Content

MacOS/NVP

Type
Trojan
SubType
Macintosh
Discovery Date
12/01/1994
Length
584 bytes
Minimum DAT
N/A (06/30/2004)
Updated DAT
4371 (06/30/2004)
Minimum Engine
N/A
Description Added
11/29/2002
Description Modified
11/29/2002 11:38 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This threat works only on Macintosh computers.

This trojan disguises itself as "New Look" application for modifying the Mac display. This program has "Nvw2" creator (and APPL type). The malicious code is in INIT 5 and PTCH 128 resources of the trojan. If the trojan is run it modifies the System file and copies INIT 5 code into it. The active System file is modified to prevent the letters "a, e, i, o, u" from being entered from the keyboard.

The effect of the trojan can only be seen after restarting the system. Under System 7 mentioned characters cannot be entered any more. Under System 6, the patching takes place, but typing is not affected.

Symptoms

Keys "a, e, i, o, u" do not work.

Method of Infection

Removal

Please use the latest updates of Virex for cleaning. If this threat is detected on a Macintosh please use Virex to repair it.

If the infected object was found on a non-Apple file server it can be cleaned using Virex from a Macintosh client.

Infected Emails (usually in BinHex format) will be currently either deleted or quarantined depending on the configuration of mail scanner. Quarantined mails should be transferred to a Macintosh and cleaned using Virex.

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Aliases

  • NoVowelsPrank

Characteristics

Characteristics -

This threat works only on Macintosh computers.

This trojan disguises itself as "New Look" application for modifying the Mac display. This program has "Nvw2" creator (and APPL type). The malicious code is in INIT 5 and PTCH 128 resources of the trojan. If the trojan is run it modifies the System file and copies INIT 5 code into it. The active System file is modified to prevent the letters "a, e, i, o, u" from being entered from the keyboard.

The effect of the trojan can only be seen after restarting the system. Under System 7 mentioned characters cannot be entered any more. Under System 6, the patching takes place, but typing is not affected.

Symptoms

Symptoms -

Keys "a, e, i, o, u" do not work.

Method of Infection

Method of Infection -

Removal -

Removal -

Please use the latest updates of Virex for cleaning. If this threat is detected on a Macintosh please use Virex to repair it.

If the infected object was found on a non-Apple file server it can be cleaned using Virex from a Macintosh client.

Infected Emails (usually in BinHex format) will be currently either deleted or quarantined depending on the configuration of mail scanner. Quarantined mails should be transferred to a Macintosh and cleaned using Virex.

Variants

Variants -

    N/A