TweetFollow Us on Twitter

Virus Protection
Volume Number:8
Issue Number:2
Column Tag:Pascal Workshop

Related Info: Resource Manager

Simple Antivirus Protection

An anti-virus scheme that can be painlessly added to every application.

By Nicholas Pisarro, Jr., Westport, Connecticut

About the author

Nick Pisarro is the principle architect of Aperture Visual Information Manager by the Graphic Management Group, Inc. He has been involved with all aspects of computer design including both hardware and software since 1961 and with the Macintosh since 1986.

The Virus Scout Pascal unit described in the January 1991 Programmer’s Forum is a nice idea. One problem with Virus Scout was that it was coded to handle only those specific viruses that the author knew about and could offer no protection against any future viruses that may infect an application.

It did set me to wondering, however, if there is a way to make both a simpler yet more universal virus detection scheme. I began to think about how viruses infect and reproduce themselves through an application, and how I could have applications I have developed protect themselves from becoming infected.

In order for a virus to infect an application it needs to either modify the existing resources of an application and/or add resources of its own. In order to reproduce it needs to seize program control from the application and the user’s Macintosh in order to issue its own instructions of death and destruction. This requires modification of a code resource such as ‘CODE’, ‘WDEF’, ‘MDEF’, or ‘LDEF’ resource types.

Usually a virus inserts a small stub of code in an existing resource to branch to one of its own resources, or it inserts a whole new code resource of its own to seize control. I don’t believe any viruses try to insert all their code in an existing application resource but always have to add a resource. Adding to a code resource, by linking in code, is a difficult operation and runs the risk of overflowing the size restrictions of code resources.

One advantage a virus detection scheme has within an application is that it knows how many and what types of resources the application should have! Rather than checking for the addition of specific virus resources, the virus detection scheme presented here just checks the number of resources the application should have against the number it actually has. In addition there is a Toolbox call that tells me the number of types of resources a resource fork has as well as specific counts. This may be used to check for the addition of additional types of resources. As the resource map for an application is in memory when it is running these types of checks do not use significant amounts of computer time.

It would be possible to check counts of all the resource types an application has, but I believe just checking the specific counts of its code resources is sufficient. A virus must insert or modify a code resource to gain control.

The Pascal unit here reads a resource with a count of the number of types of resources an application has as well as counts of specific types. If it finds any mismatch between expectations and reality, it notifies the user and causes the application to quit early. Note the “Get1” form of the resource call is used to get counts only from this application. This unit must be run before any data file resource forks are opened. If the application modifies its own resource fork, it must be careful not to do it in a way that triggers this virus check.

In the sample code no specific resource type has been assigned for the information resource. If all applications used the same type for this resource, a new virus could be written to circumvent this protection scheme. Use your own type.

Note that the code here is only concerned with viruses that infect an application, rather than viruses that infect files in the System Folder or the Desktop. Code like that from Virus Scout or elsewhere could be added to do this additional checking.

Listing

{Written by Nicholas Pisarro, Jr., Aperture Technologies, Inc.
 No rights reserved.}

UNIT VirusCheck;

INTERFACE

USES
 {$LOAD}
 MemTypes, QuickDraw, OSIntf, ToolIntf, PackIntf;
 

{Returns TRUE if Application can run.}
FUNCTION ApplicationCanRun: BOOLEAN;


IMPLEMENTATION

{Returns TRUE if Application can run.}
FUNCTION ApplicationCanRun: BOOLEAN;
 CONST
 kVirusChkKinds  = '????';{Rsrc type for the # 'CODE' & # of Kinds of 
resources}
 kVirusChkID=  32; {Resource ID for the Virus Check Rsrc}
 
 {The Virus found alert and its sub-messages}
 kVirusAlrt =  1282; {A Virus has been detected!}
 kCountRsrcMissing = 1;   {The Resource count Resource is missing}
 kTypeMiscount   = 2;{Wrong number of resource types}
 kRsrcMiscount   = 3;{Wrong number of a specific res. kind}
 
 TYPE
 {Resource & Count list.}
 RsrcCount = RECORD
 RType: ResType;
 RCount:INTEGER;
 END;
 
 RsrcRSRC = ARRAY[0..0] OF RsrcCount;
 pRsrcRSRC = ^RsrcRSRC;
 hRsrcRSRC = ^pRsrcRSRC;
 
 VAR
 {For counting Resources.}
 theResType:ResType; { The kind we’re looking for }
 subMsgNo:INTEGER; { Submessage number }
 msgStr,{ Submessage to go into dialog}
 workStr: Str255;{ Resource name to go into the message }
 
 aRsrcRSRC: hRsrcRSRC;  { Handle to the Count Rsrc}
 
 i:INTEGER;
 dummy: INTEGER;
 
 LABEL 100;
BEGIN   { ApplicationCanRun }
 ApplicationCanRun := FALSE;{Assume failure.}
 
 {Virus Check: Load resources with counts of various kinds of resources
  in Application. Make sure the counts in the resource match the actual
  counts in Application.}
 workStr[0] := CHR(0);    {Make WorkStr have no length.}
 
 {Try to get the counts of the various resources in the Application.}
 aRsrcRSRC := hRsrcRSRC(Get1Resource(kVirusChkKinds, kVirusChkID));
 IF aRsrcRSRC <> NIL THEN BEGIN
 
 {Check out each of the counts read.}
 FOR i := 0 TO GetHandleSize(Handle(aRsrcRSRC)) div SIZEOF(RsrcCount) 
- 1 DO BEGIN
 
 {If the kind is a 0, a total resource count is wanted.}
 IF ORD(aRsrcRSRC^^[i].RType[1]) = 0 THEN BEGIN
 
 {Does the total number of resource kinds in the Application
  match the count the resource?}
 IF (Count1Types <> aRsrcRSRC^^[i].RCount) THEN BEGIN
 
 subMsgNo := kTypeMiscount; { Sub message }
 
 {Issue a Virus Alert to the user.}
100:    GetIndString(msgStr, kVirusAlrt, subMsgNo);
 ParamText(msgStr, workStr, '', '');
 dummy := StopAlert(kVirusAlrt, NIL);
 
 EXIT(ApplicationCanRun);
 END;
 END
 
 {Otherwise, check a specific type.}
 ELSE BEGIN
 
 {Does the number of this kind of resource in the Application
  match the count the resource?}
 theResType := aRsrcRSRC^^[i].RType;
 IF Count1Resources(theResType) <> aRsrcRSRC^^[i].RCount THEN BEGIN
 
 { Make a string out of the resource type. }
 WorkStr[0] := CHR(4);
 BlockMove(@theResType[1], @workStr[1], 4);
 
 subMsgNo := kRsrcMiscount; { Sub message }
 
 GOTO 100;
 END;
 END;
 END;   {End FOR i }
 
 {Finished with the resource}
 ReleaseResource(Handle(aRsrcRSRC));
 END    {End IF aRsrcRSRC <> NIL}
 
 {Count Resource not found.}
 ELSE BEGIN
 subMsgNo := kCountRsrcMissing;    { Sub message }
 
 GOTO 100;
 END;
 
 {Possibly put other virus checks, checks for the proper system version,
  etc. here.}
 
 ApplicationCanRun := TRUE; {Success!}
END;    { ApplicationCanRun }

END.
 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Live Home 3D Pro 3.2.2 - $69.99
Live Home 3D Pro, a successor of Live Interior 3D, is the powerful yet intuitive home design software that lets you build the house of your dreams right on your Mac. It has every feature of Live Home... Read more
Live Home 3D Pro 3.2.2 - $69.99
Live Home 3D Pro, a successor of Live Interior 3D, is the powerful yet intuitive home design software that lets you build the house of your dreams right on your Mac. It has every feature of Live Home... Read more
FileZilla 3.27.0.1 - Fast and reliable F...
FileZilla (ported from Windows) is a fast and reliable FTP client and server with lots of useful features and an intuitive interface. Version 3.27.0.1: MSW: Add misssing file to .zip binary package... Read more
Spotify 1.0.59.395. - Stream music, crea...
Spotify is a streaming music service that gives you on-demand access to millions of songs. Whether you like driving rock, silky R&B, or grandiose classical music, Spotify's massive catalogue puts... Read more
Sierra Cache Cleaner 11.0.6 - Clear cach...
Sierra Cache Cleaner is an award-winning general purpose tool for macOS X. SCC makes system maintenance simple with an easy point-and-click interface to many macOS X functions. Novice and expert... Read more
DiskCatalogMaker 7.1.2 - Catalog your di...
DiskCatalogMaker is a simple disk management tool which catalogs disks. Simple, light-weight, and fast Finder-like intuitive look and feel Super-fast search algorithm Can compress catalog data for... Read more
Live Home 3D Pro 3.1.2 - $69.99
Live Home 3D Pro, a successor of Live Interior 3D, is the powerful yet intuitive home design software that lets you build the house of your dreams right on your Mac. It has every feature of Live Home... Read more
Deeper 2.2.1 - Enable hidden features in...
Deeper is a personalization utility for macOS which allows you to enable and disable the hidden functions of the Finder, Dock, QuickTime, Safari, iTunes, login window, Spotlight, and many of Apple's... Read more
Pinegrow 3.04 - Mockup and design webpag...
Pinegrow (was Pinegrow Web Designer) is desktop app that lets you mockup and design webpages faster with multi-page editing, CSS and LESS styling, and smart components for Bootstrap, Foundation,... Read more
Deeper 2.2.1 - Enable hidden features in...
Deeper is a personalization utility for macOS which allows you to enable and disable the hidden functions of the Finder, Dock, QuickTime, Safari, iTunes, login window, Spotlight, and many of Apple's... Read more

Latest Forum Discussions

See All

The best deals on the App Store this wee...
There are quite a few truly superb games on sale on the App Store this week. If you haven't played some of these, many of which are true classics, now's the time to jump on the bandwagon. Here are the deals you need to know about. [Read more] | Read more »
Realpolitiks Mobile (Games)
Realpolitiks Mobile 1.0 Device: iOS Universal Category: Games Price: $5.99, Version: 1.0 (iTunes) Description: PLEASE NOTE: The game might not work properly on discontinued 1GB of RAM devices (iPhone 5s, iPhone 6, iPhone 6 Plus, iPad... | Read more »
Layton’s Mystery Journey (Games)
Layton’s Mystery Journey 1.0.0 Device: iOS Universal Category: Games Price: $15.99, Version: 1.0.0 (iTunes) Description: THE MUCH-LOVED LAYTON SERIES IS BACK WITH A 10TH ANNIVERSARY INSTALLMENT! Developed by LEVEL-5, LAYTON’S... | Read more »
Full Throttle Remastered (Games)
Full Throttle Remastered 1.0 Device: iOS Universal Category: Games Price: $4.99, Version: 1.0 (iTunes) Description: Originally released by LucasArts in 1995, Full Throttle is a classic graphic adventure game from industry legend Tim... | Read more »
Stunning shooter Morphite gets a new tra...
Morphite is officially landing on iOS in September. The game looks like the space shooter we've been needing on mobile, and we're going to see if it fits the bill quite shortly. The game's a collaborative effort between Blowfish Studios, We're Five... | Read more »
Layton's Mystery Journey arrives to...
As you might recall, Layton's Mystery Journey is headed to iOS and Android -- tomorrow! To celebrate the impending launch, Level-5's released a new trailer, complete with an adorable hamster. [Read more] | Read more »
Sidewords (Games)
Sidewords 1.0 Device: iOS Universal Category: Games Price: $2.99, Version: 1.0 (iTunes) Description: Grab a cup of coffee and relax with Sidewords. Sidewords is part logic puzzle, part word game, all original. No timers. No... | Read more »
Noodlecake Games' 'Leap On!...
Noodlecake Games is always good for some light-hearted arcade fun, and its latest project, Leap On! could carry on that tradition. It's a bit like high stakes tetherball in a way. Your job is to guide a cute little blob around a series of floating... | Read more »
RuneScape goes mobile later this year
Yes, RuneScape still exists. In fact, it's coming to iOS and Android in just a few short months. Jagex, creators of the hit fantasy MMORPG of yesteryear, is releasing RuneScape Mobile and Old School RuneScape for mobile devices, complete with... | Read more »
Crash of Cars wants you to capture the c...
Crash of Cars is going full on medieval in its latest update, introducing castles and all manner of new cars and skins fresh from the Dark Ages. The update introduces a new castle-themed map (complete with catapults) and a gladiator-style battle... | Read more »

Price Scanner via MacPrices.net

Save or Share
FotoJet Designer, is a simple but powerful new graphic design apps available on both Mac and Windows. With FotoJet Designer’s 900+ templates, thousands of resources, and powerful editing tools you... Read more
Logo Maker Shop iOS App Lets Businesses Get C...
A newly released app is designed to help business owners to get creative with their branding by designing their own logos. With more than 1,000 editable templates, Logo Maker Shop 1.0 provides the... Read more
Sale! New 15-inch MacBook Pros for up to $150...
Amazon has the new 2017 15″ MacBook Pros on sale for up to $150 off MSRP including free shipping: – 15″ 2.8GHz MacBook Pro Space Gray: $2249 $150 off MSRP – 15″ 2.89Hz MacBook Pro Space Gray: $2779 $... Read more
DEVONthink To Go 2.1.7 For iOS Brings Usabili...
DEVONtechnologies has updated DEVONthink To Go, the iOS companion to DEVONthink for Mac, with enhancements and bug fixes. Version 2.1.7 adds an option to clear the Global Inbox and makes the grid... Read more
15-inch 2.2GHz Retina MacBook Pro, Apple refu...
Apple has Certified Refurbished 2015 15″ 2.2GHz Retina MacBook Pros available for $1699. That’s $300 off MSRP, and it’s the lowest price available for a 15″ MacBook Pro. An Apple one-year warranty is... Read more
13-inch 2.3GHz Silver MacBook Pro on sale for...
B&H Photo has the new 2017 13″ 2.3GHz/256GB Silver MacBook Pro (MPXU2LL/A) on sale for $1399 including free shipping plus NY & NJ sales tax only. Their price is $100 off MSRP. Read more
Apple Tackles Distracted Driving With iOS 11...
One of the most important new features coming in iOS 11 is Do Not Disturb while driving, intended to help drivers stay more focused on the road. With Do Not Disturb while driving, your iPhone can... Read more
iMazing Mini for Mac: Free Automatic and Priv...
Geneva, Switzerland-based indie developer DigiDNA has released iMazing Mini, their free macOS utility designed to automatically back up iOS devices over any local Wi-Fi network. The app offers users... Read more
Clearance 2016 13-inch MacBook Airs, Apple re...
Apple dropped prices recently on Certified Refurbished 2016 13″ MacBook Airs, with models now available starting at $809. An Apple one-year warranty is included with each MacBook, and shipping is... Read more
9.7-inch 2017 iPads available for $299, save...
B&H Photo has 2017 9.7″ 32GB WiFi iPads on sale for $30 off MSRP for a limited time. Shipping is free, and pay sales tax in NY & NJ only: – 32GB iPad WiFi: $299, $30 off Read more

Jobs Board

*Apple* Retail - Multiple Positions - Apple...
SalesSpecialist - Retail Customer Service and SalesTransform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
*Apple* Retail - Multiple Positions - Apple...
SalesSpecialist - Retail Customer Service and SalesTransform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
Senior Payments Architect - *Apple* Pay - A...
Changing the world is all in a day's work at Apple . If you love innovation, here's your chance to make a career of it. You'll work hard. But the job comes with more Read more
Frameworks Engineering Manager, *Apple* Wat...
Frameworks Engineering Manager, Apple Watch Job Number: 41632321 Santa Clara Valley, California, United States Posted: Jun. 15, 2017 Weekly Hours: 40.00 Job Summary Read more
Manager, *Apple* Media Products - Apple Inc...
Job Summary The Apple Media Products Discovery, Fraud and Abuse team is responsible for protecting the integrity of Apple services. As a manager of the team, you Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.