[comp.sys.mac] Virus attack? Help PLEASE!

weevil@nmtsun.nmt.edu (Jeff Eliasen) (05/07/89)

Well, it finally happened:  I got hit by a virus (I think) and have no
idea where to start in replacing everything.

First the symptoms:

I've been downloading a lot of PD stuff off of a nearby board (I think
that habit will stop soon).
After this one d/l session, I decided to copy everything on my internal
20 meg to a friend's external 60.  I had GateKeeper (whatever the last
version posted on comp.binaries.mac was) running in the background, but
I was still unfamilliar with using it and could not give Finder write
access, so to save time in copying the 500+ files I hit the override
switch.  When I dragged the icon for the one drive over to the other,
there was a noticable delay (10 seconds(?) or so) where neither hard drive
was accessed (this was before the status window came on-screen).  Then
everything started up and worked fine.
Then, yesterday, I tried to boot up but the machine booted off the wrong
hard drive (the external).  When Finder did show up, it showed both drives
being there with the correct System versions and everything in the right
place.  It just didn't boot off the internal.  I chose "Startup Device"
from the control panel and tried again, but the same thing happened.  Then
I booted off a (locked) floppy with the same results.  I replaced System and
Finder on the drive in question, and that time it booted fine.  I went to
the control panel, selected "GateKeeper" (I don't remember why), and every-
thing froze completely.  I re-booted and it gave me a message saying the
hard drive was damaged (soft-damage) and would I like to initialize it.
Not wanting to lose everything, I selected 'No', so when the desktop came
up the drive was non-existant.  I booted again, selected 'Yes' to the
initialization question, and lost everything.

I guess my main question is this:  Is this a virus anyone recognizes?  If
not, what else may it have been?

Now for the removal:

My dad is sending me a program called Nomad.  Is it good for this sort of
thing?  What software should I use to find and remove any/all occurences
of the virus?

Thanks a lot for your help and suggestions.  If anyone is interested,
I'll post a summary in a week (Friday the 12th).  Don't bother responding
after then, as I'll be gone forever (transfering).

Thanks again!

- Jeffrey Eliasen
- NewCo MexiTech

ins_apw@jhunix.HCF.JHU.EDU (Philip Wong) (05/08/89)

I've found disinfectant to be the best program for checking out virus'.  Interferon has the nice feature of searching for anomaly's (sp).  Whatever your virus
was, it doesn't sound like scores...but that's all i can tell you.  disinfectant is availiable on assorted mac ftp sites.