T4-A Virus (25-July-1992) Entry...............: T4-A Virus Alias(es)...........: --- Virus Strain........: T4 Virus Strain Virus detected when.: June 1992 where.: Several FTP sites around the world Classification......: Link virus, applications only; stealth (attempt) Length of Virus.....: Resource fork extension 5610 bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All systems including System 7 Computer model(s)...: All Mac models --------------------- Attributes ------------------------------------- Easy Identification.: STR ID 32767 Resource. Near the end of one of the CODE resources, the string "Disinfectant" can be found. Moreover, strings "Application is infected" and "with the T4 virus" can be found in that resource. Resource pattern....: Extending an existing CODE resource by 5610 Bytes Type of infection...: Patching the first InitDialogs (or TEInit if no InitDialogs is found) to a call to a BSR to virus code and adding the virus at the end of that resource. Infection trigger...: Executing an infected file infects one other file. The virus uses a recursive search to find the next uninfected file starting on the desktop of volume 0. A file is only infected if the size of the resource to become infected is less than 32767-5610 bytes. Applications affected:All applications that use InitDialogs or TEInit. Traps intercepted...: None Damage..............: Permanent damage: 1. Infected files may not be restored to their original state because of different patches for InitDialogs and TEInit. 2. The virus disables all INITs and cdevs on all next boots by patching INIT 31 to a RTS (System 6.xx) and boot 2 (System 7.x). 3. Patching boot 2 on a System 7.01 (Quadra, Powerbook) may cause the computer to hang because boot 2 has been changed. Transient damage: 1. The virus displays the message "Application is infected with the T4 virus" and displays some biological virus icon. Damage Trigger......: Running an infected application. Trigger for message and icon: if the infected program infected 10 other applications. Peculiarities.......: In some attempt to undergo detection (stealth), the virus tries to fool the user by renaming an application to "Disinfectant" during infection; if Disinfectant is present, it will be renamed to "Dis". If SAM Intercept or another monitoring program is installed, this will cause messages that "Disinfectant" wants to modify boot 2 (System 7) or INIT 31 (System 6.xx) and to modify a program which the virus tries to infect. Similarities........: T4-B variant; a predecessor (not widely distri- buted), some kind of trojan, performed its infectuous task only after user allowance (displaying some display box where the user could acknowledge virus' action) --------------------- Agents ----------------------------------------- Countermeasures/direct: Restoring the original boot 2 (System 7.x) or INIT 31 resources in System with ResEdit. Repairing applications may not be possible (see above). Countermeasures/software:Use a commercial anti-viral product or a public domain utility such as Virus Detective or Disinfectant >= 2.9 to carry out virus signature scans. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 13-July-1992 .