======= Computer Virus Catalog 1.2: "AIDS" Virus (20-July-1990) ======
Entry...............: "AIDS" Virus
Alias(es)...........: ---
Virus Strain........: nVIR (B) Virus Strain
Virus detected when.: March 1989
              where.: Netherlands
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3550 bytes (application),
                         3568 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Variation...........: All details are as for nVIR B except that all
                      references to nVIR resources should be read as
                      AIDS resources; for all other details: see
                      nVIR B (MACVIR.790)
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "AIDS"-Virus ============================
====== Computer Virus Catalog 1.2: "ALADIN" Virus (14-June-1990) =====
Entry...............: "ALADIN" Virus
Alias(es)...........: ---
Virus Strain........: "Aladin Emulator Viruses"
Virus detected when.: December '87
              where.: Hamburg, FRG
                      The virus was detected on a disk containing a
                      document transfer utility for Aladin which was
                      deliberately distributed by the Aladin producer
                      "Proficomp" to protect their Aladin hardware
                      and software by destroying illegal copies.
Classification......: Program Virus
Length of Virus.....: Varying from 3312 to 3822 Bytes in storage
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS
Version/Release.....: Version 2.0 and higher
Computer model(s)...: infection: all Apple MacIntosh series computers
                         Aladin (MacIntosh-Emulator on Atari); other
                         emulators not tested (probably, Spectre (Atari)
                         will not be infected); all ROM versions
                      damage: will only occur on ATARI ST computers
                         running a MacIntosh Emulator other than the
                         original ALADIN (Board equipped with ROMs
                         and a PAL chip)
--------------------- Attributes ------------------------------------
Easy Identification.: ---
Type of infection...: - extending infected programs by virus size
                      - modifying infected program's jump table
                      - patching operating system calls in RAM
                      - upon each launch, the programs "last modified"
                        date entry is updated
Infection Trigger...: - program files are infected when copied (when
                           an infected "Finder" is running)
                      - program files are infected when launched
                           (when an infected "Finder" is running)
                      - a running "Finder" is infected when it
                           launches an infected program
Storage media affected: all type of media which is not write-protected
Interrupts hooked...: System traps OpenRF and SetFileInfo
Damage..............: all printing functions are intercepted
Damage Trigger......: value of infection counter
Particularities.....: Probably, Spectre (MacIntosh emulator) will not
                         be infected (similar to Frankie) as a bug in
                         Spectre's bus error handler may deceive
                         Aladin into thinking that it is not running
                         on an Atari.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures.....: Names of tested products of Category 1-5:
                      Category 1: ---
                      Category 2: Viruskiller (VTC)
                      Category 3: Viruskiller, FrankieKiller (VTC)
                      Category 4: ---
                      Category 5: write protect media
                      Category 6: ---
Countermeasures successful: Applying Viruskiller application
Standard means......: - check file size, file modification date
                      - open file with ResEdit and check sequence of
                           "CODE" resource entries: if the upper left
                           icon has a higher resource number, be
                           warned;
                      - open "CODE 0" with ResEdit and check byte $15:
                        if it equals the highest available resource
                        number, be warned;
                      - use the INIT "Vaccine"
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, FRG
Classification by...: Christian Markus, VTC
Documentation by....: Christian Markus/Zbigniew Fiedorowicz
Date................: 14-June-90
Information Source..: ---
===================== End of "Aladin"-Virus ==========================
===== Computer Virus Catalog 1.2: "FRANKIE" Virus (14-June-1990) =====
Entry...............: "FRANKIE" Virus
Alias(es)...........: ---
Virus Strain........: "Aladin Emulator Viruses"
Virus detected when.: December '87
              where.: Hamburg, FRG
                      The virus was detected on a disk containing a
                      document transfer utility for Aladin which was
                      deliberately distributed by the Aladin producer
                      "Proficomp" to protect their Aladin hardware
                      and software by destroying illegal copies.
           appeared.: France: January 1989
Classification......: Program Virus
Length of Virus.....: Varying from 3312 to 3822 Bytes in storage
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS
Version/Release.....: Version 2.0 and higher
Computer model(s)...: Infection: all Apple MacIntosh series computers
                         and Aladin (MacIntosh Emulator on Atari));
                         Spectre (Atari) and AMAX (AMIGA) emulators
                         not infected, others not tested;
                         all ROM versions
                      Damage: will only occur on ATARI ST computers
                         running illegal emulators other than the
                         original ALADIN (Board equipped with ROMs
                         and a PAL chip); on AMAX (AMIGA) and SPECTRE
                         (Atari) emulators, Frankie is inactive.
--------------------- Attributes ------------------------------------
Easy Identification.: ---
Type of infection...: - extending affected programs by virus size;
                      - modifying affected program's jump table;
                      - patching operating system calls in RAM;
                      - upon  each launch, the programs "last
                           modified" date entry is updated.
Infection Trigger...: - program files are infected when copied (when
                           an infected "Finder" is running);
                      - program files are infected when launched
                           (when an infected "Finder" is running);
                      - a running "Finder" is infected when it
                           launches an infected program.
Storage media affected: All type of media which is not write-protected
Interrupts hooked...: System traps OpenRF and SetFileInfo
Damage..............: The menu bar is replaced with a 'bomb' icon and
                         the message "Frankie says:  no more piracy";
                         then, the system crashes.
Damage Trigger......: Value of infection counter, random time period
                         (taken from VBL).
Particularities.....: Spectre (MacIntosh emulator) will not be in-
                        fected as a bug in Spectre's bus error
                        handler deceives Aladin into thinking that
                        it is not running on an Atari.
Similarities........: ---
--------------------- Agents ------------------------------------------
Countermeasures.....: Names of tested products of Category 1-5:
                      Category 1: ---
                      Category 2: Viruskiller (VTC)
                      Category 3: Viruskiller, FrankieKiller (VTC)
                      Category 4: ---
                      Category 5: write protect media
                      Category 6: ---
                      Moreover, many Macintosh antivirus programs
                      detect and eradicate Frankie.
Countermeasures successful: Applying Viruskiller application
Standard means......: - Check file size, file modification date;
                      - open file with ResEdit and check sequence of
                           "CODE" resource entries; if the upper left
                           icon has a higher resource number, be
                           alert;
                      - open "CODE 0" with ResEdit and check byte $15;
                           if it equals the highest available resource
                           number, be warned.
                      - Use the INIT "Vaccine"
--------------------- Acknowledgement --------------------------------
Location............: Virus Test Center, University Hamburg, FRG
Classification by...: Christian Markus, VTC
Documentation by....: Christian Markus/Zbigniew Fiedorowicz
Date................: 14-June-90
Information Source..: Zbigniew Fiedorowicz, Ohio (USA)
===================== End of "Frankie" Virus =========================
======= Computer Virus Catalog 1.2: "fuck" Virus (20-July-1990) ======
Entry...............: "fuck" Virus
Alias(es)...........: ---
Virus Strain........: nVIR Virus (B) Strain
Virus detected when.: January 1990
              where.: USA
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3550 bytes (application),
                         3568 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Variation...........: All details are as for nVIR B except that all
                      references to nVIR resources should be read as
                      fuck resources; for all other details:
                      see nVIR B (MACVIR.790)
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "fuck" Virus ============================
====== Computer Virus Catalog 1.2: "Hpat" Virus (20-July-1990) =======
Entry...............: "Hpat" Virus
Alias(es)...........: ---
Virus Strain........: nVIR (B) Virus Strain
Virus detected when.: December 1988
              where.: Arizona, USA
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3550 bytes (application),
                         3568 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Variation...........: All details are as for nVIR B except that all
                      references to nVIR resources should be read as
                      Hpat resources, and CODE 256 to be read as
                      CODE 255; for other details: nVIR B (MAC.790)
Easy identification.: 1. Characteristic Hpat auxiliary resources
                      2. CODE 0 Jump table entry 1 changed to
                                0000 3F3C 00FF A9F0
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "Hpat" Virus ============================
======= Computer Virus Catalog 1.2: "Jude" Virus (20-July-1990) ======
Entry...............: "Jude" Virus
Alias(es)...........: ---
Virus Strain........: nVIR (B) Virus Strain
Virus detected when.: November 1989
              where.: Switzerland
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3550 bytes (application),
                         3568 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Variation...........: All details are as for nVIR B except that all
                      references to nVIR resources should be read as
                      Jude resources; for all other details:
                      see nVIR B (MACVIR.790)
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "Jude" Virus ============================
====== Computer Virus Catalog 1.2: "MEV#" Virus (20-July-1990) =======
Entry...............: "MEV#" Virus
Alias(es)...........: ---
Virus Strain........: nVIR (B) Virus Strain
Virus detected when.: April 1989
              where.: Belgium
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3550 bytes (application),
                         3568 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Variation...........: All details are as for nVIR B except that all
                      references to nVIR resources should be read as
                      MEV# resources; for all other details:
                      see nVIR B (MACVIR.790)
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "MEV#" Virus ============================
======= Computer Virus Catalog 1.2: "nFLU" Virus (20-July-1990) ======
Entry...............: "nFLU" Virus
Alias(es)...........: ---
Virus Strain........: nVIR (B) Virus Strain
Virus detected when.: August 1989
              where.: Minnesota, USA
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3550 bytes (application),
                         3568 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Variation...........: All details are as for nVIR B except that all
                      references to nVIR resources should be read as
                      nFLU resources; for all other details:
                      see nVIR B (MACVIR.790)
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "nFLU" Virus ============================
====== Computer Virus Catalog 1.2: "nVIR A" Virus (20-July-1990) =====
Entry...............: "nVIR A" Virus
Alias(es)...........: ---
Virus Strain........: nVIR Virus Strain
Virus detected when.: December 1987
              where.: USA
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3658 bytes (application),
                         3676 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Easy Identification.: 1. Characteristic nVIR auxiliary resources
                      2. CODE 0 Jump table entry 1 changed to
                                0000 3F3C 0100 A9F0
Resource pattern....: System file     Application     Common to both
                       INIT 32 366b    CODE 256 372b   nVIR 1 378b
                       nVIR 0  2b      nVIR 2   8b     nVIR 6 868b
                       nVIR 4  372b    nVIR 3   366b   nVIR 7 1562b
                       nVIR 5  8b
Type of infection...:  1.Infected application copies viral resources
                         to the system file, adding nVIR 3 as an
                         INIT 32 resource. A nVIR 0 counter resource
                         is added and set to 1000, a dummy jump table
                         entry for an infected application is added as
                         nVIR 5.
                       2.On reboot the INIT 32 resource is executed
                         causing the TEInit trap to be patched.
                       3.An application subsequently launched which
                         calls this trap will be infected by the addi-
                         tion if viral nVIR resources and a CODE 256
                         resource.
                       4.The application entry point in the CODE 0 jump
                         table is saved as nVIR 2. The original entry
                         being replaced by the stored nVIR 5 entry.
                         Launch of the application will now cause the
                         viral CODE 256 resource to be executed, fol-
                         lowing which the viral code will invoke the
                         host application via the stored jump table
                         entry.
Infection trigger...: All applications calling the TEInit trap will
                           cause infection to be attempted.
Applications affected:All applications which are not locked, have a
                          non-readonly resource fork and an un-
                          protected CODE 0 resource will be infected.
Traps intercepted...: TEInit
Damage..............: None. Virus occasionally uses MacinTalk to say
                         the words "Don't Panic", if the latter is not
                         installed the virus will beep.
Damage Trigger......: The counter nVIR 0 resource is set to 1000 on 1st
                         infection of the system. This counter is de-
                         cremented by 1 on system reboot, and 2 each
                         time an infected application is run. When the
                         counter reaches zero the virus will speak or
                         beep 1 in 16 reboots, and 1 in 8 infected
                         application launches.
Peculiarities.......: 1. An nVIR 10 resource in the system file will
                         prevent infection by the virus.
                      2. Applications calling OpenResFile prior to
                         TEInit will be damaged.
                      3. The virus will hybridise with other variants
                         of the nVIR strain.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures/direct:
                      1. Removal of INIT 32 from the system file will
                         disinfect system.
                      2. Copying saved jump entry from nVIR 2 to first
                         entry in CODE 0 jump table entry will dis-
                         infect an application.
Countermeasures/software:
                      1. Use of a commercial anti-viral product or a
                         public domain utility such as Virus detective,
                         VirusRx, Interferon or Disinfectant to carry
                         out virus signature scans.
                      2. Use of a protection INIT such as vaccine or
                         gatekeeper to trap resource manager calls.
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "nVIR A" Virus ==========================
====== Computer Virus Catalog 1.2: "nVIR B" Virus (20-July-1990) =====
Entry...............: "nVIR B" Virus
Alias(es)...........: ---
Virus Strain........: nVIR Virus Strain
Virus detected when.: December 1987
              where.: USA
Classification......: Application and system file infector
Length of Virus.....: Resource fork extension 3550 bytes (application),
                         3568 bytes (System file)
--------------------- Preconditions ----------------------------------
Operating System(s).: MacOS proprietary
Version/Release.....: All
Computer model(s)...: Apple Macintosh: all models
--------------------- Attributes ------------------------------------
Easy Identification.: 1. Characteristic nVIR auxiliary resources
                      2. CODE 0 Jump table entry 1 changed to
                                0000 3F3C 0100 A9F0
Resource pattern....: System File     Application     Common to both
                        INIT 32 416b    CODE 256 422b   nVIR 1 428b
                        nVIR 0  2b      nVIR 2   8b     nVIR 6 66b
                        nVIR 4  422b    nVIR 3   416b   nVIR 7 2106b
                        nVIR 5  8b
Type of infection...:  1.Infected application copies viral resources
                         to the system file, adding nVIR 3 as an
                         INIT 32 resource. A nVIR 0 counter resource
                         is added and set to 1000, a dummy jump table
                         entry for an infected application is added as
                         nVIR 5.
                       2.On reboot the INIT 32 resource is executed
                         causing the TEInit trap to be patched.
                       3.An application subsequently launched which
                         calls this trap will be infected by the addi-
                         tion if viral nVIR resources and a CODE 256
                         resource.
                       4.The application entry point in the CODE 0 jump
                         table is saved as nVIR 2. The original entry
                         being replaced by the stored nVIR 5 entry.
                         Launch of the application will now cause the
                         viral CODE 256 resource to be executed, fol-
                         lowing which the viral code will invoke the
                         host application via the stored jump table
                         entry.
Infection trigger...: All applications calling the TEInit trap will
                           cause infection to be attempted.
Applications affected:All applications which are not locked, have a
                          non-readonly resource fork and an un-
                          protected CODE 0 resource will be infected.
Traps intercepted...: TEInit
Damage..............: None. Virus occasionally beeps.
Damage Trigger......: The counter nVIR 0 resource is set to 1000 on 1st
                         infection of the system. This counter is de-
                         cremented by 1 on system reboot, and 2 each
                         time an infected application is run. When the
                         counter reaches zero the virus will beep 1 in
                         8 reboots, and 1 in 4 infected application
                         launches.
Peculiarities.......: 1. An nVIR 10 resource in the system file will
                         prevent infection by the virus.
                      2. Applications calling OpenResFile prior to
                         TEInit will be damaged.
                      3. The virus will hybridise with other variants
                         of the nVIR strain.
Similarities........: ---
--------------------- Agents -----------------------------------------
Countermeasures/direct:
                      1. Removal of INIT 32 from the system file will
                         disinfect system.
                      2. Copying saved jump entry from nVIR 2 to first
                         entry in CODE 0 jump table entry will dis-
                         infect an application.
Countermeasures/software:
                      1. Use of a commercial anti-viral product or a
                         public domain utility such as Virus detective,
                         VirusRx, Interferon or Disinfectant to carry
                         out virus signature scans.
                      2. Use of a protection INIT such as vaccine or
                         gatekeeper to trap resource manager calls.
--------------------- Acknowledgement --------------------------------
Location............: Heriot-Watt University, Edinburgh (UK)
Classification by...: David Ferbrache
Documentation by....: David Ferbrache
Date................: 12-March-1990
Information Source..: ---
===================== End of "nVIR B" Virus ==========================
