This essay will help you in reading
documents and manuals of antivirus
toolkit to learn what you must do
to avoid them, and how far you must
go. Many virus writers waste their
time by overdoing themselves with
antiheuristic tricks and the like.
We are not interested in receiving copies of false alarms that are only reported with /PARANOID, so don't waste your time sending them to us.
This means that, should the user issue the /PARANOID option and is getting false alarms, he is on his own and can't send the samples to Datafellows. So this means trying to avoid /PARANOID is a waste of time, since Datafellows does not want to act on false alarms generated by the /PARANOID switch. Of course you must try to avoid being detected by the /ANALYSE switch at all costs, since this won't generate false alarms quickly, thus exposing your virus a little earlier. Use the /GURU parameter to see what flags your virus triggers so you can write code that avoids the virus being detected.
Cleaning Multiple Files
TbClean has no provisions for cleaning multiple programs in one run. There are two reasons for this omission:
- TbClean cannot search for viruses automatically since it does not know any virus.
- We recommend that you clean the system on a file-by-file basis. Clean one file, verify the result, and go on to the next file. Again, this helps you keep track of which files are clean, which files are damaged and should be restored from a backup, and which files are still infected.