Computing Services Office   Microcomputer Virology
Microcomputer Virology
 
 
(Mark and Dave's Excellent Virus Course)
 
I. Definitions
 
1. Bug/User error/Hardware failure
-warrants more concern than viruses
general term for all kinds of problems
Bug: an error in the design or implementation of a program that 
causes it to do something that neither the user nor the program 
author had intended to be done (White/Chess/Kuo- Coping with 
Computer Viruses and Related Problems)
 
2. Harmful or malicious code
Software intended to cause problems, that is, any software that plays 
pranks, deletes files, etc.
 
3. Virus: there are many definitions:
 
MZ:
code that is: 
dependant on a host program to run, and
replicates itself
 
Fridrik Skulason
A program that modifies other programs by placing a copy of itself 
inside them.
 
Dr. Fred Cohen:
a program that can infect other programs by modifying them to 
include a possibly evolved copy of itself.  
 
John McAfee:
Programs (or code segments) that are:
Self replicating and require a host or executable disk segment
That move from machine to machine
Through transfer of diskettes
Program sharing
Data sharing
Through electronic communications
Networks
Bulletin boards
Other communications
and may or may not be harmful
Humorous
Innocuous
Catastrophic
 
Stanley A. Kurzban
Code that plants a (possibly changed) copy of itself in any program it 
can modify (and may do something else, for example, a logic bomb).
 
Eugene H. Spafford
Characterized by lack of ability to run independently or spread 
themselves to other machines.
 
4. Trojan Horse
Harmful code concealed within another program
Example: mainframe game program containing hidden code 
implementing privileged functions; written by someone without 
access to those functions as a means of bypassing security. When a 
user with privileged access runs the game, the code is run, 
unbeknownst to that user.
 
5. Logic Bomb
Harmful code which is triggered by some specified condition or 
event.
Example: corporate payroll system that stops working when a 
particular programmer is dropped from the payroll
 
6. Worm
A program that reproduces over a network without requiring a host.
A worm is a program that plants copies of itself in remote, 
electronically connected nodes. (Shoch, Hupp)
Example: the Internet Worm
 
7. Trap door/Hole
A security gap left in a program by its creator allowing that person 
special privileges within the program. This is known as a Hole when 
the gap was left unintentionally.
Example: Unix sendmail debug option (one of the security holes taken 
advantage of by the Internet Worm)
 
8. Bacteria
A program which reproduces without bounds
Known as a rabbit by White/Chess/Kuo
 
9. Mutation/Evolution
Code such as a virus that is modified after the initial release
 
10. Trusted code
Code that is known to be free of harmful or malicious code
Note: This does not automatically include commercial software- 
viruses have been found in shrink-wrapped software from major 
vendors!
 
II. Safe Computing
 
1. Backup
Most versatile safeguard; protects against hardware, software, and 
user failures/errors.
 
2. OS security & security add-ons
write-protect disks
original software on CD-ROMs, laptops with DOS in ROM are better
setting file permissions, e.g. read-only, execute-only
file encryption - protects against unauthorized modification or 
reading
 
3. Boot & execute only trusted software
Immediately write-protect all new software. When you pop it out of 
the box, write-protect it!  Then back it up, and only use the originals 
when your backups fail or are infected.
 
4. Education -understand your system
its important to be familiar with how your system normally 
functions and apply Sherlock-Holmesian observation to deviations 
from normal behaviour.
i.e., if your floppy drive starts spinning when you should only be 
accessing the hard drive, somethings not right! (Dave and Marks 
Excellent Virus Course)
 
a. How a PC works in a nutshell
Everything connects to the CPU
All software is loaded into the CPU for execution through ROM and 
RAM
Memory Map/Boot process
CPU is reset; executes code in the ROM chip
Does basic system diagnostics
memory tests
identifies present hardware
Sets up interrupt vector table in RAM
Sets up ROM BIOS table in RAM
Loads DOS into memory
IBMBIO/IBMDOS = Kernel
Command.com - command interpreter
Terminate and stay-resident routines (TSRs) are installed and 
operate by hooking interrupt vectors
2 common vectors:
keyboard
clock
many PC viruses are TSRs that hook the disk I/O interrupt
Diskettes
there is no such thing as a blank formatted diskette (a boot sector is 
a program)
 
b. How a Mac works in a nutshell
The Mac uses very similar hardware to the PC, but has another layer 
of software on top, creating the windowing environment known as 
the Macintosh interface.
Mac programs are modular
They are broken up into parts that are easily modified
 
The Toolbox
this is a collection of routines that make the mac special; they 
provide a consistent method of programming on the Mac.  Most of 
the toolbox routines are stored in ROM, updates and fixes to the ROM 
routines are loaded as part of the system software.
 
Files and Resources
Macintosh files have two main parts:
Data fork
stores data
Resource fork
stores program code, fonts, cursors, sounds, desk accessories, menu 
definitions, and many other things
Programs on the Macintosh have parts broken up into resources; this 
makes it easier to program for the windowing environment, and 
much easier to customize without recompiling the entire application.
Files also have a type and a creator- this is used by the finder to 
assign the appropriate icon to a file
common resource types:
ALRT	Alert template
BNDL	Bundle (associates files and their icons for the Finder)
CDEF	Control definition function
CNTL	Control template
CODE	Application code segment
CURS	Cursor
DITL	Item list in a dialog or alert
DLOG	Dialog template
DRVR	Desk accessory or other device driver
DSAT	System error alert table
FKEY	Command-Shift-number routine
FOND	Font family
FONT	Font
and a whole bunch more, through...
WDEF	Window definition function
Normal in any resource fork EXCEPT the desktop files
WIND	Window template
 
INITs and cdev's
these are initialization resources that are used during system startup.  
INIT resources are loaded into the system heap immediately after 
patch resources.  A special initialization resource in the System file 
searches the system folder of the startup volume for files of type 
INIT or RDEV.  When it finds such a file, it opens the file, gets all 
resources in that file of type INIT, and executes them.
 
The Desktop file
when the Finder first encounters an application, it normally copies 
the applications version data, bundle, icon lists, and file references 
from the applications resource file into the invisible Desktop file...
the desktop file ordinarily retains information for every application 
that has ever been on a disk.
 
Mac programs are event-driven (as are all windowing environments)
i.e., they are controlled by the users actions
The Event Loop
Main Program loop of a typical Mac program
repeat continuously:
		GetNextEvent
			Deal with the event
Types of events:
mouse:		mouseUp
keyboard:		keyDown, keyUP
disk-insertion
Window:		activate, deactivate, update
Null:			i.e., nothing happened
 
Event queue
events are detected and recorded by an interrupt mechanism, which 
records the events and places them in a queue, waiting to be 
processed
 
VBL (vertical blanking interrupt)tasks
The Mac updates the contents of the video screen 60 times a second; 
each time, after painting the screen, there is a short delay while the 
electron beam returns to the top of the screen; each time this 
happens, the video circuitry sends a vertical retrace interrupt 
message to the processor.
The VBL delay is used to perform system housekeeping chores, 
such as checking for mouse movement, updating the cursor position, 
incrementing the system clock, and posting disk-insertion events.  
These are performed out of sequence with the normal event loop, 
that is, every 1/60 of a second, the Mac stops working on the current 
program, and performs these specific tasks.  Other programs can 
install tasks to be performed during the VBL delay; some viruses do 
this.
 
III. Anti-virus safe computing (Protect yourself specifically from 
harmful code)
 
1. Education -information on existing threats
Know enough about existing viruses that you:
Recognize their symptoms
Know the appropriate precautions and countermeasures
Distinguish virus problems from ordinary bugs
How to find out the latest info: the Virus-L mailing list
on VMD:
Tell Listserve at Lehiibm1.Bitnet
on Unix:
Mail to:  listserve@ib1.cc.lehigh.edu
First line of message should be: 
sub Virus-L  <<your name here>>
 
2. Tests -screen (or scan) to detect known harmful code
Advantages:
Simpler
Faster
Interfere less with normal operations
May have some ability to repair damage due to harmful code
Disadvantages:
Require frequent updating
Re-infection
Since viruses tend to infect large numbers of disks during an 
outbreak, new outbreaks tend to occur as these disks turn up.
Moral: Test every disk you put into your system!
 
3. File test & file change detectors
Checksums & cyclical redundancy checks (CRCs)
viruses can infect files without changing their checksums or CRC
A useful method for detecting file changes
 
4. System monitors or system modifications
Advantages:
Useful against unknown or future viruses
May be able to prevent damage
Disadvantages:
Complex
Slows system performance
Interferes with normal operations (false alarms)
 
IV. Introduction to Known Virus Examples
 
1. Unix
Internet Worm
 
2. VM
Christmas EXEC
 
3. PC
Boot sector infectors
Pakistani Brain
Stoned
Ping Pong
Jerusalem
Lehigh Command.com
Notroj.com- a program which appears to be a useful anti-trojan 
utility.  It is actually a logic bomb that erases any hard drive that it 
can find, and warns, another program is attempting a format, cant 
abort!  It is triggered when it finds a hard drive over 50% full when 
it is run.
etc., etc., etc.... there are currently over 213 known PC viruses!  There 
are several lists of current viruses:
virlist.txt in scanv67b.zip
The Dirty Dozen list:  dirtyd9c.zip
virussum.doc in vsum9010.zip
bootvir.txt
filvir-1.txt, filvir2.txt
fprot113.zip
 
4. Mac
 
MacMag
First appeared: December 1987
Also known as: Peace, Drew, Brandow, and Aldus
Infects: System file
Originally spread via a HyperCard stack called New Apple Products- 
when the stack was run, it spread to the currently active system file, 
after which it spread to the system files on any disks inserted into 
the system.
Action:  MacMag was designed to display a message calling for world 
peace on March 2, 1988 (the anniversary of the introduction of the 
Mac II).  After this, it deleted itself.
 
Scores
First appeared: Spring 1988
Also known as: Eric, Vult, NASA, and San Jose Flu
Infects:System, Note Pad, Scrapbook files, and applications
Creates two invisible files named Scores and Desktop in the 
system folder of an infected system
Alters the Note Pad File and Scrapbook File in the system folder so 
that they appear with generic document icons
Two days after a system file becomes infected, Scores begins to 
spread to each application that is run.
 
nVIR
First appeared:  early 1987
Has two basic strains, nVIR A and nVIR B, as well as many clones.
Infects: System file, applications
Spreads to applications immediately once the system file is infected
Counts down from 1000 to 0, decrementing 1 for each time the 
system is restarted, 2 for each time an infected application is run.  
When the counter reaches 0, nVIR A will beep, or if MacinTalk is 
installed, it will say Dont Panic   nVIR B will beep (it does not use 
MacinTalk)
 
ANTI
First appeared:  early 1989
Infects: applications
Often damages applications in a way that Disinfectant and other anti-
virus utilities cannot repair
 
INIT 29
First appeared:  late 1988
Infects: System file, applications, and documents
(can only spread via system files and applications)
INIT 29 has one side effect which reveals its presence. If you try to 
insert a locked floppy disk on a system infected by INIT 29, you will 
get the following alert:
 
      The disk xxxxx needs minor repairs.
      Do you want to repair it?
 
If you see this alert whenever you insert a locked floppy, it is a good 
indication that your system is infected by INIT 29.
 
WDEF
First appeared:  December, 1989
Has two strains, WDEF A and WDEF B
Infects: Desktop file
Spreads through disk sharing, rather than application sharing
Note: WDEF stands for Window DEFinition procedure- it is a 
legitimate Macintosh resource in most cases.  The finder will look for 
alternate procedures in files such as the desktop file, and use them 
instead of the normal ones if available.  This is how the WDEF virus 
spread.
The easiest way to get rid of the WDEF virus is to perform a 
procedure known as rebuilding the desktop file.  To do this on your 
hard drive, simply reboot with the command and option keys held 
down. A dialog box will appear asking you if you wish to rebuild the 
desktop file; click on OK to proceed.  To rebuild the desktop file on a 
floppy disk, simply hold down the command and option keys while 
inserting the floppy.  One drawback to this procedure is that 
rebuilding the desktop file wipes out any comments stored in the 
comments box in the get Info window on any particular file.
 
ZUC
First appeared: March, 1990
Infects: applications
Timed to activate two weeks after an application is first infected; at 
this point it causes erratic cursor behavior
 
MDEF
First appeared: May, 1990
Has two strains, MDEF A, also known as Garfield, and MDEF B, also 
known as Top Cat
Infects: System file, applications
Note: MDEF B totally bypasses Vaccine,  MDEF A damages the system 
file causing menus to stop functioning on systems protected by 
Vaccine. 
 
CDEF
First appeared: August, 1990
Infects: Desktop files
Similar to WDEF, but is a completely different virus
 
V. Specific Antivirus software products
 
1. PC
a. Test- FILETEST
Author: Dr. Leonard Levine
Simple freeware CRC checker
Uses DOS, so it can be fooled by active viruses
(boot from a trusted disk to run)
FILETEST.ZIP on ux1
 
b. Scan- ViruScan
Author: John McAfee
Shareware scanner- part of the VIRUSCAN package (includes the 
VSHIELD monitor and other useful utilities
Site licensed at UIUC by CSO
scanv66b.zip on ux1
 
c. System monitor- Flushot+
Shareware system monitor by author of commercial anti-virus 
package Virex-PC
fsp_17.fsp
 
d. FPROT
Author: Fridrik Skulason (Iceland)
Shareware anti-virus package- very comprehensive.
fprot113.zip on CSOs ux1 mainframe
 
e. VIRSCAN
Simple string scanner from IBM
Available in the MRC
 
2. Mac
 
a. Vaccine
A freeware INIT/cdev that scans the system for virus-like activity
Now out of date- Disinfectant INIT or GateKeeper work better
 
b. Disinfectant
A freeware utility that scans for known viruses and repairs damage 
done by most
Includes a virus-scanning INIT which scans for known viruses
Includes a very complete online help manual which describes all 
currently known Mac viruses and ways to prevent and deal with 
infection.
 
c. Gate Keeper
A freeware INIT/cdev that scans for known viruses and monitors for 
virus-like activity
 
d. GateKeeper Aid
A freeware INIT that specifically scans for WDEF and similar viruses
 
e. SAM
A commercial application similar to Disinfectant
Scans for known viruses and repairs damage done by most
Includes a virus-scanning INIT/cdev that scans floppies and files for 
known viruses and monitors the system for virus-like activity
Virus Clinic (the application) includes a feature that allows one to 
enter in information about new viruses that enables Virus Clinic and 
SAM Intercept to scan for them
 
f. Virex
A commercial application similar to Disinfectant
Scans for known viruses and repairs damage done by most
Includes a virus-scanning INIT/cdev that scans floppies and files for 
known viruses
Note: all of the freeware anti-virus utilities are available in the MRC, 
and on ux1 in the /pub/mac/virus directory.
 
VI. Disinfection hints
 
1. PC
Cold boot from known clean, write-protected boot floppy, and run 
disinfection software.
(cold boot: power the machine off, wait 15 seconds, power on)
 
2. Mac
Close all windows, shut down system.  Boot from known clean write-
protected floppy, and run disinfection software.
 
