TweetFollow Us on Twitter

Virus Protection
Volume Number:8
Issue Number:2
Column Tag:Pascal Workshop

Related Info: Resource Manager

Simple Antivirus Protection

An anti-virus scheme that can be painlessly added to every application.

By Nicholas Pisarro, Jr., Westport, Connecticut

About the author

Nick Pisarro is the principle architect of Aperture Visual Information Manager by the Graphic Management Group, Inc. He has been involved with all aspects of computer design including both hardware and software since 1961 and with the Macintosh since 1986.

The Virus Scout Pascal unit described in the January 1991 Programmer’s Forum is a nice idea. One problem with Virus Scout was that it was coded to handle only those specific viruses that the author knew about and could offer no protection against any future viruses that may infect an application.

It did set me to wondering, however, if there is a way to make both a simpler yet more universal virus detection scheme. I began to think about how viruses infect and reproduce themselves through an application, and how I could have applications I have developed protect themselves from becoming infected.

In order for a virus to infect an application it needs to either modify the existing resources of an application and/or add resources of its own. In order to reproduce it needs to seize program control from the application and the user’s Macintosh in order to issue its own instructions of death and destruction. This requires modification of a code resource such as ‘CODE’, ‘WDEF’, ‘MDEF’, or ‘LDEF’ resource types.

Usually a virus inserts a small stub of code in an existing resource to branch to one of its own resources, or it inserts a whole new code resource of its own to seize control. I don’t believe any viruses try to insert all their code in an existing application resource but always have to add a resource. Adding to a code resource, by linking in code, is a difficult operation and runs the risk of overflowing the size restrictions of code resources.

One advantage a virus detection scheme has within an application is that it knows how many and what types of resources the application should have! Rather than checking for the addition of specific virus resources, the virus detection scheme presented here just checks the number of resources the application should have against the number it actually has. In addition there is a Toolbox call that tells me the number of types of resources a resource fork has as well as specific counts. This may be used to check for the addition of additional types of resources. As the resource map for an application is in memory when it is running these types of checks do not use significant amounts of computer time.

It would be possible to check counts of all the resource types an application has, but I believe just checking the specific counts of its code resources is sufficient. A virus must insert or modify a code resource to gain control.

The Pascal unit here reads a resource with a count of the number of types of resources an application has as well as counts of specific types. If it finds any mismatch between expectations and reality, it notifies the user and causes the application to quit early. Note the “Get1” form of the resource call is used to get counts only from this application. This unit must be run before any data file resource forks are opened. If the application modifies its own resource fork, it must be careful not to do it in a way that triggers this virus check.

In the sample code no specific resource type has been assigned for the information resource. If all applications used the same type for this resource, a new virus could be written to circumvent this protection scheme. Use your own type.

Note that the code here is only concerned with viruses that infect an application, rather than viruses that infect files in the System Folder or the Desktop. Code like that from Virus Scout or elsewhere could be added to do this additional checking.

Listing

{Written by Nicholas Pisarro, Jr., Aperture Technologies, Inc.
 No rights reserved.}

UNIT VirusCheck;

INTERFACE

USES
 {$LOAD}
 MemTypes, QuickDraw, OSIntf, ToolIntf, PackIntf;
 

{Returns TRUE if Application can run.}
FUNCTION ApplicationCanRun: BOOLEAN;


IMPLEMENTATION

{Returns TRUE if Application can run.}
FUNCTION ApplicationCanRun: BOOLEAN;
 CONST
 kVirusChkKinds  = '????';{Rsrc type for the # 'CODE' & # of Kinds of 
resources}
 kVirusChkID=  32; {Resource ID for the Virus Check Rsrc}
 
 {The Virus found alert and its sub-messages}
 kVirusAlrt =  1282; {A Virus has been detected!}
 kCountRsrcMissing = 1;   {The Resource count Resource is missing}
 kTypeMiscount   = 2;{Wrong number of resource types}
 kRsrcMiscount   = 3;{Wrong number of a specific res. kind}
 
 TYPE
 {Resource & Count list.}
 RsrcCount = RECORD
 RType: ResType;
 RCount:INTEGER;
 END;
 
 RsrcRSRC = ARRAY[0..0] OF RsrcCount;
 pRsrcRSRC = ^RsrcRSRC;
 hRsrcRSRC = ^pRsrcRSRC;
 
 VAR
 {For counting Resources.}
 theResType:ResType; { The kind we’re looking for }
 subMsgNo:INTEGER; { Submessage number }
 msgStr,{ Submessage to go into dialog}
 workStr: Str255;{ Resource name to go into the message }
 
 aRsrcRSRC: hRsrcRSRC;  { Handle to the Count Rsrc}
 
 i:INTEGER;
 dummy: INTEGER;
 
 LABEL 100;
BEGIN   { ApplicationCanRun }
 ApplicationCanRun := FALSE;{Assume failure.}
 
 {Virus Check: Load resources with counts of various kinds of resources
  in Application. Make sure the counts in the resource match the actual
  counts in Application.}
 workStr[0] := CHR(0);    {Make WorkStr have no length.}
 
 {Try to get the counts of the various resources in the Application.}
 aRsrcRSRC := hRsrcRSRC(Get1Resource(kVirusChkKinds, kVirusChkID));
 IF aRsrcRSRC <> NIL THEN BEGIN
 
 {Check out each of the counts read.}
 FOR i := 0 TO GetHandleSize(Handle(aRsrcRSRC)) div SIZEOF(RsrcCount) 
- 1 DO BEGIN
 
 {If the kind is a 0, a total resource count is wanted.}
 IF ORD(aRsrcRSRC^^[i].RType[1]) = 0 THEN BEGIN
 
 {Does the total number of resource kinds in the Application
  match the count the resource?}
 IF (Count1Types <> aRsrcRSRC^^[i].RCount) THEN BEGIN
 
 subMsgNo := kTypeMiscount; { Sub message }
 
 {Issue a Virus Alert to the user.}
100:    GetIndString(msgStr, kVirusAlrt, subMsgNo);
 ParamText(msgStr, workStr, '', '');
 dummy := StopAlert(kVirusAlrt, NIL);
 
 EXIT(ApplicationCanRun);
 END;
 END
 
 {Otherwise, check a specific type.}
 ELSE BEGIN
 
 {Does the number of this kind of resource in the Application
  match the count the resource?}
 theResType := aRsrcRSRC^^[i].RType;
 IF Count1Resources(theResType) <> aRsrcRSRC^^[i].RCount THEN BEGIN
 
 { Make a string out of the resource type. }
 WorkStr[0] := CHR(4);
 BlockMove(@theResType[1], @workStr[1], 4);
 
 subMsgNo := kRsrcMiscount; { Sub message }
 
 GOTO 100;
 END;
 END;
 END;   {End FOR i }
 
 {Finished with the resource}
 ReleaseResource(Handle(aRsrcRSRC));
 END    {End IF aRsrcRSRC <> NIL}
 
 {Count Resource not found.}
 ELSE BEGIN
 subMsgNo := kCountRsrcMissing;    { Sub message }
 
 GOTO 100;
 END;
 
 {Possibly put other virus checks, checks for the proper system version,
  etc. here.}
 
 ApplicationCanRun := TRUE; {Success!}
END;    { ApplicationCanRun }

END.
 
AAPL
$101.70
Apple Inc.
+0.84
MSFT
$46.56
Microsoft Corpora
-0.20
GOOG
$586.04
Google Inc.
+6.09

MacTech Search:
Community Search:

Software Updates via MacUpdate

Apple Digital Camera RAW Compatibility 5...
Apple Digital Camera RAW Compatibility update adds RAW image compatibility to Aperture 3 and iPhoto '11. For more information on supported RAW formats, see here.Version 5.07: Adds RAW camera... Read more
Transmit 4.4.7 - Excellent FTP/SFTP clie...
Transmit is an excellent FTP (file transfer protocol), SFTP, S3 (Amazon.com file hosting) and iDisk/WebDAV client that allows you to upload, download, and delete files over the internet. With the... Read more
Macgo Blu-ray Player 2.10.8.1715 - Blu-r...
Macgo Mac Blu-ray Player can bring you the most unforgettable Blu-ray experience on your Mac. Overview Macgo Mac Blu-ray Player can satisfy just about every need you could possibly have in a Blu-ray... Read more
Capture One Pro 8.0.0.433 - RAW workflow...
Capture One Pro 8 is a professional RAW converter offering you ultimate image quality with accurate colors and incredible detail from more than 300 high-end cameras -- straight out of the box. It... Read more
Adobe Acrobat Pro 11.0.09 - Powerful PDF...
Adobe Acrobat allows users to communicate and collaborate more effectively and securely. Unify a wide range of content in a single organized PDF Portfolio. Collaborate through electronic document... Read more
Adobe Reader 11.0.09 - View PDF document...
Adobe Reader allows users to view PDF documents. You may not know what a PDF file is, but you've probably come across one at some point. PDF files are used by companies and even the IRS to... Read more
iFFmpeg 4.6.1 - Convert multimedia files...
iFFmpeg is a graphical front-end for FFmpeg, a command-line tool used to convert multimedia files between formats. The command line instructions can be very hard to master/understand, so iFFmpeg does... Read more
NTFS 11.3.62 - Provides full read and wr...
Paragon NTFS breaks down the barriers between Windows and OS X. Paragon NTFS effectively solves the communication problems between the Mac system and NTFS, providing full read and write access to... Read more
OS X Yosemite 10.10 DP8 - Developer Prev...
Note: This is a Developer Preview. You must be a registered Apple Mac Developer to download this update. You can also sign up for the free OS X Beta Program to download and preview public beta... Read more
FotoMagico 4.5 - Powerful slideshow crea...
FotoMagico lets you create professional slideshows from your photos and music with just a few, simple mouse clicks. It sports a very clean and intuitive yet powerful user interface. High image... Read more

Latest Forum Discussions

See All

Little World Escape Review
Little World Escape Review By Jordan Minor on September 17th, 2014 Our Rating: :: EARTHBOUNDUniversal App - Designed for iPhone and iPad Little World Escape draws players in with captivating concepts before pushing them away with... | Read more »
Light in the Dark Review
Light in the Dark Review By Nadia Oxford on September 17th, 2014 Our Rating: :: LIGHT 'EM UP UP UPUniversal App - Designed for iPhone and iPad Light in the Dark is an interesting and challenging puzzle game with some amusing bits... | Read more »
ShareFile for iPad is iOS 8-Ready with N...
ShareFile for iPad is iOS 8-Ready with New File-Editi​ng Feature Posted by Jessica Fisher on September 17th, 2014 [ permalink ] | Read more »
Pizo Animals
Pizo Animals By Amy Solomon on September 17th, 2014 Our Rating: :: DELIGHTFUL PUZZLESUniversal App - Designed for iPhone and iPad Pizo Animals is a puzzle app that includes many options adults can choose to customize the experience... | Read more »
ETA for iOS 8 Introduces Today View Exte...
ETA for iOS 8 Introduces Today View Extension and is Having a 50% Off Sale Posted by Jessica Fisher on September 17th, 2014 [ permalink ] | Read more »
Get Ready to Hit the Ice – NHL 2K is Com...
Get Ready to Hit the Ice – NHL 2K is Coming to the App Store Soon Posted by Jessica Fisher on September 17th, 2014 [ permalink ] 2K announced today that they are bringing NHL 2K< | Read more »
Readdle Adds Tons of iOS 8 Updates for A...
Readdle Adds Tons of iOS 8 Updates for All Readdle Apps Posted by Jessica Fisher on September 17th, 2014 [ permalink ] With the iOS 8 dropping today, Readdle has dramatically | Read more »
Let it Rainbow Review
Let it Rainbow Review By Jennifer Allen on September 17th, 2014 Our Rating: :: SIMPLE COLORSiPhone App - Designed for the iPhone, compatible with the iPad A little too simple for extended sessions, Let It Rainbow is still a cute... | Read more »
Goat Simulator (Games)
Goat Simulator 1.0.1 Device: iOS Universal Category: Games Price: $4.99, Version: 1.0.1 (iTunes) Description: Goat Simulator is the latest in goat simulation technology, bringing next-gen goat simulation to YOU. You no longer have to... | Read more »
Almightree: The Last Dreamer Review
Almightree: The Last Dreamer Review By Blake Grundman on September 17th, 2014 Our Rating: :: CLIMBING HIGHERUniversal App - Designed for iPhone and iPad Can this Zelda-inspired platformer reach new heights of success?   | Read more »

Price Scanner via MacPrices.net

Logitech Bluetooth Multi-Device Cross-Platfor...
Logitech has an enviable track record of making some of the best computer keyboards and mice. At least in my estimation, the best freestanding keyboards I’ve ever used have been Logitech units,... Read more
Roundup of Apple refurbished iPad Airs and iP...
Apple is offering Certified Refurbished iPad Airs for up to $140 off MSRP. Apple’s one-year warranty is included with each model, and shipping is free. Stock tends to come and go with some of these... Read more
Sprint offers 16GB iPad mini for $199.99 with...
Sprint is offering 1st generation 16GB iPad minis for $199.99 with a 2-year service agreement. Standard MSRP for this iPad is $429. Their price is the lowest available for this model. Read more
2.5GHz Mac mini remains on sale for $549, sav...
B&H Photo has the 2.5GHz Mac mini on sale for $549.99 including free shipping. That’s $50 off MSRP, and B&H will also include a free copy of Parallels Desktop software. NY sales tax only. Read more
Apple refurbished iMacs available for up to $...
The Apple Store has Apple Certified Refurbished iMacs available for up to $300 off the cost of new models. Apple’s one-year warranty is standard, and shipping is free. These are the best prices on... Read more
13″ 2.5GHz MacBook Pro offered for $100 off M...
B&H Photo has the 13″ 2.5GHz MacBook Pro on sale for $999.99 including free shipping plus NY sales tax only. Their price is $100 off MSRP. Read more
Free GIMP Professional Grade Graphics App Ver...
The latest 2.8.14 version of the oddly-named GIMP (acronym for: GNU Image Manipulation Program) open source, high-end image editing and creation alternative to Adobe’s Photoshop and refuge from... Read more
Apple Announces Record Pre-orders for iPhone...
Apple has released metrics showing a record number of first day pre-orders of iPhone 6 and iPhone 6 Plus, with over four million sold in the first 24 hours. Demand for the new iPhones exceeds the... Read more
10% off iPhone 6 and 6 Plus Otterbox cases
Get 10% off on popular Otterbox iPhone 6 and iPhone 6 Plus cases at MacMall through September 19th. Use code OTTERBOX10 to see the discount. Read more
15-inch MacBook Pros on sale for up to $125 o...
Amazon has the new 2014 15″ Retina MacBook Pros on sale for up to $125 off MSRP including free shipping: - 15″ 2.2GHz Retina MacBook Pro: $1899.99 save $100 - 15″ 2.5GHz Retina MacBook Pro: $2374... Read more

Jobs Board

*Apple* Retail - Multiple Positions (US) - A...
Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
*Apple* Retail - Multiple Positions (US) - A...
Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
*Apple* Retail - Multiple Positions (US) - A...
Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
*Apple* Retail - Multiple Positions (US) - A...
Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
*Apple* Retail - Multiple Positions (US) - A...
Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.