It is extremely difficult to remove this virus manually without damaging an application. It is STRONGLY recommended that a program such as Disinfectant be used!
The virus starts with the following hex sequence:
xxxx xxxx contains the saved values for the instruction words that have been patched by the virus.
To repair an application:
Open the CODE ID=0 resource. Write down the word at position 16 (first word of the third line if opened with ResEdit). This is the position within the CODE ID=1 resource
you have to look for the patch, and is usually 0000. Search in the CODE ID=1 resource for the hex sequence above. Write down the value noted as ‘xxxx xxxx’. Find the location of the patch, with the value you found in CODE resource ID=0. The first word of the patch should be 4EBA. Replace the patch by the two words noted before as ‘xxxx xxxx’. Remove the whole virus code (everything from the virus start to the end of the resource).