home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
MacHack 1995
/
MacHack 1995.toast
/
Presentations
/
Presentations ’90
/
John Norstad
/
Disinfectant 2.0b2
/
Disinfectant 2.0b2.rsrc
/
STR#_213.txt
< prev
next >
Wrap
Text File
|
1990-06-12
|
5KB
|
185 lines
### File infected by an unknown strain of WDEF
following message in the report:
been reported. If an unknown strain is detected, Disinfectant places the
also detect and repair other strains which may exist but have not yet
In addition to the two known strains of the WDEF virus, Disinfectant will
using MultiFinder, you will get an error message.
“busy,” and Disinfectant is not able to repair them. If you try to repair
instead of MultiFinder. Under MultiFinder, the Desktop files are always
When using Disinfectant to repair WDEF infections, you must use Finder
is cause for concern.
operating system. Any WDEF resource on a Finder Desktop file, however,
Finder Desktop files. WDEF resources are a normal part of the Macintosh
resources, do not be alarmed if you find them in files other than the
If you use ResEdit, VirusDetective, or some other tool to search for WDEF
from a TOPS client to a TOPS server.
infected volume. It does not appear, however, that the virus can spread
published volume’s Desktop file is infected and the client mounts the
The WDEF virus can spread from a TOPS server to a TOPS client if a
server to other Macs on the network, however.
it exists. It does not appear that the virus can spread from an AppleShare
on server root directories. We also recommend deleting the Desktop file if
reason, administrators should never grant the “make changes” privilege
performance on the network will be very severely degraded. For this
the Desktop file on the server. If a server Desktop file becomes infected,
directory on the server, then any infected user of the server can infect
administrator has granted the “make changes” privilege to the root
file, many servers have an unused copy of this file. If the AppleShare
Even though AppleShare servers do not use the normal Finder Desktop
Desktop file on the disk, and eliminate the virus.
Command and Option keys held down, and click OK. This will rebuild the
infected by WDEF, just eject the disk, unlock it, insert it again with the
For example, if the Disinfectant INIT warns you that a floppy disk is
Desktop file than it is to use Disinfectant.
It is often easier to get rid of a WDEF infection by simply rebuilding the
the alert.
Option keys while inserting the disk into a drive. Click on the OK button in
To rebuild the Desktop file on a floppy disk, hold down the Command and
button.
asking if you really want to rebuild the Desktop file. Click on the OK
throughout the startup process. You should be presented with an alert
MultiFinder), and keep both the Command and Option keys held down
To rebuild the Desktop file on a hard disk, start up using Finder (not
file.
You can remove a WDEF infection from a disk by rebuilding the Desktop
proper functioning of your Macintosh.
the errors in the virus can cause almost any kind of problem with the
style. Many other symptoms have also been reported and it appears that
styles. In particular, it often causes problems with the “outline” font
disks. The virus also causes problems with the proper display of font
other Macs to crash much more frequently than usual and it can damage
immediately after insertion of an infected floppy. The virus also causes
virus causes both the Mac IIci and the portable to crash almost
contains errors which can cause very serious problems. In particular, the
Although the virus does not intentionally try to do any damage, WDEF
whereas WDEF A does not beep.
difference is that WDEF B beeps every time it infects a new Desktop file,
The WDEF A and WDEF B strains are very similar. The only significant
application for the virus to spread.
WDEF spreads from disk to disk very rapidly. It is not necessary to run an
disks, usually floppy disks.
sharing of applications, but rather through the sharing and distribution of
other system files. Unlike the other viruses, it is not spread through the
one of these files. WDEF does not infect applications, document files, or
few exceptions, every Macintosh disk (hard drives and floppies) contains
WDEF only infects the invisible “Desktop” files used by the Finder. With a
and “WDEF B.”
is very widespread. We know of two strains, which we call “WDEF A”
has also been reported at many other locations, and we now know that it
one of our labs at Northwestern University. Since the initial discovery, it
The WDEF virus was first discovered in December, 1989 in Belgium and in
xThe WDEF Virus
ˇˇ