======= Computer Virus Catalog 1.2: INIT 17 Virus (31-July-1993) =======
Entry...............: INIT 17 Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: April 1993
              where.: USA
Classification......: Link virus, Applications and System infector
Length of Virus.....: Resource fork extension: 1,682 bytes
--------------------- Preconditions ------------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All prior to System 7
Computer model(s)...: All.
--------------------- Attributes ---------------------------------------
Easy Identification.: INIT 17 resource in System file with the string
                         "Trnt" at offset 4 from the beginning.
                      In applications, same string can be found at
                         offset 1,678 from end of the CODE 1 resource.
Resource pattern....: INIT 17: 1,682 bytes in System file.
                      CODE 1:  extended by 1,682 bytes in applications.
Type of infection...: Adding an INIT 17 resource to System file.
                      Extending a present CODE 1 resource in applica-
                         tions and modifying the CODE 0 resource to
                         point at virus code.
Infection trigger...: 1. Starting an infected application infects
                         system, and every application started after-
                         wards becomes infected.
                      2. After starting up with an infected System,
                         every application launched becomes infected.
Applications affected:1. The System file
                      2. All applications except Finder,
                         All programs created with StuffIt (self
                         extracting archives),
                         file Virex and all applications who's creator
                         starts with 'AL'.
                      An application can only be infected when the
                         following preconditions hold:
                         a) first entry in CODE 0 points to CODE 1,
                         b) size of CODE 1 < 31,086 bytes,
                         c) file is not locked or it's name is locked,
                         d) file is not already infected.
Traps intercepted...: LoadSeg
Damage..............: The virus pops up a window named
                         "From the depths of Cyberspace" displaying the
                         message "-Trent Saburo was here". On 68000
                         systems (old Macs), a system bus error occurs.
Damage Trigger......: Running an infected System or application after
                         internal date reached Oct.31,1993 6:06:06 AM.
Peculiarities.......: If WriteResource and SetResAttrs traps are
                         redirected to RAM (eg. by AntiVirus program),
                         the virus does NOT infect programs.
Similarities........: ---
--------------------- Agents -------------------------------------------
Countermeasures/direct: Remove INIT 17 resource from System file using
                         ResEdit. Repairing applications should NOT be
                         performed manually.
Countermeasures/software:Use a commercial, shareware or freeware Anti-
                         Viral product such as VirusDetective or
                         Disinfectant >= 3.2 to scan for viral signatures.
--------------------- Acknowledgement ----------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Hisao Tai, Peer Reymann, Ronald Greinke
Documentation by....: Tim Dierks
Date................: 31-July-1993
===================== End of INIT 17 Virus =============================
======= Computer Virus Catalog 1.2: INIT M Virus (31-July-1993) ========
Entry...............: INIT M Virus
Alias(es)...........: WDEF M = MindCrime Virus
Virus Strain........: ---
Virus detected when.: April 1993
              where.: USA
Classification......: Link virus, Applications and System infector
Length of Virus.....: WDEF 0:           5,840 bytes
                      INIT (random ID): 2,766 bytes named "MindCrime"
--------------------- Preconditions ------------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: System 7 and upwards
Computer model(s)...: All.
--------------------- Attributes ---------------------------------------
Easy Identification.: INIT resource named "MindCrime". A file called
                         "FSV Prefs" in Preferences folder.
Resource pattern....: INIT (random ID): 2,766 bytes
                      WDEF 0:           5,840 bytes in applications.
Type of infection...: Adding the two resources to any resource file open.
Infection trigger...: 1. Executing SystemTask trap with a probability
                         of 11/60.
                      2. Opening a window with an infected WDEF 0
                         resource in most recently opened resource file.
Applications affected:All resource files except Finder and System. Only
                         INIT's with following names are affected:
                         "File Sharing Extension", "Apple Share",
                         "Apple CD-ROM", "QuickTime", "CD Remote INIT".
Traps intercepted...: SystemTask
Damage..............: 1. Renames all files to random 8 byte names.
                      2. Renames folder to random 1..8 character names.
                      3. Changes Type and Creator to random 4 byte values.
                      4. Changes creation and modification date to
                         January 1, 1904.
                      5. Files that can't be renamed will be deleted.
                      6. Files to be renamed will be choosen in alpha-
                         betical order, so some files will be renamed
                         multiple times and some won't be renamed at all.
                      7. One file or folder may be renamed to
                         "Virus MindCrime" - if not renamed again.
Damage Trigger......: Running system with internal date Friday 13th.
                         (no boot needed!)
Peculiarities.......: ---
Similarities........: Damage is similar to that one of INIT 1984 virus.
--------------------- Agents -------------------------------------------
Countermeasures/direct: 1. Boot from a clean System disk.
                        2. Remove INIT resource named "MindCrime" from
                           all(!) files that have a resource fork.
                        3. Remove any WDEF 0 resource with length=5,840
                           which contains string "MindCrime".
                        4. Delete "FSV Prefs" file from Preferences
                           folder.
Countermeasures/software:Use a commercial, shareware or freeware Anti-
                         Viral product such as VirusDetective or
                         Disinfectant >= 3.2 to scan for viral signatures.
--------------------- Acknowledgement -----------------------------------
Location............: Virus Test Center, University Hamburg,Germany
Classification by...: Peer Reymann, Ronald Greinke
Date................: 31-July-1993
===================== End of INIT M Virus ===============================
== Computer Virus Catalog 1.2: Merryxmas HyperCard Virus (31-July-1993)==
Entry...............: Merryxmas Virus
Alias(es)...........: ---
Virus Strain........: ---
Virus detected when.: October 1991
              where.: Cornell University, USA
Classification......: Hypercard stacks infector
Length of Virus.....: 1384 Bytes (XCMD Resources)
--------------------- Preconditions -------------------------------------
Operating System(s).: MacOS proprietary and Hypercard
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models with 128 KByte ROM
--------------------- Attributes ----------------------------------------
Easy Identification.: Stack contains resources "XCMD" ID 69 and ID 405
Resource pattern....: XCMD 69 "openbackground", XCMD 405 "viralcopy"
Type of infection...: Virus infects hypercard stack scripts.
Infection trigger...: Virus will infect other stack scripts when an
                         infected stack is opened. An uninfected Home
                         stack will be infected first.
Applications affected: All Hypercard stacks.
Traps intercepted...: ---
Damage..............: Permanent/Transient damage: Virus contains an XCMD
                         which will shutdown the System without saving
                         open documents; therefore, new documents are
                         lost. But virus script does not contain any
                         command to execute XCMD.
Damage Trigger......: The script contains no commands to execute the
                         damage routine which is in XCMD id 69 (at least
                         in the version available for analysis).
Peculiarities.......: Virus is written in Hypertalk.
Similarities........: ---
--------------------- Agents --------------------------------------------
Countermeasures/direct:1. Delete XCMD Resource pattern from Home stack
                          and all other infected stacks with ResEdit.
                       2. Start HyperCard and search in stackscript for
                          string "on openbackground --merryxmas" and
                          delete the script until string "end getxmas".
                       3. Then quit HyperCard.
                       4. Writeprotect HyperCard Home stack and then
                          delete the script virus from the other infected
                          stacks following step 2.
Countermeasures/software: merryxmas vaccine
--------------------- Acknowledgement -----------------------------------
Location............: Virus Test Center, University Hamburg, Germany
Classification by...: Thomas Piehl, Ralf Stegen
Documentation by....: Ralf Stegen
Date................: 31-July-1993
Information Source..: ---
=================== End of Merryxmas HyperCard Virus ====================
