[comp.virus] New Virus turns up at U. of Pa!

GREVE@wharton.upenn.edu (Michael Greve) (02/22/90)

      I think a new MAC virus has turned up here at Penn.  A
co-worker/student gave me a disk with some papers he wanted laser
printed.  When I put the disk into my machine Gatekeeper Aid remove a
WDEF A virus then I got a message saying "GateKeeper found an "Implied
Loader 'INIT'" virus, it has been removed".  I'm glad Gatekeeper Aid
caught it!  I think mention was made of this virus a week ago.  Is
this a new virus??  What does it do??  Is it spread like WDEF A??  I'm
using Gatekeeper Aid 1.0.1.  Will/Can Disinfectant 1.6 catch this
virus.  All these questions....

					Michael Greve
					Univ. of Pa.
					Wharton Computing
					greve@wharton.upenn.edu

dplatt@coherent.com (02/23/90)

>       I think a new MAC virus has turned up here at Penn.  A
> co-worker/student gave me a disk with some papers he wanted laser
> printed.  When I put the disk into my machine Gatekeeper Aid remove a
> WDEF A virus then I got a message saying "GateKeeper found an "Implied
> Loader 'INIT'" virus, it has been removed".  I'm glad Gatekeeper Aid
> caught it!  I think mention was made of this virus a week ago.  Is
> this a new virus??  What does it do??  Is it spread like WDEF A??  I'm
> using Gatekeeper Aid 1.0.1.  Will/Can Disinfectant 1.6 catch this
> virus.  All these questions....

1) This sounds as if you are infected with the "INIT 29" virus.

2) No, it's not new;  it has been around since late 1988.

3) It spreads via system files and applications.  It also infects documents,
   but the infected documents are not infectious.  It tends to cause
   problems when printing, and may also cause system crashes.  It will
   infect _any_ file which has a resource fork.

4) Disinfectant will detect it, remove it from infected files, and
   repair infected applications (subject to the usual warning that the
   repairs cannot be guaranteed to be 100% correct in all cases).

5) Gatekeeper and Vaccine will prevent it from spreading.  If you use
   Vaccine, do NOT check the "Always compile MPW INITs" button... some
   viruses can sneak past Vaccine's protection if this feature is
   enabled (I don't remember whether INIT29 is one of those which can...)

You should use Disinfectant to scan and disinfect all of your disks,
and then install Gatekeeper or Vaccine.

- --
Dave Platt                                             VOICE: (415) 493-8805
  UUCP: ...!{ames,apple,uunet}!coherent!dplatt   DOMAIN: dplatt@coherent.com
  INTERNET:       coherent!dplatt@ames.arpa,  ...@uunet.uu.net
  USNAIL: Coherent Thought Inc.  3350 West Bayshore #205  Palo Alto CA 94303