[comp.virus] HyperCard virus --should I wait to script?

IPBR400@INDYCMS.BITNET (Pat Ralston) (04/27/91)

I use HyperCard frequently and am not happy to see that there is a
HyperCard viurs on the loose.

Since there have been several comments on the HyperCard anti-virus
script recently which say in general ..."this won't/may not work", I
am not confident that I want to enter this script in my Home Stack.
In fact I have more than one Home Stack because I have customized
several Home Stacks for the specific uses I make of my stacks.

I have found John Norstad to be very responsive in the past when new
Mac viruses developed.  John, are you working on this one too?  Or
does anyone else know if the Disinfectant virus checking software is
being updated to include the HyperCard virus?

If that is the case I'll wait rather than script something into my
Home Stack that I may not really want there.

I do appreciate the work that Mike went to in trying to give us all a
script to defend against the virus.  And I am sure that many Mac users
are grateful for the work that has been done to give us Disinfectant.

Pat Ralston
IUPUI   Indiana University - Purdue University at Indianapolis

mike@pyrite.SOM.CWRU.Edu (Michael Kerner) (04/30/91)

O.K., Paul, much to my chagrin, the script has the _potential_ of not
working since scriptors can simply change their code to get around it.
I am currently working on a separate script that searches for possible
viruses and trojans.  So, if anyone has the code to the new German HC
virus, would you please send it to me?

This new script is essentially designed to work in HC 1.2.x because it
appears from all the EMAIL that I'm getting that my script works
(through some fluke, mind you) in 2.0v2.  I am studying for finals
right now and have been unable to confirm that it will still work with
a virus implementing "Start using" in its script, or if I can simply
intercept the message even though it may be sent directly to HC.

The problem with my new script is that if there is a handler in the
inheritence path that the user has set up, I won't ever see the
necessary messages to do the job.  This new script will search a stack
when the stack opens.  Options still to be worked out.  Suggestions
welcome.  If anyone wants to run with this idea and beat me to the
punch, feel free, 'cause the main thing is to get to the point where
vandals get the picture that we can protect HC as well as VD,
Disinfectant, and Virex can protect the rest of the Mac.

Mikey.