home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
JCSM Shareware Collection 1993 November
/
JCSM Shareware Collection - 1993-11.iso
/
cl840
/
tbav605.lzh
/
WHATSNEW.604
< prev
next >
Wrap
Text File
|
1993-09-01
|
17KB
|
432 lines
Update report of Thunderbyte Anti-Virus utilities.
Prefixes:
'-' indicates a change that does not require user attention.
'->' indicates a modification that requires user attention, such as a
change in program invocation, etc.
*** NOTE ***
NetWork administrators, read the TBAV.Doc file for information about a
fast and reliable way to update all workstations automatically!
6.04 Product update
-------------------
- Major signature / heuristics update!
- Documentation completely revised. The TBAV utilities no longer have
separate manuals. All TBAV utilities are now described in one manual
name TBAV.DOC. This manual is nicely formatted and it is highly
recommended to print it.
-> It is highly recommended to run the batch file Upgrade.Bat. This will
save a lot of disk space as all old doc files will be deleted!
- New agents added! See the file Agents.Doc and the Register program.
-> Address/Phone change of the USA agent. See Agents.Doc and Register.Exe.
TBAV:
-> Signature file format enhanced! Make sure you don't mix up the
current signature file with TbScan(X) or TbGenSig from previous
versions, as this will result in failure to detect some viruses!
- Added a TBAV.INI keyword for the menu shell: 'DefScanPaths=<paths>'.
With this keyword you can specify the default paths that TbScan
should scan from within the menu shell. Previously, the default
scan path was hardcoded 'C:\'.
- Added a TBAV.INI keyword for all TBAV utilities: 'AvFile=<filename>'.
You can use this keyword to alter the name of the Anti-Vir.Dat file.
Consult the file 'Addendum.Doc' for information!
TbGenSig:
- Because the format of the TbScan.Sig file has been changed slightly
(because of new features) TbGenSig had to be modified.
TbScan:
-> Errorlevels have been changed! (0 = OK, 1 = no files found,
2 = Some error occured, 3 = Some files have been changed,
4 = Virus(es) found by heuristic analysis, 5 = Virus(es)
found by signatures or algorithmic detection).
- Slightly modified the code tracer.
- Heuristics improved! More viruses can now be detected with
heuristics, while false alarms have been reduced!
Changed the weight of some heuristic flags to solve many false
alarms. The hit-rate is almost not affected.
TbScan now scans bootsectors always with heuristics fully enabled.
This increases the detection rate dramatically.
- Implemented an automatic code decryptor! Now TbScan is even able
to apply heuristic analysis on program code that has been
encrypted! TbScan is now also able to find signatures in some
encrypted viruses. Therefore a few algorithmic virus recognition
modules could be replaced by a simple signature.
- TbScan no longer issues a false alarm if a Windows or OS2 file
without valid DOS-stub is scanned (not executable for DOS) but
skips the file instead.
- TbScan was not able to scan ramdrives with non-standard sector
sizes (like DrDos VDisk) correctly without option 'Compat'.
Solved.
- Revised the file-read logic. TbScan now almost never needs to
read parts of the file more than once. TbScan performs now faster
on slower disk media.
- TbScan now temporary disables SmartDrv on DBLSpace disks, resulting
in a much better performance!
TbScanX:
- Now works faster due to changes in the signature format.
- Current version consumes about 10% less conventional memory
when using XMS or EMS swap memory.
- Finally removed the (already undocumented) multiplex interrupt.
- Added a new undocumented option 'xmsseg=<hexnum>' (xs). You can
use this option to specify on which address the temporary XMS
swap buffer should be located while files are being copied. The
default address is 6000h. If you experience troubles using the
XMS option, try if this option can solve it. Recommended values
are from 2000h to 8800h (default is 6000h). Let us know if this
helps and which value you use.
- Cosmetic change: TbScanX now displays a signature counter while
reading the signature file data.
TbSetup:
- TbSetup didn't remove Anti-Vir.Dat files from empty directories.
Bug fixed.
- Removed some entries from the TbSetup.Dat file because TbScan
doesn't cause false alarms for these files anymore.
Added several new entries for convenience.
TbDriver:
- The 'noavok' option now also accepts 'Z' as valid drive.
TbCheck:
- The 'noavok' option now also accepts 'Z' as valid drive.
-> Now also obeys the master 'noavok' option of TbDriver.
TbMem:
- TbMem 6.03 could not be disabled with option 'off'. Solved.
Also the behavior under Windows has been improved.
TbClean:
- Removed two bugs in the stack segment register emulator.
- Improved the security of the code tracer of the heuristic
cleaning mode.
- Added a new option 'noheur' (nh). You can use this option
if you want to prevent TbClean to use the heuristic cleaning
mode. A corresponding TBAV.INI keyword has been added too.
TbUtil:
- Added a new option 'getboot <drive>'. This option can be used
to save the bootsector of the specified drive into a file.
This allows you to send suspected bootsectors to our Bulletin
Board Systems or transport a contaminated bootsector safely
on a diskette.
TbGarble:
-> This program is no longer available. Instead we will launch a
complete new product (TbFence) to encrypt and decrypt diskettes.
Call us for more information!
GetBoot:
-> Program no longer available as the same funtionality is now
offered by TbUtil.
TbLanMsg:
-> This is a new program, intended for network users. Its purpose
is to forward TBAV messages on workstations to the supervisor or
helpdesk. Consult the file Addendum.Doc for detailed information.
TbLog:
-> This is a new program. This program records all messages of
resident TBAV utilities and TbScan into a log file. This program
is primarily intended for network users. The supervisor can
examine this file frequently so he can take action in time.
Consult the file Addendum.Doc for detailed information.
Viruses:
Performed major maintenance on the signature database!
Note: There are several viruses which do nothing interesting, except
for replicating. These viruses are very easy to detect, but it consumes
a lot of resources to identify them uniquely. Naming was also difficult,
how to name a virus without 'special effects'? Now these signatures
are replaced by a generic detection algorithm (actually some type of
extremely reliable heuristics developed to detect small viruses).
The viruses detected by this algorithm are named 'Trivial.xxx' where
the 'xxx' will be replaced by the effective length of the virus.
Several small, previously not detected, viruses, are now detected by
the new generic 'Trivial' virus detection algorithm. These viruses
are NOT listed in the list of "added signatures/algo's"!
- Removed detection algorithms:
TPE_demo (Was not a virus but a demo program).
NED now replaced by a signature.
- Removed signatures:
Cascade.1704.G Now detected by 'Cascade {1}' signature
Tremor Replaced by algorithmic detection routine
VCL.Grunt.346 Replaced by one generic 'Grunt' signature
VCL.Grunt.427 Replaced by one generic 'Grunt' signature
VCL.Grunt.473 Replaced by one generic 'Grunt' signature
Raubkopie.1888 Replaced by one generic 'Raubkopie' signature
Raubkopie.2219 Replaced by one generic 'Raubkopie' signature
Traceback.2930 Replaced by one generic 'Traceback' signature
Traceback.3029 Replaced by one generic 'Traceback' signature
Traceback.3066 Replaced by one generic 'Traceback' signature
SK Obsolete. Detected by the Tolbuhin signature
DisCom Obsolete. Detected by the Jerusalem signature
Deicide.A Was actually detected by Deicide.B
Formiche Obsolete. Detected by the Cascade {1} sig.
Leprosy {1} and {3} Covered by the other Leprosy signatures
Liberty.B Now detected by the new Liberty signature
Kampana.3700 Detected by the Kampana.3784 signature
Stupid Detected by the Haddock signature
Stupid Sadam Detected by the Haddock signature
Stupid Rock No virus could be found by it
1591 No virus could be found by it
Timid.306 Replaced by generic Timid signature
Timid.382 Replaced by generic Timid signature
WWT All variants are now detected by Trivial.xxx
Trivial {3} Replaced by generic 'Trivial.xxx' detector
_178 Detected by generic det. algo (Trivial.178)
Demon Detected by generic det. algo (Trivial.272)
Yukon Detected by generic det. algo (Trivial.151)
Vienna.Com2Con Detected by generic det. algo (Trivial.311)
Tiny.97 Detected by generic det. algo (Trivial.97)
Toxic.2 Detected by generic det. algo (Trivial.171)
Trivial.44 Detected by generic det. algo (Trivial.44)
Civil_War Detected by generic det. algo (Trivial.244)
Danish_Tiny.Kennedy Detected by generic det. algo (Trivial.333)
Itty-Bitty.99 Detected by generic det. algo (Trivial.99)
Itty-Bitty.161 Detected by generic det. algo (Trivial.161)
Luca Detected by generic det. algo (Trivial.309)
Milan Detected by generic det. algo (Trivial.265)
Milan.New_Bad_Guy Detected by generic det. algo (Trivial.208)
MSK.Blaze Detected by generic det. algo (Trivial.284)
Swiss.143 Detected by generic det. algo (Trivial.143)
ZigZag Detected by generic det. algo (Trivial.127)
- Changed signatures:
_2Kb_II Detects additional variants. Renamed to LZR
_1092 Detects additional variants. Renamed to Intrep
_Cyber Renamed to Cybertech (CARO name)
_Dennis Renamed to PS-MPC.Dennis (CARO name)
_Mut_Int Renamed to Mutating_Interrupt (McAfee name)
_PopSci Renamed to Trivial.Popoolar (CARO name)
_Texas Renamed to Joker.1602
Anto Renamed to Tiny-GM (CARO name)
Brainy (COM) Renamed to Brainy (CARO name)
Brainy (EXE) Renamed to Warrior (CARO name)
Burger.382 Changed because of scanner modifications
Captain Trips Renamed to Jerusalem.Captain_Trips.
Cascade {1} Detects new variants.
CSL {1} and CSL {2} Changed to one generic signature.
dBase Changed because of scanner modifications
Datacrime_II {1}/{2} Changed to one generic signature.
Deicide.B Renamed to 'Deicide'.
Diamond Now detects additional variants.
Experiment Now detects additional variants.
FileHider Now detects a new variant.
Guppy Now detects a new variant.
Halloechen Now detects a new variant.
Helloween Now detects additional variants.
HH&H Now detects additional variants.
Hitchcock Now detects additional variants.
Hymn.Hymn Changed because of scanner modifications
I-am-ill Renamed to Ill (CARO name)
Infector Now detects additional variants.
Jerusalem.Solano Changed because of scanner modifications
Jerusalem.Zero_Time Now detects additional variants.
July_13th Now detects additional variants.
Kampana.3445 Changed because of scanner modifications
Kampana.3784 Renamed to Kampana.37xx (includes 3700)
Leech Changed because of scanner modifications
Leprosy Now detects additional variants.
Liberty Now also detects the Liberty.B variant.
Lovechild Now detects additional variants.
Lyceum Now detects additional variants.
Mannequin Detects a new variant.
November_17th Detects a new variant.
On_64 Now also detects the .B variant.
Oxana Now detects more variants.
Paris Changed because of scanner modifications
PCBB.3072 Solved a false positive.
Phalcon.* Renamed several Phalcon viruses to PS-MPC
Pixel Now detects additional variants.
Possessed Now works more reliable.
Proto-T Now detects additional variants.
Rape_II Now detects additional variants.
Stasi Now detects additional mutants.
Ten_Bytes Changed because of scanner modifications
Terminator_II Changed because of scanner modifications
Virdem Now detects additional variants.
Walker Now actually detects the Walker virus! :-)
X-Fungus Now also detects the B variant.
Yaunch Changed because of scanner modifications
- Added detection algorithms:
Tremor Detection of all Tremor virus instances.
Trivial.xxx Generic detection of trivial viruses <400 b.
TPE:Civilwar Now detects 100% of these polymorphic viruses!
TPE:Girafe.A Now detects 100% of these polymorphic viruses!
TPE:Girafe.B Now detects 100% of these polymorphic viruses!
- Added signatures:
_160
_1068
_1391
_1403
_17690
4res
Alpha
Amt
Andromeda
AntiD
Aragorn (com/exe)
Arusiek
Att
Butterfly
Cascade {3}
Chang
CHCC
Chips
Chr
Clone
Close.960
Coib
Compagnion
Coruna.2
Coruna.3
Cpxk
CV4
Davis
Dead
Dismember
Disk_Plus_1
_Dodo
Dracula
Dupacel
E-Riluttanza
Error
Fat_table
Frajer
Freak
Galicia
Gingerbread
Granada
Grune
Hacktic.1
Hacktic.2
Halley
Hallo
Hamster
Harm
HideNowt
Honey
Horns
Invisible_man
Iron_Umbrella
James
Joker-01
Joker.1602
Kela
Kudepsta
LEV
Liberty_SSSSS
Lippi
Little_Red
MH-757
Mierda
Mutator
Mr-D
Naziphobia
Nazgul
NG
Omt
Over4032
PC-Flu_1
Peter_II
Pick
Plagiarist
Play_Tetris
Plutonium
Poledne
Polish_Tiny
Porridge
Quiet
Raubkopie
Runtime-err412
Sandra
Screaming_Fist.652
Sleepwalker
SlowLite
Small (generic)
Small.127b
Spring
Stardot.805
Suicidal
Talking_Heads
Tchantches
Timid
Tiny.143b
Tiny.212
Tired
Tonya
Toxic.3
Tremor (memory)
Trivial.Encrypted
TU-482
Tula_I
Under7
VCL {1} (generic)
VCL.Grunt
VCL.Lockup
VCL.Mimic
VCL.Mindless
Vienna.T-Soft
Voidpoem
Wanderer
Warlock
Witch
XAM
Yankee_Doodle.TP-44