VIRUS NAME: Unix/Zerto
Virus
Characteristics
The Unix/Zerto virus
was included inside a virus collector set that was sent to AVERT. The
viral code has not been encountered "in the wild".
The virus code is written in a Bourne (sh) shell script. It looks for
target files to infect that are flagged as executable (x).
The viral script code prepends to executable files, which may be both
for example a shell script or ELF binary files.
Symptoms
Infected files that are flagged as executable (x) may have the viral shell
script code prepended to the original code of the file.
Method
Of Infection
Running an infected Bourne shell script starts the infection.
|