home *** CD-ROM | disk | FTP | other *** search
- InVircible - Revision 6.12c
- ---------------------------
- ResQdisk had a new 'physical' mode added, providing extended capability
- for handling sectors through the entire hard drive, not only the boot
- areas. The new mode can be toggled in and out through ^P or with the
- mode selection menu, ^L.
-
- Two search modes are provided in physical drive access mode: search for
- candidate boot or partition sectors (^B), and case insensitive search
- (^F) for a user defined string. Extended ASCII characters, from ASCII
- 128 to 255 can be entered with Alt + numeric keys.
-
- Extended sector editing capability (^E) is provided in physical mode. A
- particularly useful feature of the physical mode is its ability to save
- a range of contiguous sectors to file (^S). The latter provides for
- user guided data recovery. The 'save to file' and extended editing
- features are available to registered ResQpro users only.
-
- IVB changes. IVB can be configured (see below) to either automatically
- renew the signature file when a program's new version is found or to
- prompt the user before replacing the signatures. IVB will return an
- errorlevel 16 when only renewing signatures, errorlevel 1 when an
- infection is suspected and errorlevel 0 if nothing is found. The
- renewing of a signature file is now recorded in both IVB and the audit
- reports.
-
- A 'configuration' option was added to INSTALL. The following parameters
- can be set through the configuration menu:
-
- The attribute of the signature files can be selected from 'none',
- 'read-only' or 'hidden'.
-
- The memory stealing test can be set to 'skip' or the threshold can
- be reset to the current value.
-
- Renewal of the signature file in case of a new version can be set to
- either renew automatically or prompt the user first.
-
- The IVINIT CMOS test can be set to 'skip' or 'run'. This option
- could be useful on laptops that are used in both stand alone and
- docked mode. The NOCMOS switch in IVINIT and the utility with the
- same name are not required anymore.
-
- The default of IVB's piggybacking detection (PBD) is as follows: PBD is
- enabled when running under DOS or Windows 3.11 on local drives and
- disabled when checking remote (network) drives.
-
- To prevent false piggybacking alerts, PBD in IVB is now disabled when
- invoked trough the IV menu shell while running under Windows NT or 95.
-
- False piggybacking alert is caused by PBD running non-exclusively on a
- particular drive. This could be the case on a network drive or in a
- multi tasking environment such as Win-95 and NT, hence the above
- mentioned default states.
-
- For advanced users and system administrators, an 'exclusivity modifier'
- was introduced which overrides the default.
-
- The IVB /NE (non-exclusive) modifier inhibits piggybacking detection
- altogether regardless of the default.
-
- The /EX (exclusive) modifier will enable piggybacking detection
- wherever possible, including network drives regardless of the
- default.
-
- A timed message was added to indicate when piggybacking detection is
- disabled.
-
- The following changes were made to IVX:
-
- The correlation algorithm was improved, based on experience gained
- in the last couple of years. In result, the discrimination ability
- of IVX increased significantly and its use was simplified. Some of
- the default parameters and dialog items were changed accordingly.
-
- The 'wildcards' option in the user defined signature mode was
- removed as IVX now processes 'approximate' signatures automatically.
-
- The sampling 'offset' parameter, formerly available only in command
- line mode was added to the dialog, where applicable. This way, IVX
- can now be used in full capacity from the IV shell.
-
- The default value of the detection threshold in statistical mode was
- changed from 20% to 40%, due to the increased sensitivity of IVX.
- Also, the string matching mode now has a controllable threshold,
- with a default value of 80%.
-
- The way how to use the improved IVX need some changes, in order to take
- full advantage of the new capabilities. The recommended strategy for
- using IVX consists of two stages:
-
- Stage 1: Establish the search parameters that give best results. The
- parameters to use while optimizing are the selection of the sample
- file and the sampling offset.
-
- Stage 2: Run IVX in string matching mode, against the latest (best)
- recorded signature. IVX automatically extracts a signature from the
- sample file on every run and saves it in a file (IVX.LOG).
-
- Enhanced macro handling in IVX. The handling of macro viruses and
- Trojans has been significantly improved in this version as well as the
- rejection of false positives.
-
- A new IVX feature is its ability to detect and restore documents from
- botched macro disinfection.
-
- The thermometer scale in IVB and IVSCAN was refined to indicate
- progress in increments of 1% rather than per directory, as before.
-
- A problem reported about IV sometimes dropping out of bad or corrupted
- directories was fixed. The change applies to IVB, IVX and IVSCAN.
-
- The processing under NT of the boot sector on floppies was improved in
- IVSCAN and FIXBOOT. NT requires different techniques than DOS (and Win
- 95) for disk direct access.
-
- The online IV manual (MANUAL.H!) was updated with the recent changes.
- The printable Word manual and the Windows help will be updated at a
- later date.
-