Because this virus modifies the CODE 0 resource of an Application it is difficult to remove.
Open the infected application with ResEdit and look for a CODE 256 resource of size 372 or 422. If it is found, remove it. Next open the CODE 0 resource. If you see “000 3F3C 0100 A9F0” in the 3rd line, you will need to replace the 8 bytes shown above with the 8 bytes in the nVIR 2 resource. Remove all of the nVIR resources.
-- part contents for background part 11
----- text -----
Make sure you have repaired CODE 0 first! If you destroy the nVIR 2 resource before checking to see whether the CODE 0 resource was modified, you will not be able to repair the application.
Disinfecting a System file requires only that you boot from the clean system, as mentioned above, and then delete the INIT 32 resource and the nVIR resources from the infected System.