Horrortaxi said:That's what I'm asking about--what sort of viruslike behavior is it looking for? And would that behavior be the same on both platforms? I can see on Windows how this would work, but since the structure of the systems are so different and viruses on Windows take advantages of flaws that Mac OS doesn't have I"m wondering if a virus for Mac would look enough like one for Windows for the antivirus to catch.
Well I'm not a virus writer, but I imagine things like installing its own smtp to send emails, trying to open ports frequently used by worms, trying to bulk email everyone in your email addressbook, etc would trigger it. I don't know every trick used by virus writers!!! the structural differences shouldn't make a difference, and although I agree Macs tend to be a bit more secure and should restrict alot of things, no system is perfect. I think heuristics can be really useful (but not perfect) for "day zero" threats where there is no virus signature or patch available yet.