home *** CD-ROM | disk | FTP | other *** search
Text File | 1991-03-06 | 2.3 KB | 82 lines | [TEXT/GEOL] |
- Item forwarded by VOLOTTA to ANDERSON.K
-
- Item forwarded by RSWOLFF to PHUGHES M.BACKES VOLOTTA
-
- Item forwarded by SCHMUCKER1 to RSWOLFF
-
- Item forwarded by SCHMUCKER1 to MOORE12 D5717 PHELPS1
-
- Item forwarded by SCHMUCKER1 to BUBECK CDA0242 HAMMER2
-
- Item forwarded by HABLUTZEL to A0173
-
- Item forwarded by CREMER.M to NCD.STAFF$
-
- Item 2992173 5-June-90 12:27PDT
-
- From: MICRO.WAVES Microwaves Newsletter
-
- To: MACAPP.TECH$ MacApp Technical
-
- Sub: Steroid Trojan Horse WARNING
-
- Steroid Trojan Horse
- --------------------
-
- •••••••••• DESKTOP SERVICES WARNING ••••••••••
- •••••••••• DESKTOP SERVICES WARNING ••••••••••
-
- There is a Trojan Horse called "Steroid". It is an INIT that claims to speed
- up QuickDraw on Macintosh computers with 9" screens. The INIT contains code
- that checks for the date being greater than June 6,1990. If it is, it will
- ERASE all mounted drives.
-
- I have performed some tests on a Macintosh SE. Having Comm Toolbox installed
- seemed to interfere with the INIT and keep the erase from happening. The SE
- simply crashed.
-
- I then installed the INIT on a floppy disk and booted the SE. The floppy and
- hard disk were promply erased. NOTE: I had set the date to 7/7/90.
-
- So far, we know that the code does the following:
-
- OPERATIONS AT RESTART:
- ----------------------
- DATE & TIME CHECK (Loop)
- SYSENVIRONS CHECK
- GETS VOLUME INFORMATION (probably checking for HFS)
- GETS SOME ADRESSES (Toolbox traps)
- DOES SOME HFS DISPATCH OPERATIONS
- VOLUME IS REINITIALIZED to "Untitled"
-
- INFORMATION:
- ------------
- TYPE: INIT
- CREATOR: qdac
- CODE SIZE: 1080
- DATA SIZE: 267
- ID: 148
- Name: QuickDraw Accelorator
- File Name: " Steroid" (First 2 characters are ASCII 1)
-
- WHAT TO DO:
- -----------
- If your disk becomes erased, you can use SUM II Disk Clinic to recover the
- deleted files. We have tried this and it seems to work. If you read this
- today, before June 6 1990, REMOVE the Steroid INIT from all disks IMMEDIATELY.
-
-
-
- POSTED BY:
-
- Thomas Scott
- Desktop Services
- AppleLink: MICRO.SUPT
-
- Thanks to Larry Nedry, Lee Neuse, & Gary Giusti for information
-
- •••••••••• DESKTOP SERVICES WARNING ••••••••••
- •••••••••• DESKTOP SERVICES WARNING ••••••••••
-
-
-