====== Computer Virus Catalog 1.2: "ANTI A" Virus (17-Dec-1991) ====== Entry...............: "ANTI A" Virus Alias(es)...........: --- Virus Strain........: ANTI Virus Strain Virus detected when.: --- where.: USA Classification......: Link virus Length of Virus.....: 1348 Bytes + 1 Jump table entry --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: all versions Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: The strings "ANTI" and "#000001" can be found in CODE 1 resource Resource pattern....: CODE 1 is increased by 1348 bytes Type of infection...: Extending CODE 1 and modifying CODE 0 Infection trigger...: Running an infected application to get in memory. Use of OpenResFile Applications affected:All those having a CODE 0 and 1 resource with size of old CODE 1 + virus <= 32768 bytes. Traps intercepted...: OpenResFile, MountVol Damage..............: If MountVol is called for a disk drive, this virus searches the first sector of track 16 for the string $16+"%%S" at offset 8 from begin of sector (works only on 400K and 800K floppies); if this string is found, virus executes the code in that sector via JSR call. (No such code has been discovered until classification date) Damage Trigger......: Invocation of MountVol Peculiarities.......: Detects files infected with ANTI B and modifies them to become ANTI Variant Similarities........: ANTI B, ANTI Variant --------------------- Agents ----------------------------------------- Countermeasures/direct: Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 17-December-1991 Information Source..: --- ===================== End of "ANTI A" Virus ========================== ======= Computer Virus Catalog 1.2: "ANTI B" Virus (17-Dec-1991) ===== Entry...............: "ANTI B" Virus Alias(es)...........: --- Virus Strain........: ANTI Virus Strain Virus detected when.: --- where.: USA Classification......: Link virus Length of Virus.....: 1144 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: all versions Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: The strings "ANTI" and "#000001" can be found in the CODE 1 resource Resource pattern....: CODE 1 is increased by 1144 bytes Type of infection...: Extending CODE 1 and modifying CODE 0 Infection trigger...: Running an infected application to get in memory. Use of OpenResFile. Applications affected:All those having a CODE 0 and 1 resource with size of old CODE 1 + virus <= 32768 bytes. Traps intercepted...: OpenResFile, MountVol Damage..............: If MountVol is called for a disk drive, this virus searches the first sector of track 16 for the string $16+"%%S" at offset 8 from begin of sector (works only on 400K and 800K floppies); if this string is found, virus executes the code in that sector via JSR call. (No such code has been discovered until classification date) Damage Trigger......: Invocation of MountVol Peculiarities.......: --- Similarities........: ANTI A, ANTI Variant --------------------- Agents ----------------------------------------- Countermeasures/direct: Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 17-December-1991 Information Source..: --- ===================== End of "ANTI B" Virus ========================== === Computer Virus Catalog 1.2: "ANTI Variant" Virus (17-Dec-1991) === Entry...............: "ANTI Variant" Virus Alias(es)...........: --- Virus Strain........: ANTI Virus Strain Virus detected when.: --- where.: USA Classification......: Link virus Length of Virus.....: 1348 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: all versions Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: The strings "ANTI" and "#000001" can be found in CODE 1 resource Resource pattern....: CODE 1 is increased by 1348 bytes Type of infection...: Extending CODE 1 and modifying CODE 0 Infection trigger...: Running an infected application to get in memory. Use of OpenResFile. Applications affected:All those having a CODE 0 and 1 resources with size of old CODE 1 + virus <= 32768 bytes. Traps intercepted...: OpenResFile, MountVol Damage..............: Due to a programming error, the computer will hang if an infected application is executed. If MountVol is called for a disk drive, the virus searches the first sector of track 16 for the string $16+"%%S" at offset 8 from begin of sector (works only on 400K and 800K floppies); if this string is found, virus executes the code in that sector via JSR call. (No such code has been discovered until classification date) Damage Trigger......: Execution of an infected application Peculiarities.......: --- Similarities........: ANTI A, ANTI B --------------------- Agents ----------------------------------------- Countermeasures/direct: Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 17-December-1991 Information Source..: --- ===================== End of "ANTI Variant" Virus ==================== ====== Computer Virus Catalog 1.2: "MacMag" Trojan (17-Dec-1991) ===== Entry...............: "MacMag" Trojan Alias(es)...........: Peace Trojan Virus Strain........: MacMag Trojan/Virus Strain Virus detected when.: --- where.: USA Classification......: Trojan Horse containing virus Length of Trojan....: 1908 (DREW)+ 408 (XCMD) Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: all versions Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: The stack contains resources "XCMD" ID 95 and "DREW" ID. Resource pattern....: XCMD 95 "Effects", DREW 0 "Main" Type of infection...: Adding the DREW resource as an INIT with first unused ID beginning with 6 to System file Infection trigger...: Opening stack Applications affected:System file Traps intercepted...: none Damage..............: none Damage Trigger......: --- Peculiarities.......: --- Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct: Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 17-December-1991 Information Source..: --- ===================== End of "MacMag" Trojan ========================= ======= Computer Virus Catalog 1.2: "MacMag" Virus (17-Dec-1991) ===== Entry...............: "MacMag" Virus Alias(es)...........: Peace Virus Virus Strain........: MacMag Trojan/Virus Strain Virus detected when.: --- where.: USA Classification......: System file virus Length of Virus ....: 1908 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: all versions Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: INIT in System file named "DR" Resource pattern....: INIT with normally unused ID Type of infection...: Generated by MacMag trojan horse Infection trigger...: --- Applications affected:System file Traps intercepted...: none Damage..............: This virus displays a peace message on screen and shows an icon with America symbol. Damage Trigger......: Launching an infected system after March 2,1988 Peculiarities.......: The virus destroys itself after the damage. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct:Remove INIT from System file using ResEdit Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 17-December-1991 Information Source..: --- ===================== End of "MacMag" Virus ========================== ======= Computer Virus Catalog 1.2: "MDEF C" Virus (10-Aug-1991) ===== Entry...............: "MDEF C" Virus Alias(es)...........: --- Virus Strain........: MDEF Virus Strain Virus detected when.: May 1990 where.: New York, USA Classification......: Link virus Length of Virus.....: Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: (MDEF Resource with ID 6982 in System file) MDEF 0 Resource Resource pattern....: MDEF Resource ID 0 (and old MDEF 0 with ID 6982) Type of infection...: Adding (and renaming) an MDEF resource Infection trigger...: Executing an infected file. Applications affected:All + Documents used by current application Traps intercepted...: (only 128 and 256K ROMs) AddResource, ChangedResource Damage..............: Due to an error in this virus, an invocation of AddResource may crash the system because AddResource will point to ChangedResource which has a different number of arguments; garbage left on stack may cause problems. Damage Trigger......: Infecting one file Peculiarities.......: If SAM Intercept is present, it will allow changing the ID of MDEF 0 to 6982 but will prevent the addition of the MDEF 0 resource. This causes the system to hang if a menu item is activated. Similarities........: MDEF A,B viruses --------------------- Agents ----------------------------------------- Countermeasures/direct:1.System: Removal of MDEF resource ID 0 and changing the ID of MDEF 6982 back to 0 with ResEdit. 2. Applications and documents: Remove MDEF 0 resource. Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 10-August-1991 Information Source..: --- ===================== End of "MDEF C" Virus ========================== ======= Computer Virus Catalog 1.2: "MDEF D" Virus (10-Aug-1991) ===== Entry...............: "MDEF D" Virus Alias(es)...........: --- Virus Strain........: MDEF Virus Strain Virus detected when.: May 1990 where.: New York, USA Classification......: Link virus Length of Virus.....: Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------- Easy Identification.: MDEF Resource with ID 8375 Resource pattern....: MDEF Resource ID 8375 Type of infection...: Adding an MDEF resource and changing a MENU resource. Infection trigger...: Executing an infected file. This virus searches (via GetCatInfo) for the first file of type "APPL" that has no MDEF ID 8375 and infects it Applications affected:All of type "APPL" Traps intercepted...: none Damage..............: none Damage Trigger......: none Peculiarities.......: --- Similarities........: MDEF A,B,C viruses --------------------- Agents ----------------------------------------- Countermeasures/direct: Removal of MDEF resource ID 8375. Change 2 bytes at offset 6 in MENU 1 resource from $20B7 to 0. Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 10-August-1991 Information Source..: --- ===================== End of "MDEF D" Virus ========================== ======= Computer Virus Catalog 1.2: "Scores" Virus (17-Dec-1991) ===== Entry...............: "Scores" Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: --- where.: USA Classification......: System file virus Length of Virus ....: 7026 Bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: all versions Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: A visible Desktop file Resource pattern....: Application: Additional CODE Resource with highest ID+2 (S=System,D=Desktop,B=Scrapbook File V=Scores,N=Note Pad): INIT 6, 772 Bytes (S,N,B) INIT 10, 1020 Bytes (S,D,V) INIT 17, 480 Bytes (S,B) atpl 128, 2410 Bytes (S,D,V) DATA -4001, 7026 Bytes (S,D,V) Type of infection...: System and file infector (Link virus) Infection trigger...: Running an infected System or application two days after infection or later Applications affected:System file, All applications Traps intercepted...: --- Damage..............: Damage 1: after 25 minutes of use, applications of type VULT or ERIC are bombed with ID 12 Damage 2: after 15 minutes, a write attempt causes a bomb; after 25 minutes, an infected program will bomb anyway. Damage Trigger......: Only applications with resources of type VULT or ERIC: Damage 1: 4 days after infection Damage 2: 7 days after infection Peculiarities.......: INIT's used by virus are present in System versions 6.04-6.08 Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct: Countermeasures/software:Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 17-December-1991 Information Source..: --- ===================== End of "Scores" Virus ========================== ==== Computer Virus Catalog 1.2: "WDEF B" Virus (17-December-1991) === Entry...............: "WDEF B" Virus Alias(es)...........: --- Virus Strain........: WDEF Virus Strain Virus detected when.: March 1991 where.: Hannover,Germany Classification......: File infector only Desktop file Length of Virus.....: Resource fork extension: 1842 bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: System 4.1 or greater , not 7.0 Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------- Easy Identification.: Additional WDEF 0 resource in Desktop file; Desktop shouldn't have one. Resource pattern....: Desktop File: WDEF 0 1842 Bytes. Type of infection...: The virus copies itself to all Desktop files on all connected volumes. Infection trigger...: Executing an infected Desktop file and a random algorithm produces the value 1 long and the availability of SysEnvirons-Trap; the random value is calculated using the RandomSeed system variable. Applications affected:Only Desktop files Traps intercepted...: Only during infection: Write, AddResource, ChangedResouse, WriteResource, UpdateResFile Damage..............: Permanent damage: --- Transient damage: Only when running under MultiFinder. Only first launched application: if the application has a menu that displays font-size-information using the system, available font sizes are no longer displayed outlined; all sizes are displayed in normal style. Switching between applications doesnot change the first application's behavior. Damage Trigger......: Running an infected Desktop file. Peculiarities.......: No infection on systems without SysEnvirons. Virus beeps once if infected application is run. Similarities........: CDEF, WDEF A --------------------- Agents ----------------------------------------- Countermeasures/direct:1.Removal of WDEF 0 from all Desktop files: copy Desktop to another file and cut off WDEF 0 resource, delete original Desktop file and rename cleaned copy to Desktop. The desktop file is always active, so copying and renaming must be done by special file utilities like the file tools DA. 2.Or create a new Desktop file by pressing Option and Command key when opening a volume. (Can be very time-consuming on full harddisk, and information in the comment field of file information are lost) Countermeasures/software: 1.Use an anti-viral product (public domain or commercial) such Disinfectant, Interferon, Virus detective or VirusRx to scan for virus signature. 2.Use a protection INIT called Eradicat'Em that prevents WDEF infection (also prevents CDEF infection) --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 17-December-1991 Information Source..: --- ===================== End of "WDEF B" Virus ========================== ======= Computer Virus Catalog 1.2: CODE 252 Virus (25-July-1992) ==== Entry...............: CODE 252 Virus Alias(es)...........: D-Day Virus Virus Strain........: --- Virus detected when.: April 1992 where.: USA Classification......: Application and system file infector Length of Virus.....: Resource fork extension 1916 bytes (application), 1908 bytes (System file) --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All versions (including System 7) Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: 1. CODE 252 Resource 1908 Bytes in applications 2. INIT 34 Resource in System 3. The following strings can be found at offset Hex 3E0 from beginning of both resources: "Ha Ha Ha Ha Ha Ha Ha You have a virus. Now erasing all disks! P.S. Have a nice day (Click to continue!)" Resource pattern....: CODE ID 252 1908 Bytes; INIT ID 34 1908 Bytes Type of infection...: Applications infect the System by adding a INIT 34 Resource. System and Applications infect other applications by adding a CODE 252 Resource and patching the Jumptable to point at it. Infection trigger...: To infect system: Running an infected application. To infect application: Running it by using the Launch trap. Applications affected:System, all applications including the Finder. Traps intercepted...: Launch,AddResource,ChangedResource,WriteResource Damage..............: The Virus opens a window, displays some text (see Easy Identification) and then removes itself. Damage Trigger......: If the internal clock's date is between June 6th (D-Day) and December 31th (included), any year. Peculiarities.......: The virus searches for a file 'Hard Disk:Empty Folder:pf' that includes a 'PROC' ID 42 Resource; if this is found, it will be executed, but the resource hasn't been encountered yet. The virus tries to work around SAM Intercept by getting the addresses of AddResource, ChangedResource and WriteResource out of the code of SAM to call Traps without SAM noticing it; this will go wrong if any other program or recent versions of SAM starts the pathed trap calls with a JSR instruction ($4EFA) or if the patch-address are located at another adress. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct: 1. Removal of INIT 34 from the system file will disinfect the system. 2. Copying saved jump entry from CODE 252 offset Hex 45A to the first entry in CODE 0 jump table entry will disinfect an infected application. Countermeasures/software:1. Use of a commercial anti-viral product or a public domain utility such as Virus Detective, Disinfectant >=2.8 to carry out virus signature scans. 2. Use of a protection INIT such as Vaccine or Gatekeeper to trap resource manager calls. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 20-April-1992 ===================== End of CODE 252 Virus ========================== ===== Computer Virus Catalog 1.2: INIT 1984 Virus (25-July-1992) ===== Entry...............: INIT 1984 Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: March 1992 where.: Ireland Classification......: Link virus, files of type INIT;stealth (attempt) Length of Virus.....: INIT ID 1984 bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: System 4.1 or greater Computer model(s)...: Apple Macintosh: all models --------------------- Attributes ------------------------------------ Easy Identification.: INIT ID 1984; STR ID 1984 "SCULLEY MUST DIE!" Resource pattern....: INIT ID 1984 4342 bytes Type of infection...: Adding INIT ID 1984 and STR ID 1984 resource Infection trigger...: Executing an infected INIT. The virus has a counter in STR ID 1984; depending on its value, the virus tries to infect another INIT within 6 seconds, and subsequently tries to deactivate SAM Intercept. Applications affected:All files of type "INIT" Traps intercepted...: None Damage..............: Transient damage: --- Permanent damage: several actions: Renaming all files to random 8 byte names; files to be renamed will be choosen in alphabetical order, so some files will be renamed more than once while some won't be renamed at all. Changing Type and Creator to random 4 byte values; Changing creation and modification date to January 1st, 1904. Files that can't be renamed (when filename exists or new name contains ":") will be deleted. Damage Trigger......: Running an infected system on any Friday-13th. Peculiarities.......: The virus tries to deactivate SAM Intercept but it searches for the wrong file type. Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct: Remove all INIT 1984 resources from all INIT's Remove all STR 1984 resources from all INIT's Countermeasures/software:Use of a commercial anti-viral product or a public domain utility such as Virus detective or Disinfectant >=2.8 to carry out virus signature scans. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Thomas Piehl Documentation by....: Ronald Greinke Date................: 13-July-1992 ===================== End of INIT 1984 Virus ========================= ======= Computer Virus Catalog 1.2: MBDF A Virus (25-July-1992) ====== Entry...............: MBDF A Virus Alias(es)...........: --- Virus Strain........: --- Virus detected when.: February 1992 where.: Wales Classification......: Link virus, System & applications Length of Virus.....: Resource fork extension 638 bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: System 4 or greater including system 7 Computer model(s)...: Apple Macintosh: See ROMs under Traps affected. All other systems if ChangedResource is called via ROM. --------------------- Attributes ------------------------------------ Easy Identification.: MBDF resources with ID 0 and 1 in System file; MBDF 0 with size 630 bytes Resource pattern....: MBDF ID 0 630 Bytes Type of infection...: System: Renumbering any existing MBDF 0 to MBDF 1; adding MBDF ID 0 to file. Applications: Adding MBDF ID 0 if file has none. Infection trigger...: Executing an infected file to infect System. Running an application under an infected system. Applications affected:All files that use menus and have no MBDF 0 Traps intercepted...: For the following ROMs: Mac II,x,cx,ci,SE,SE/30,Portable ROMs, the following traps are called via direct ROM calls: AddResource SetResAttrs ChangedResource WriteResource Damage..............: Permanent damage: none Transient damage: none Damage Trigger......: --- Peculiarities.......: Applications may have MBDF resources (compare size) Similarities........: --- --------------------- Agents ----------------------------------------- Countermeasures/direct: Boot from clean system disk, remove MBDF 0 from System file; change MBDF 1 to MBDF 0 with ResEdit; remove all MBDF 0 resources with size 610 bytes from applications. Countermeasures/software: Use of a commercial anti-viral product or a public domain utility such as Virus detective, VirusRx, Interferon or Disinfectant >= 2.6 to carry out virus signature scans. --------------------- Acknowledgement -------------------------------- Location............: VTC University Hamburg,Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 04-April-1992 ===================== End of MBDF A Virus ============================ ======== Computer Virus Catalog 1.2: T4-A Virus (25-July-1992) ======= Entry...............: T4-A Virus Alias(es)...........: --- Virus Strain........: T4 Virus Strain Virus detected when.: June 1992 where.: Several FTP sites around the world Classification......: Link virus, applications only; stealth (attempt) Length of Virus.....: Resource fork extension 5610 bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All systems including System 7 Computer model(s)...: All Mac models --------------------- Attributes ------------------------------------- Easy Identification.: STR ID 32767 Resource. Near the end of one of the CODE resources, the string "Disinfectant" can be found. Moreover, strings "Application is infected" and "with the T4 virus" can be found in that resource. Resource pattern....: Extending an existing CODE resource by 5610 Bytes Type of infection...: Patching the first InitDialogs (or TEInit if no InitDialogs is found) to a call to a BSR to virus code and adding the virus at the end of that resource. Infection trigger...: Executing an infected file infects one other file. The virus uses a recursive search to find the next uninfected file starting on the desktop of volume 0. A file is only infected if the size of the resource to become infected is less than 32767-5610 bytes. Applications affected:All applications that use InitDialogs or TEInit. Traps intercepted...: None Damage..............: Permanent damage: 1. Infected files may not be restored to their original state because of different patches for InitDialogs and TEInit. 2. The virus disables all INITs and cdevs on all next boots by patching INIT 31 to a RTS (System 6.xx) and boot 2 (System 7.x). 3. Patching boot 2 on a System 7.01 (Quadra, Powerbook) may cause the computer to hang because boot 2 has been changed. Transient damage: 1. The virus displays the message "Application is infected with the T4 virus" and displays some biological virus icon. Damage Trigger......: Running an infected application. Trigger for message and icon: if the infected program infected 10 other applications. Peculiarities.......: In some attempt to undergo detection (stealth), the virus tries to fool the user by renaming an application to "Disinfectant" during infection; if Disinfectant is present, it will be renamed to "Dis". If SAM Intercept or another monitoring program is installed, this will cause messages that "Disinfectant" wants to modify boot 2 (System 7) or INIT 31 (System 6.xx) and to modify a program which the virus tries to infect. Similarities........: T4-B variant; a predecessor (not widely distri- buted), some kind of trojan, performed its infectuous task only after user allowance (displaying some display box where the user could acknowledge virus' action) --------------------- Agents ----------------------------------------- Countermeasures/direct: Restoring the original boot 2 (System 7.x) or INIT 31 resources in System with ResEdit. Repairing applications may not be possible (see above). Countermeasures/software:Use a commercial anti-viral product or a public domain utility such as Virus Detective or Disinfectant >= 2.9 to carry out virus signature scans. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 13-July-1992 ===================== End of T4-A Virus ============================== ======== Computer Virus Catalog 1.2: T4-B Virus (25-July-1992) ======= Entry...............: T4-B Virus Alias(es)...........: --- Virus Strain........: T4 Virus Strain Virus detected when.: June 1992 where.: Serveral FTP sites around the world Classification......: Link virus, applications only Length of Virus.....: Resource fork extension 5792 bytes --------------------- Preconditions ---------------------------------- Operating System(s).: MacOS proprietary Version/Release.....: All systems (including System 7) Computer model(s)...: All. --------------------- Attributes ------------------------------------ Easy Identification.: STR ID 32767 Resource. Near the end of one of the CODE resources, the string "Disinfectant" can be found; in that resource, strings "@ookhb`shnm hr hmedbsdc" and "vhsg sgd S3 uhqtr" can be found. Resource pattern....: Extenting an existing CODE resource by 5792 Bytes Type of infection...: Patching the first InitDialogs (or TEInit if no InitDialogs is found) to a call to a BSR to virus code and adding the virus at the end of that resource. Infection trigger...: Executing an infected file infects one other file. The virus uses a recursive search to find the next uninfected file starting on the desktop of volume 0. A file is only infected if the size of the resource to be infected is <32767-5792 bytes. Applications affected:All applications that use InitDialogs or TEInit. Traps intercepted...: None Damage..............: Permanent damage: 1. Infected files may not be restored to their original state because of different patches for InitDialogs and TEInit. 2. The virus disables all INITs and cdevs on all next boots by patching INIT 31 to a RTS (System 6.xx) and boot 2 (System 7.x). 3. Patching boot 2 on a System 7.01 (Quadra, Powerbook) may cause the computer to hang because boot 2 has been changed. Transient damage: Virus displays the message "Application is infected with the T4 virus" and displays some biological virus icon. Damage Trigger......: Running an infected application. Trigger for message and icon: if the infected program infected 10 other applications. Peculiarities.......: In an attempt to hide before detection (stealth), the virus tries to fool the user by renaming an application to "Disinfectant" during infection. If "Disinfectant is present, it will be renamed to "Dis". If SAM Intercept or another monitoring program is installed, this will cause messages that "Disinfectant" wants to modify boot 2 (System 7) or INIT 31 (System 6.xx) and to modify a program the virus tries to infect. Similarities........: T4-A (and its trojan predecessor) --------------------- Agents ----------------------------------------- Countermeasures/direct: Restoring the original boot 2 (System 7.x) or INIT 31 resources in System with ResEdit. Repairing applications may not be possible (see above). Countermeasures/software: Use commercial anti-viral product or public domain utility such as Virus detective or Disinfectant >= 2.9 to carry out virus signature scans. --------------------- Acknowledgement -------------------------------- Location............: Virus Test Center, University Hamburg, Germany Classification by...: Ronald Greinke Documentation by....: Ronald Greinke Date................: 13-July-1992 ===================== End of T4-B Virus ==============================