[comp.virus] General virus scanner

h+@diab.se (Jon W{tte - SoftWare konsult) (07/18/90)

More on this thing about a "general virus scanner".

It might not be a simple thing to implement on the mac, but, as
opposed to the PC, most viruses on the mac are self-contained in their
own resources in the resource fork. One could try and find resources
that "look" the same (in some criterian or other) in different
applications. Some resource types would have to be excluded, though
(Like, STR, STR# &c...)

The question is: how many viruses would this catch ?  (it all depends
on the matching criteria) How many false alarms would this trigger ?
Also, some standard libraries (like "MacTraps" in THINK C) arepart of
many widespread applications, and must be excluded as well, and now we
aren't general anymore.

Input on this subject would be much appreciated. You can reach me as
h+@nada.kth.se (NOTE: Other addresses VOID except where prohibited by
law :-)