home *** CD-ROM | disk | FTP | other *** search
-
- xThe nVIR Virus
-
-
- According to news reports, the nVIR virus first appeared in Europe in
-
- 1987 and in the United States in early 1988. At least one variation of the
-
- virus was written. We know of two basic strains, which we call “nVIR A”
-
- and “nVIR B.”
-
-
- We have reliable reports of an earlier third version of nVIR which was
-
- malicious. It destroyed files in the System folder. This earlier version
-
- appears to be extinct, and we have not been able to obtain a copy.
-
-
- nVIR is simpler than Scores. It infects the System file, but it does not
-
- infect the Note Pad or Scrapbook files, and it does not create any invisible
-
- files. nVIR begins spreading to other applications immediately, without the
-
- two day delay. Whenever a new application is run, it becomes infected
-
- immediately, without the two to three minute delay. As with Scores,
-
- some applications are immune to infection, the Finder and DA Handler
-
- usually also become infected, and document files are not infected or
-
- modified.
-
-
- At first nVIR A and B only replicate. When the System file is first
-
- infected, a counter is initialized to 1000. The counter is decremented by
-
- one each time the system is started up and it is decremented by two each
-
- time an infected application is run.
-
-
- When the counter reaches zero, nVIR A will sometimes either say “Don’t
-
- panic” (if MacinTalk is installed in the System folder) or beep (if
-
- MacinTalk is not installed in the System folder). This will happen on
-
- system startup with a probability of 1/16. It will also happen, with a
-
- probability of 15/128, when an infected application is run. In addition,
-
- when an infected application is run, nVIR A may say “Don’t panic” twice
-
- or beep twice with a probability of 1/256.
-
-
- When the counter reaches zero, nVIR B will sometimes beep. nVIR B does
-
- not call MacinTalk. The beep will happen on a system startup with a
-
- probability of 1/8. A single beep will happen when an infected application
-
- is run with a probability of 7/32. A double beep will happen when an
-
- infected application is run with a probability of 1/64.
-
-
- It is possible for nVIR A and nVIR B to mate and reproduce, resulting in
-
- new viruses combining parts of their parents. Disinfectant will report
-
- that such offspring are infected by both nVIR A and nVIR B and will
-
- properly repair them.
-
-
- Unlike Scores, there is no way to tell that you have an nVIR infection just
-
- by looking at your system. You must run Disinfectant or some other virus
-
- detection tool.
-
-
- One of the viral resources added to infected files by nVIR has the resource
-
- type “nVIR,” which is how it got its name.
-
-
- As with Scores, nVIR occupies both memory and disk space, and this alone
-
- is enough to cause problems.
-
-
- In addition to the two basic strains of nVIR, many “clones” of nVIR B have
-
- appeared. These clones are all identical to nVIR B with the exception of a
-
- few very minor technical differences. Disinfectant recognizes all of these
-
- clones and treats them exactly the same as nVIR B.
-
-
-
-