VIRUS NAME: Unix/Zerto
Virus Characteristics
The Unix/Zerto virus was included inside a virus collector set that was sent to AVERT. The viral code has not been encountered "in the wild".
The virus code is written in a Bourne (sh) shell script. It looks for target files to infect that are flagged as executable (x).
The viral script code prepends to executable files, which may be both for example a shell script or ELF binary files.
Symptoms
Infected files that are flagged as executable (x) may have the viral shell script code prepended to the original code of the file.
Method Of Infection
Running an infected Bourne shell script starts the infection.
|