[comp.virus] Weird Mac Behaviour...

MWILSON@STSCI.BITNET (Michael) (08/30/90)

Hello,

  I think that my Mac IIcx was infected with a new virus.  I have SAM
II, Gatekeeper and Gatekeeper Aid running all the time.  I was
installing some software that I purchased from MacFriends onto my
computer.  There were about 10 fonts from Adobe and 10 from Bitstream
and ColorStudio from Letraset.

The system was fine before the software installation began.  I might
add that MacFriends had sent the Adobe fonts on their own labeled
disks (? very strange) I'll have to ask them about that later.  I had
a recent backup so I was not too worried once the 'weird' stuff began.

After I installed ColorStudio I tried to boot it up, but it asked me
for the Settings file and then crashed.  I rebooted and noticed that
the SunDesk icon was now upside down!!!  I checked the ColorStudio
program disks for the settings file, but it wasn't there -- by the way
I did purchase the program and it was fresh out of the shrinkwrap.  I
then tried to open the Control Panel and it told me that the system
was missing some system resources.  After opening up the system folder
I tried moving some inits because I thought I was having init
conflicts -- the inits couldn't be moved.  The system said file
busy/in use.  I was pissed!!!  I booted again from a floppy and tried
to move the files and I got the same message.  I then rebooted the mac
from the hard drive and got a message stating that the finder was
damaged and I should use the Installer to correct it.  I did and
rebooted.

This time the SunDesk Icon was upsidedown and small, with some other
trash.  The mac hung and I rebooted -- the system then started up and
only loaded four of my 15 inits and Cdev's!!  Realizing that something
was very wrong I tried to move the SunDesk icon and couldn't do it.  I
tried to delete the file and it seemed to be ok this time.  I closed
up the system folder and then opened it a few minutes later.  The
deleted files were back!!

I ran SumII on the disk and many files were listed as having their
checksum as changed.  I didn't want to infect anymore disks so I
initialized the disk and restored it.  That's where I am now.  I put
the fonts back on because I desperately need them, but ColorStudio is
off and I don't know what to make of my problems!!

HELP....HELP....HELP  has anyone seen anything like this before???

Please respond to me even if you want to take a guess......

Michael I. Wilson          MWILSON@STSCI.bitnet

Thanks in advance for your help!!