Anti Virus System Protection
AVSP
Version 1.0 (C) J. V. Dialogue
Designed by Andrew G. Borisov

1 - INTRODUCTION

Thank you for purchasing AVSP.  We are sure that this 
software will become your favourite tool on your personal 
computer.

AVSP is designed for searching for well-known and unknown 
viruses and their curing.  Our system differs from 
existing anti-virus program:

    it has the possibility to add information on searching 
for new virus and their curing;

    it has special tools for analysis of changes in files 
on your disk, for quick and easy writing of curing 
procedures; these tools include disassemble, file viewer, 
file changes visualisation system, etc.;

    friendly and convenient interface including powerful 
menu system and on-line help service;

    high working speed which practically does not depend 
on total system for convenient work - it will save your 
time and increase AVSP work reliability.

1.1 - WHAT YOU NEED

AVSP will work on IBM PC XT/AT personal computers and 
compatibles;

Operating System -- DOS 3.0 and later versions;
Graphical Adapter: EGA/VGA and compatibles.

1.2 - WHAT YOU HAVE

1) Floppy disk with AVSP
2) User's manual

On floppy disk you will find the following files:

AVSP.EXE - basic shell;
SETAVSP.EXE - installation program;
VIRUSES.INF - data file (information on known viruses);
EGA.FNT - text font for EGA;
VGA.FNT - text font for VGA;
AVSP.HLP - on-line help file.

2 - INSTALLATION

=========================================================
NOTICE !!!

To make installation process reliable you should first 
reboot your computer with a "clean" operating system.  To 
do it, put a write-protected DOS diskette into you floppy 
drive and press Reset button (or switch your computer off, 
then, after a couple of seconds, switch it on again).  
Your AVSP installation disk should be write protected too.  
Otherwise a virus may possible damage the software before 
it will start to work.
=========================================================

You need 150 KBytes of free space on your hard Disk to 
install AVSP.

Installation process looks similar to the following:

1) Insert purchased diskette into floppy drive;
2) At the system prompt type:

>A:\SETAVSP (you may type the name of your logical floppy 
drive instead of A:).

When you see the picture press Enter to enter the 
installation menu.

The program will choose default and path to install AVSP 
(C:\AVSP).  You may change these settings by choosing 
"AVSP Program Directory" item in the menu you are 
currently in.

During installation only files necessary for the main 
shell AVSP work will be copied.  If you want the 
installation and font files to be copied, choose "All 
Files" item in the menu and press space bar to select. "*" 
marker shows that your instructions are recorded.

To start installation process choose "Start Installation" 
item and press Enter.

If directory specified by you as AVSP program directory 
already exists you'll see a warning box.  All existing 
files with the same names as the AVSP files will be 
overwritten.

If you are at the DOS prompt just type

AVSP

and Enter to start Anti-Virus.  If you are in the 
installation menu choose  the appropriate item.

3 - HOW TO USE AVSP

3.1 - AVSP Menu System

First AVSP menu time is an ACTION MENU.  Main menu, 
analysis of the changes mode menu and "Viruses Information 
Changing" menu belongs to this type.  All items listed 
vertically.

The user can control the program choosing items by arrows 
and pressing Enter to execute.

You may also use Short-Cuts Alt-1 .. Alt-9; Alt-1 for the 
first item, Alt-2 for the second item and so on.  Holding 
down the Alt key results in displaying of the appropriate 
numbers near menu items.

You can exit the current submenu by pressing Esc.

Example:
To choose "System Defaults" item in the main menu press 
Alt key.  You'll see numbers corresponding to the items 
(figure 2 - near "System Defaults" item).  Holding Alt 
key, press "2" key - you'll go directly into System 
Defaults submenu.  Press Esc to return to the main menu.

The second type of AVSP menu is DIALOGUE WINDOW.  It 
allows you to perform dialogue with the computer quickly 
and comfortably.

Getting acquainted with this menu type, you will easily 
work with a great deal of other application packages where 
the same principle is used.

Entering such a menu you'll see a window with different 
menu groups.  There are four types of them in AVSP:

a) SWITCHES (similar to light switches in your  room).  
Every item of this group can be switched on and off by 
pressing the space bar.

Example:
Where to Search:
[x] Boot Sector
[ ] RAM
[x] Files


b) SWAPPERS (similar to the buttons in your radio 
recorder: pressing one of them results in the release of 
previously pressed button).  If item is on you will see 
"(*)"; if not then "( )".

This group is useful if it is necessary to choose one 
alternative from a variety of them.  Use space bar to swap 
items.

Example:

Search path:
(*)  Current Directory
( )  Current Drive
( )  All Drives

c) INFORMATION STRING - useful for text information 
entering.  You can correct that information with standard 
string editor.

Example:

Current Path:
C:\AVSP

d) ORDERS SET

Example:

What To Do Next?
Install AVSP
About AVSP
Start AVSP

Use the arrow keys, Home and End keys to move between menu 
items (and between groups).  Press Enter to execute.

3) The last menu type is an INDEX MENU.  There are two 
modes in using it.

First, in "Analysis of File Changes" mode a window with a 
list of files and subdirectories from current directory 
appears.

Second, choosing "Viruses Information Changing" item in 
"Adjusting AVSP" menu you'll see a window with a list of 
viruses known to AVSP.

For quick search for a file or virus press letter of its 
name.  The cursor will be placed on a next file or a virus 
with a name beginning with the letter you pressed.

Note: In file lists pressing a capital letter results in 
searching for subdirectories.

You may  enter the virus name directly by pressing the F@ 
key.  Being in a file list you can use the following keys:

<TAB>  - set current path
<Shift  TAB> - set types of files to be search for 
viruses.  AVSP will search for viruses only in files 
specified in this field.
<F4> - view file.  (See Chapter 6.1).

Note: You may use Tab and Shift-Tab keys from any part of 
the main menu.

3.2 - SETTING THE CURRENT PATH

In the top of the screen the current path is displayed.  
All operations, i.e. search for viruses, etc., will be 
performed using this path.  To change it press the Tab 
key.  You'll see the appropriate window:

To set new path you should:

1 - Using arrow keys place the cursor at desired field;
2 - If this field is an information string just type in 
new path;
3 - If it is a drive name use Left and Right arrow keys to 
choose new disk.
4 - Press Enter.

Press Esc to cancel command.

3.3 - ON-LINE HELP SYSTEM

Being in AVSP you can use built-in on-line help service.  
Press F1 to switch it on and off.  You'll see the Help 
window with instructions explaining all possible actions.  
Moreover, you can perform your work while the help window 
will be changed depending on your current disposition.

4 - GETTING FIRST EXPERIENCE

4.1 - LOOKING FOR VIRUSES KNOW TO AVSP

To perform this operation choose "Viruses examination and 
shooting" item in the main menu.

Press Tab to change the current path if necessary.  To 
start viruses examination press Alt-2 ("Viruses 
Examination" item in the current submenu).  First of all 
AVSP will examine your computer shell to estimate the 
volume of work, then it will examine all files specified 
in the system defaults (press Shift-Tab keys to change the 
file search pattern).  Press space bar to pause operation, 
Esc - to cancel.

If system messages will appear during work, they will be 
saved in AVSP.MSG file in your AVSP subdirectory on the 
drive being searched.  You can view AVSP.MSG by choosing 
@"View messages (Alt-F7 item in the current submenu.

See section 5.1 to learn how to configure the system.

4.2 - SHOOTING VIRUSES KNOWN TO AVSP

If a virus is found on your computer it is necessary to 
get rid of it.  You should perform the following 
operations:

1) Choose "Virus Shooting" item.  If AVSP is able to 
eliminate this virus, your file will be cured and AVSP 
will inform you about that.

2) If elimination cannot be performed you have three 
options:
    a) delete damaged file (choose "Yes" in confirmation 
box);
    b) press Ctrl-Break and try to shoot this virus by any 
other anti-virus system (such as AidsTest, Turbo 
Antivirus, etc.);
    c) You may try to teach AVSP to eliminate this virus.  
To do this you should study this manual in detail.  This 
operation should be performed by a skilled programmer.  If 
you're not sure in your knowledge of IBM computers it is 
advisable to ask a system programmer to do it.

4.3 ADJUSTING AVSP FOR YOUR SYSTEM

To get acquainted with your computer AVSP will create data 
files ?:\AVSP\DISKDATA.DTL on your computer hard disks.  
This information (files checksum, size, etc.) will be used 
for analysis of changes on your disks, for unknown viruses 
identification.

To perform this operation choose "Adjusting AVSP" item in 
the main menu.  Then choose "Create Data Files" item in 
the appearing submenu (press the Tab key to change the 
current path if necessary).

All the parameters for this operation could be set in 
"System Defaults" submenu.

4.4 - HOW TO FIND VIRUSES IN TIME

If you suspect that there is a virus somewhere in your 
computer but an AVSP search for viruses resulted in 
nothing, you can check file sizes of checksums.  If AVSP 
finds changes, your suspicions are reasonable.  Study this 
manual in detail to learn what to do in such a situation.


5 - AVSP IN DETAIL

Let's have a look at the menu.

the main menu is an action menu and it looks like this:
Viruses examination and shooting
Adjusting AVSP
Additional options
Quit AVSP

5.1 - VIRUSES EXAMINATION AND SHOOTING

Choosing this item you'll see the following submenu:

General Examination
Search For Viruses In Files
Verify Checksums
\Verify File Sizes
Viruses Shooting
Analysis Of File Changes
View Messages
System Defaults


GENERAL EXAMINATION

This operation is controlled by system defaults and 
convenient for regular system inspection.  See the "System 
Defaults" item description for more information.

SEARCH FOR VIRUSES IN FILES

All files corresponding to the patterns (press  the Tab 
key to set patterns) on your disk will be examined.  
Preliminary examination will be performed to estimate work 
volume.

VERIFY CHECKSUMS AND FILES SIZES

This examination is necessary for new viruses detection.  
AVSP will inform you about operation results; if something 
is wrong, the map of changes will be displayed.

VIRUSES SHOOTING

AVSP will perform searches for known viruses in files and 
boot sectors; these viruses if found will be eliminated 
automatically.  If damaged file is incurable AAVSP will 
offer you to delete it.

Note: To find out why a certain file is irrecoverable you 
should switch the "Automatic reaction to errors" off (see 
the "System Defaults" item for more information).

SYSTEM DEFAULTS

Choosing this option you'll see the following window:

AVSP Will Verify:
[x] File Sizes
[x] Checksums
[x] Viruses Existence

Set features desired to be checked during General 
Examination and File Changes Analysis.

AVSP Will Examine File If:
(*) Size was changed
( ) CS was changed
( ) Always

You can make AVSP work faster if you choose first or 
second item.  For example, if you choose the second item, 
file examination will be performed only in case of its 
size not equalling its previous value (written in 
DISKDATA.DTL file).  This feature works only in "General 
Examination" mode.

Subjects To Be Examined:
[x] Boot Sector
[x] Files
[x] RAM

Subjects set in this menu will be examined during General 
Examination process of Viruses Shooting.

Search Optimisation Methods:
(*) Speed
( ) Quality

Switching on optimisation by speed option means that only 
part of every file will be searched for viruses (entry 
point, etc.)

True, quick search can be performed much faster but if the 
file was damaged by several viruses only the last of them 
will be found.

Moreover, AVSP possesses a very powerful qualified search 
algorithm.  Its speed practically doesn't depend on 
search patterns counts.  That is why it is advisable to 
use qualified search mode.

ADDITIONAL OPTIONS

Additional Options:
[x] Use File Type
[ ] Sound Effects
[x] Automatic reaction to errors
[x] Search Subdirectories
[x] Show Percentage of Work Done

Switching the "Use File Type" option off means that AVSP 
will search for every virus in every file no matter if it 
is a boot virus or *.COM files damaging one.

Switching the "Automatic Reaction To Errors" on means that 
AVSP will react on errors occurring during its work without 
your confirmation.

Switch the "Search Subdirectories" on to examine files in 
all modes of current directory.

"Show Percentage Of Work Done" option controls whether 
AVSP will make preliminary examination to estimate volume 
of work to be done or not.

Searching Path:
(*) Current Directory
( ) Current Drive
( ) All Drives

All Activities can be performed with files in current 
directory, current drive or all disk drives (Except floppy 
disk drives A: and B:).

VIEW MESSAGES

During file size and checksums verification different 
messages may appear.  All of them will be saved in the 
AVSP.MSG file in \ASVP directory located on the drive 
being examined.

Choosing "View Messages" item you'll see the window with 
messages list.  Use cursor control keys to view the whole 
file.

ANALYSIS OF FILES CHANGES

This mode is the most important and powerful one.  It is 
necessary if your computer is damaged by an unknown virus 
(or you suspect it to be damaged).  Entering this mode 
you'll be offered a list of files.  You should place the 
cursor on the name of the file to be examined and press 
Enter.  Press F4 to view the file.  See Chapter 6 for more 
details.

5.2 - ADJUSTING AVSP FOR YOUR SYSTEM

Entering this mode you'll see the following menu:

Changing Information On Viruses
Create Data Files
Edit Data Files
View Messages
Set Defaults

5.2.1 CHANGING INFORMATION ON VIRUSES

AVSP great advantage is possibility tor the user to change 
information on know viruses.  Moreover, the user can enter 
information about new viruses and their curing.  This data 
is stored in VIRUSES.INF text file.  You may change it 
using any text editor (if you want so).

Choosing "Changing Information On Viruses" item you'll see 
a list of all viruses known to AVSP.  You may place the 
cursor on any virus and press Enter to view information 
about this virus.  Press F2 to insert new virus name.

Use cursor control keys and backspace to change 
information about virus.

To save changes box will be displayed:

Save Changes
Continue Editing
Exit Without Saving

SAVE CHANGES

Current virus information will be saved in VIRUSES.INF 
file.  If virus name is missing the information will be 
erased.

CONTINUE EDITING

You can just press Esc while in the confirmation box.  
You'll return to information editing.

EXIT WITHOUT CHANGES

All changes WILL NOT BE SAVED in VIRUSES.INF

Now we'll describe the information on the viruses in 
detail.

Virus Name
Edit virus name.  If you want the information on this 
virus to be erased from VIRUSES.INF you should delete the 
name (press Ctrl-Y).

Virus Type
AVSP has two virus types: boot viruses and program 
viruses.  Perhaps this differentiation is not accurate but 
it is functional.  Program viruses distributes through 
program files (*.COM, *.EXE)

Boot viruses distributes through boot sectors of hard 
disks and diskettes.  Enter the virus type so that AVSP 
can search for this virus in the proper place.  Values 
available are PROGRAM and BOOT.

Virus Size
It is value (or range of values) if file size shift after 
is was infected.  It can be set in one of the following 
formats:
<size>, or
<low limit>:<high limit>

If you don't have any information on virus size leave this 
field empty.  All figures should be decimal.  If you want 
to enter numbers in hex format type "$" symbol right 
before it.  Examples $100, 648, 512:528

Checking and Curing Procedure Description
This should be entered into "Infection" field and looks 
similar to the following:

<Mask>{ <Cure Procedure> };<Mask>{ <Cure Procedure> } ...

Example:
*.EXE;*.COM{Optimal(Start:16) Delete(Start:0,100)}
It means that *.EXE and *.COM could be infected; you can 
see the curing procedure for damaged *.COM files (there is 
no curing procedure for *.EXE files).

If a virus has a BOOT type masks may look like this:

#HardDisk - Virus infects Hard Disk Boot Sector
#FloppyDisk - Virus infects Floppy Diskette Boot Sector.

Example:
#HardDisk{MoveSector(0:0:7,0:0:1)}

It means that the virus infects the HDD boot sector; 
curing procedure follows the mask.

AVSP has its own macrolanguage which allows the user to 
write curing procedures quickly and easily.

COMMANDS AVAILABLE IN CURING PROCEDURE

Optimal(Addr1 [,Addr2])
Sets definite location of pattern in damed files.  Useful 
for eliminating several viruses from a file in optimal 
order.  Addr1 - low limit, Addr2 - high limit of the first 
byte of the pattern.  The default is Addr2 = Addr1.  If 
the pattern location does not correspond to Optimal 
command parameters the process will be cancelled.

Delete(Addr,Count)
Erases block with start address ADDR and with length equal 
to Count from the damaged file.

Move(AddrSource, AddrDestination, Count)
Moves a block with start address AddrSource and with a 
length of Count to an AddrDestination address.

MoveSector(SourceSector, DestinationSector)
Copies sectors: SourceSector to DestinationSector.

Truncate(Addr)
Erase block from the file starting with Addr address 
(inclusively) ending with the last byte of the file.

Sub(Addr,Value[,Count])   subtracts value
Add(Addr,Value[,Count])   adds value
Xor(Addr,Value[,Count])   XOR value
These perform specified operation with the block of bytes 
starting at Addr address with a length equal to Count 
(Count = 1 by default).

SubWord(Addr,Value[,Count])   subtracts value
AddWord(Addr,Value[,Count])   adds value
XorWord(Addr,Value[,Count])   XOR Value
These perform specified operations with a block of words 
(word=2 bytes) with a length equal to Count (Count=1 by 
default, length measures in words).

ADDRESS FORMAT DESCRIPTION

Any address in AVSP should be represented in the following 
format:
Base:Offset.  The following identifiers may be used as a 
base:

MaskPos  - found pattern address
Header   - *.EXE files header address (equals 0)
BegCode  - program code start address (1st byte after       
           header in *.EXE files; 0 in other files)
EndCode  - address equal to the file size
Start    - First executive command address

Note: During procedure action all addresses change 
automatically and always have correct value.  All figures 
are in decimal format.

SECTOR FORMAT DESCRIPTION

<Sector> - logical sector on the current drive
<Head>:<Track>:<Sector> - physical sector on the current 
drive.

So, Master BOOT sector (Partition Table) can be designate 
as 0:0:1, HDD boot sector - as 0 or 1:0:1.

Example:
Move(MaskPos:10,Header:20,4)
Truncate(Start:1050)
MoveSector(0:0:7,0:0:1)
SubWord(Header:4,1)

Now some more information about viruses.

PATTERN DESCRIPTION

Pattern is a block from a virus code (length range is 5 to 
25 bytes).  Using the pattern AVSP will look for a virus 
in the program files, in RAM and in boot sectors.  The 
pattern should be chosen accurately - if AVSP finds it in 
the file's code it should be imply that the file is 
infected.  It is advisable to include text strings into 
patterns and it should be "near" the first executive 
command of the virus.

Example:
EAF005C4F,'VACSINA',002C
E900000102A02E8B
'Eddie lives somewhere'

All figures should be in hex format; ASCII symbols should 
be in quotation marks.

Press F5 while in the pattern field to insert pattern 
copied to a buffer in "File View" mode.

VIRUS DESCRIPTION

You may enter some words about the virus itself; how it 
works, consequences, etc.

5.2.2 - DATA FILES CREATION

Full information about file sizes and checksums will be 
saved in DISKDATA.DTL files, which should be created on 
every logical disk in the \AVSP directory.

Afterwards this information will be used by AVSP to 
identify new viruses.

You should create data files after AVSP installation on 
your computer.  But before you do this it is advisable to 
perform general examination of the data on your computer 
and viruses shooting (if any are found).

If data file already exits AVSP will warn you.

5.3 ADDITIONAL SERVICE POSSIBILITIES

I this menu (you can enter it from the main one) the 
following items are available:

Configuration
About AVSP
System Information
Set Path      TAB

CONFIGURATION

In Configuration menu you can set file masks, AVSP.MSG, 
DISKDATA.DTL and VIRUSES.INF files home directories, and 
some other options.

SYSTEM INFORMATION

Programs loaded into memory, DOS version, date and time, 
and other information will be displayed.

SET PATH

Allows you to set the path for AVSP utilities.  See 
Chapter 3.2 for more details.

6 - CHANGES ANALYSIS

6.1 - FILE VIEW

This mode allows you to view any file.

On the left of the screen the file contents are displayed 
in hex format; on the right - in decimal format.  Use 
cursor control keys to move through the file.  In the top 
of the screen the current position is displayed 
(Base:Offset).

The following identifiers may be used as a base as well as 
any digit:

MaskPos  - found pattern address
Header   - *.EXE files header address (equals 0)
BegCode  - program code start address (1st byte after  
           header in *.EXE files; 0 - n other files)
EndCode  - address equal to the file size
Start    - first executive command address

Offset is always a digit.

This format is convenient for curing procedure creating, 
it is used in AVSP macrolanguage (See Section 5.2.1).

In File View mode several functions are available allowing 
you to change Base Address and to place cursor on any 
position.  You can use this function from the menu (press 
F10 to enter it) or through the short-cuts (Ctrl-B for 
Base address change, etc.).  So, you can easily calculate 
address of patterns, of any part of the file; calculate 
any byte address relatively to Base set by you.

"Changes Analysis" menu also offers you the following 
functions:

FIND PROCEDURE

You can find any pattern in file, AVSP will place the 
cursor on it (if found).  You may enter the pattern 
directly entering this item or you may mark it by space 
bar and the F5 key, and then press Ctrl-L (in File View 
mode).  These short-cuts will be described later in this 
section.

You can perform search for all virus patterns know to 
AVSP.  To set MaskPos equal to pattern location you should 
do it right after "Find Pattern" procedure successfully 
performed.

COMPARE FILES

Allows you compare the current file with any other.  You 
should specify a name of a file and co-ordinate files 
position.  It means that you should set position in viewed 
file which corresponds to a position in the file to which 
the current file is to be compared.  You may also specify 
category of bytes to be displayed in bright colour 
(identical or non-identical).

CHANGING INFORMATION ON VIRUSES

See Section 5.2.1 for details.

ADDITIONAL SERVICE POSSIBILITIES IN FILE VIEW MODE

AVSP allows you to store a pattern in memory and calculate 
Offset relatively to the position.

To store the pattern in memory you should perform the 
following steps:
1) Press space bar to mark pattern start byte. (It also 
means you set Base equal to the current cursor location)

2) Locate cursor right after the last byte of the pattern 
desired to be stored. (Offset displayed in the top of the 
screen equals the pattern length in that case - you can 
calculate any string length using this function).

3) Press F5.

In the bottom of the screen the pattern chosen will be 
displayed.  If you want to view this pattern in text mode 
press Tab after F5.  Pressing Tab again will switch the 
pattern view into hex mode again.

See Section 5.2.1 for pattern usage information ("Pattern 
Description" paragraph).

6.1.1 SYSTEM DISASSEMBLER

A disassembler is included in AVSP for those users who are 
familiar with Assembler Language.  Using this feature on 
can likely catch onto the technique using which virus 
infected the examined program file.

You can enter the Disassembler routine by pressing Ctrl-D 
keys while in File View mode or from the menu (F10).  The 
Disassembler window with part of the file starting with 
the current position.  Use cursor control keys to move 
over disassembled file.

Note: You cannot move to the point location before the 
current position.  If necessary, press Ctrl-G and set new 
position.

String of disassembled file will correspond to one of the 
following formats:

Offset: File Bytes   Command, or
Offset: File Bytes   Jump Command (Offset:)

Example:
148 : 8E06970B   mov   es,[0B97h]
204 : E8C305     call  05C3h (1682:)

Offset placed in brackets means  that this is most likely 
the address of the command to which transfer of control is 
performed.  If you want to jump to this address you may 
either specify a new value in "Current Position Set" menu 
(Ctrl-G) or place the cursor on jump command and press F7.

The following keys are available in the Disassembler 
routine:

<Ctrl-G>    - to set current position
<F7>        - to trip to address specified in jump command
<Ctrl-B>    - to set Base address
<space bar> - to set Base = current position
<F5>        - to store pattern in memory
<Enter>     - to quit Disassembler and set new current  
              position
<Esc>       - to quit Disassembler retaining the previous  
              current position
<Home>      - to move to disassemble starting position
<F10>       - to access the "File View" main menu

6.2 - ANALYSIS OF CHANGES MODE

You can activate Analysis Of Changes Mode pressing Enter 
with a cursor located on the file you want to examine in 
"Files Changes Analysis" mode.

Information window will be displayed.  It contains basic 
information about the chosen file: file name, file type, 
file attributes, amount of viruses found, file size 
(previously stored and current), map of changes in the 
file.  The most important feature is the last one - map of 
changes in the file.  The file is displayed as a couple of 
coloured blocked.  You can find out current state of file 
by the colour of the blocks:

    Blue        - block was not changed
    Red         - block was changed
    Transparent - there was no such block in the file  
                  before

Using this map you can understand what has happened to 
your file.

Example:
If the first block of *.COM file was changed and at the 
same time at the end of it some new block appeared - this 
file was probably infected by a virus.

To quit Analysis Of Changes mode press Esc.

There is a menu available in Analysis Of Changes mode.  To 
enter it press either F10 or Enter.  Press Esc to quit 
menu.

Menu offers you the following items:

Recover File
Overwrite File
Delete File
Rename File
View File
Change Data
Display Information About Viruses

RECOVER FILE

If your file was damaged by a virus known to our system 
and AVSP possess curing procedure this file can be 
recovered.  The new map of changes will be displayed after 
the operation is complete.

OVERWRITE FILE

Allows you to copy a file from some source drive.  Use 
his option during curing procedure debugging and for 
damaged file recovery.  The new map of changes will be 
displayed after the operation is complete.

DELETE FILE

Allows you to delete damaged files from the current 
directory.  Useful if the file is impossible for some 
reason.

RENAME FILE

Allows to rename a file or to move it within the logical    
disk the file is situated on.

VIEW FILE

This mode allows you to view the file contents, write 
curing procedure, disassemble your file, compare it to any 
other file, etc.  See Paragraph 6.1 for more details.

CHANGE DATA

If changes in the file are reasonable (for example they 
were made by you) you can same new data in DISKDATA.DTL 
file.

DISPLAY INFORMATION ABOUT VIRUSES

If during file examination viruses were found choose this 
option to get these viruses listed.  You can easily get 
information on any virus from that list (just press 
Enter).


For more information contact:

Planning Works International (PWI)
6665 Huntley Road
Suite K
Columbus, OH  43229
voice (614) 436-5300
fax   (614) 436-7108
CompuServe 70544,3632


