home *** CD-ROM | disk | FTP | other *** search
Text File | 1988-11-29 | 2.0 KB | 39 lines | [TEXT/WORD] |
- The nVIR Virus
- --------------
- How the nVIR Virus Spreads and What It Does
-
- The nVIR virus is similar to the Scores virus in many ways. It does not
- appear to have malicious intent and is relatively harmless. Initial
- infection of a system is also caused by an application with a modified
- CODE ID = 0 resource. When a nVir carrier application is launched, the
- virus' code segment is executed first. This code checks for its INIT in
- the System File, and if it doesn't find it, the code copies the INIT there.
- Along with the INIT resource, eight 'nVIR' resources (0-7) are added to the
- System file.
-
- The next time the system is restarted, the INIT ID = 32 is loaded into
- memory and tries to infect every application that is launched. The nVir
- virus adds a CODE ID = 256 resource and modifies the CODE ID = 0 so that
- the nVir code is executed first.
-
- Again, infection of an application is determined by examination of the
- CODE ID = 0 resource. If the eleventh word of the resource (third word on
- the third line in the ResEdit listing) is NOT "0001", the application is
- suspect. If the third word is something other than "0001", convert the
- value to its decimal equivalent (the numbers are in hexadecimal). Then
- determine the resource number of the CODE resource at the top of the ResEdit
- resource list. If these numbers are the same, the application is probably
- infected, and should be replaced. Some applications will appear to be
- infected even though they are not. If the eleventh word of CODE ID = 0 is
- not 1, check the tenth word; if it is '4EED' the application is most likely
- not infected. The tenth word normally contains '3F3C'.
-
- When launching an infected application, there is a one in sixteen chance
- that you will hear a short system beep. We have been told that if MacinTalk
- is installed you will hear the words "don't panic".
-
- How to Get Rid of the nVIR Virus
-
- Remove the nVIR virus the same way you remove the Scores virus except you
- do not need to throw away all of the files in the System Folder; just throw
- away the System file.