[comp.virus] Possible New Infection

C0195@UNIVSCVM.BITNET (Gregory E. Gilbert) (01/12/90)

I saw this posted in Vol. 8, Number 6 of the INFO-MAC Digest.  THought is was
worthy of a cross posting.

Date: Tue, 9 Jan 90 15:22 EST
From: FRIEDMAN@anchor.rutgers.edu
Subject: Trojan Horse???? A new one

I recently saw a posting about two new sharewares, JCremote and Mac II
Diagnostic Sound.  After unBinHexing and Unstuffing them, I did what most of
would, I checked for viruses using SAM Virus Clinic 1.3.  No known viruses were
detected.  I tried the Mac II Diagnostic Sound and then installed JCremote.  As
I installed JCremote into my system folder SAM 1.3 warned me about attempts to
modify the system file, however, this is not uncommon with a CDEV or RDEV.
After installing it, I opened the chooser and selected JCremote.  The system
froze.  When I rebooted the computer the computer started to launch, but the
crashed.  There was no bomb or any message, just a blank screen.  After
rebooting with a floppy and checking with Disinfectant 1.5, the system file was
noted as having a damaged resource fork.  This meant I had to install a new one
.

I am not sure which of the two mentioned files are the culprit.  The first time
it happened I heard a sound which sounded like one of the Mac II Diagnostic
Sound sounds and the freeze occurred when I tried running JCremote.

Rich
Friedman@biovax

Greg

Postal address: Gregory E. Gilbert
                Computer Services Division
                University of South Carolina
                Columbia, South Carolina   USA   29208
                (803) 777-6015
Acknowledge-To: <C0195@UNIVSCVM>