home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
PC World Komputer 1998 January
/
Pcwk0198.iso
/
Warsztat
/
ANTWIRUS
/
INVIRCBL
/
WHATSNEW.TXT
< prev
Wrap
Text File
|
1996-11-30
|
6KB
|
120 lines
InVircible - Revision 6.12c
---------------------------
ResQdisk had a new 'physical' mode added, providing extended capability
for handling sectors through the entire hard drive, not only the boot
areas. The new mode can be toggled in and out through ^P or with the
mode selection menu, ^L.
Two search modes are provided in physical drive access mode: search for
candidate boot or partition sectors (^B), and case insensitive search
(^F) for a user defined string. Extended ASCII characters, from ASCII
128 to 255 can be entered with Alt + numeric keys.
Extended sector editing capability (^E) is provided in physical mode. A
particularly useful feature of the physical mode is its ability to save
a range of contiguous sectors to file (^S). The latter provides for
user guided data recovery. The 'save to file' and extended editing
features are available to registered ResQpro users only.
IVB changes. IVB can be configured (see below) to either automatically
renew the signature file when a program's new version is found or to
prompt the user before replacing the signatures. IVB will return an
errorlevel 16 when only renewing signatures, errorlevel 1 when an
infection is suspected and errorlevel 0 if nothing is found. The
renewing of a signature file is now recorded in both IVB and the audit
reports.
A 'configuration' option was added to INSTALL. The following parameters
can be set through the configuration menu:
The attribute of the signature files can be selected from 'none',
'read-only' or 'hidden'.
The memory stealing test can be set to 'skip' or the threshold can
be reset to the current value.
Renewal of the signature file in case of a new version can be set to
either renew automatically or prompt the user first.
The IVINIT CMOS test can be set to 'skip' or 'run'. This option
could be useful on laptops that are used in both stand alone and
docked mode. The NOCMOS switch in IVINIT and the utility with the
same name are not required anymore.
The default of IVB's piggybacking detection (PBD) is as follows: PBD is
enabled when running under DOS or Windows 3.11 on local drives and
disabled when checking remote (network) drives.
To prevent false piggybacking alerts, PBD in IVB is now disabled when
invoked trough the IV menu shell while running under Windows NT or 95.
False piggybacking alert is caused by PBD running non-exclusively on a
particular drive. This could be the case on a network drive or in a
multi tasking environment such as Win-95 and NT, hence the above
mentioned default states.
For advanced users and system administrators, an 'exclusivity modifier'
was introduced which overrides the default.
The IVB /NE (non-exclusive) modifier inhibits piggybacking detection
altogether regardless of the default.
The /EX (exclusive) modifier will enable piggybacking detection
wherever possible, including network drives regardless of the
default.
A timed message was added to indicate when piggybacking detection is
disabled.
The following changes were made to IVX:
The correlation algorithm was improved, based on experience gained
in the last couple of years. In result, the discrimination ability
of IVX increased significantly and its use was simplified. Some of
the default parameters and dialog items were changed accordingly.
The 'wildcards' option in the user defined signature mode was
removed as IVX now processes 'approximate' signatures automatically.
The sampling 'offset' parameter, formerly available only in command
line mode was added to the dialog, where applicable. This way, IVX
can now be used in full capacity from the IV shell.
The default value of the detection threshold in statistical mode was
changed from 20% to 40%, due to the increased sensitivity of IVX.
Also, the string matching mode now has a controllable threshold,
with a default value of 80%.
The way how to use the improved IVX need some changes, in order to take
full advantage of the new capabilities. The recommended strategy for
using IVX consists of two stages:
Stage 1: Establish the search parameters that give best results. The
parameters to use while optimizing are the selection of the sample
file and the sampling offset.
Stage 2: Run IVX in string matching mode, against the latest (best)
recorded signature. IVX automatically extracts a signature from the
sample file on every run and saves it in a file (IVX.LOG).
Enhanced macro handling in IVX. The handling of macro viruses and
Trojans has been significantly improved in this version as well as the
rejection of false positives.
A new IVX feature is its ability to detect and restore documents from
botched macro disinfection.
The thermometer scale in IVB and IVSCAN was refined to indicate
progress in increments of 1% rather than per directory, as before.
A problem reported about IV sometimes dropping out of bad or corrupted
directories was fixed. The change applies to IVB, IVX and IVSCAN.
The processing under NT of the boot sector on floppies was improved in
IVSCAN and FIXBOOT. NT requires different techniques than DOS (and Win
95) for disk direct access.
The online IV manual (MANUAL.H!) was updated with the recent changes.
The printable Word manual and the Windows help will be updated at a
later date.