There are six strains of the AutoStart 9805 Worm. These strains can be copied to server volumes but they do not launch when the volumes are mounted. In some cases, the worm destroys earlier versions of the worm and/or destroys itself after a certain date.
AutoStart 9805 spreads via disks that contain an invisible application file named 'DB', 'BD' or 'DELDB' on the top level of volume (the root directory). When an infected disk is inserted into a Power Macintosh running QuickTime 2.5 or later, the 'DB', 'BD' or 'DELDB' application is launched automatically.
Your best defense against this worm is to de-select the option labelled 'Enable CD-ROM AutoPlay' in the QuickTime Settings Control Panel (QuickTime version 2.5 and later).
Strains
AutoStart 9805 A
Startup Application: DB
Background Application: Desktop Print Spooler
AutoStart 9805 B
Startup Application: BD
Background Application: Desktop Printr Spooler
AutoStart 9805 C
Startup Application: DELDB
Background Application: DELDesktop Print Spooler
AutoStart 9805 D
Startup Application: DB
Background Application: Desktop Print Spooler
AutoStart 9805 E
Startup Application: DB
Background Application: Desktop Print Spooler
AutoStart 9805 F
Startup Application: DB
Background Application: Desktop Print Spooler
SevenDust
There are 7 strains of the SevenDust virus. Some strains can infect an application by modifying specific resources and others can create a System Extension or add an 'INIT' resource to the System File.
Strains
SevenDust A
Spreads only but does not cause any damage
Extension: 666
SevenDust B
Activates every six months and deletes all document files
Extension: 666
SevenDust C
Extension: 666
SevenDust D
Extension: 666
SevenDust E
If launched between 6 and 7 AM on the 6th or 12th of the month, deletes document
files on the startup volume
Extension: Graphics Accelerator
SevenDust F
If launched between 6 and 7 PM on the 6th of the month, deletes document files on the
startup volume. A Trojan Horse application can initiate a sub-strain which may infect
applications, Control Panels and Extensions as well as the System file
Extension: ExtensionConflict
Extension: Graphics Accelerator
Extension: CD-ROM Driver
Extension: VideoSync
Extension: Monitors Plug-In
Extension: Open Transport
Extension: PPP.Lib
Extension: ADSP Tool
Extension: Photo Access
Extension: Video Picker
Extension: ISO 9661 File Access
Extension: Serial Port
Extension: XMODEM.Lib
Extension: TCP/IP.Lib
Extension: Text Encodings
Extension: Power Enabler
Extension: Internet Library
Extension: AppleTalk Library
Extension: MacLinkPlus
Extension: Internet Config
Extension: Ethernet Ports
SevenDust G
Attempts to delete document files when launched on the 6th of the month between 6
and 7 PM
Extension: Graphics Accelerator
Trojan Horses
Trojan Horses are programs or applets that may cause your system to act strangely. They can cause a great deal of damage and must be deleted. Trojan Horses may secretly install viruses on your Macintosh. Others may attempt to format currently mounted disks. Some Trojan Horses may erase or damage your hard disk directory.
Filenames
MacOS 8.5.1 Chooser Updater
MacOS 8.5.1 ChooserUpdater
200+ Sherlock PlugIns
50 Sherlock PlugIns
Movie BOOSTER
C&N August 1998.sit
C&N August 1998
Internet Hacking Tips
Mac OS 8.1 Tricks and Tips
Hotline Server Speedup
PC-Specific Viruses
Worms like "happy99" and macro viruses like "melissa" won't harm your Macintosh but it is possible to transfer them to other computers over a local area network and through e-mail so that a PC somewhere down the line eventually gets infected.