All applications calling the TEInit trap will cause attempted infection. Applications affected:All applications with a non-readonly resource fork and an unprotected CODE 0 resource will be infected. Traps intercepted...: TEInit Damage..............: Permanent damage: --- Transient damage: Virus occasionally beeps. Damage Trigger......: The counter nVIR 0 resource is set to 1000 on first infection of the system; this counter is decremented by 1 on system reboot, and by 2 each time when an infected application is run; when counter= 0, the virus will beep 1 in 8 reboots, and one in 4 infected appli- cation launches. Peculiarities.......: 1. An nVIR 10 resource in the system file will prevent infection by this virus. 2. Applications calling OpenResFile prior to TEInit will be damaged. 3. The virus will hybridise with other variants of the nVIR strain. Similarities........: The code of all resources is identical to nVIR B except the nVIR 4 resource in system file and the CODE 256 resource in applications. --------------------- Agents ----------------------------------------- Countermeasures/direct:1.Removal of INIT 32 from the system file will disinfect system. 2. Copying saved jump entry from nVIR 2 to first entry in CODE 0 jump table entry will dis- infect an application. Countermeasures/software: 1. Use a commercial anti-viral product or a public domain utility such as Virus Detective, VirusRx, Interferon or Disinfectant to scan for virus' signature. 2. Use a protection INIT such as vaccine or gatekeeper to trap resource manager calls. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 15-July-1991 Information Source..: --- .