Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > other software & services
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 22nd, 2005, 09:15 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default ADinf32

The purpose of this thread is to give you some info about ADinf32.

ADinf means Advanced Diskinfoscope.

The site:
http://www.adinf.com/

You might like to consider ADinf32 as a file integrity checker.
It will build up a database (table) of the files on your system.
It will warn you about file changes, new added files, and deleted files.

ADinf comes in several versions.
ADinf for DOS.
ADinf32.
ADinf32 Pro.

This thread is about ADinf32 (for Windows).

ADinf32 and ADinf32 Pro are not free.

The main difference between ADinf32 and ADinf32 Pro is that the Pro version can use a stronger HASH algorithm: LAN64.
  #2  
Old March 22nd, 2005, 09:24 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

I will try to give you an impression of ADinf32 by giving several screenshots of the program.

Please keep in mind :
Screenshots are taking from a Windows 98 SE system.
The Windows version is a Dutch version, so a few lines might be in Dutch.
I have edited out several private parts in those screenshots.
  #3  
Old March 22nd, 2005, 09:32 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

As for any advanced program, there are lots of settings that you can change.

It is all up to you which settings you like.

In the screenshots some settings are the default settings, some are changed.
  #4  
Old March 22nd, 2005, 09:34 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Of course the Helpfile gives you also lots of information.
  #5  
Old March 22nd, 2005, 09:37 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

OK, here we go.

I start ADinf32 manually and get the following screen
Attached Images
 
  #6  
Old March 22nd, 2005, 09:39 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Clicking OK gives this
Attached Images
 
  #7  
Old March 22nd, 2005, 09:49 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Before I let ADinf32 scan my system, I would like to give you some screenshots about its settings.

So for the purpose of this learning thread I click Options.

I get the following screen.

Note:
The Dutch words "Eigenschappen voor" are in English "Properties for"
Attached Images
 
  #8  
Old March 22nd, 2005, 09:59 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

I click the Properties button to give you an impression about the available settings.

I get this screen.

Again: I would like to warn you that I have edited out several parts in all the following screenshots.
Attached Images
 
  #9  
Old March 22nd, 2005, 10:06 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Now I am going to give you screenshots of all those available options.

This one is for the settings of :
which file types you want ADinf32 to check for,
and which HASH algorithm it will use.
Attached Images
 
  #10  
Old March 22nd, 2005, 10:20 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Here comes the menu for the drives settings.

A very important option is: Drive Acces Type

As you see, I have chosen BIOS Call on my W 98 SE machine.

This is one of the most important parts of ADinf32 !!!

Here are coming quotes from the Helpfile:

Disk Access Methods

ADinf32 checks a drive by reading disk sectors and parsing its file system. There are several ways to read disk sectors referred to as disk access methods. A brief explanation of the existing methods is given below.

Windows 95/98 and OSR2 offer three access methods:

· Access via BIOS
This is the fastest and most reliable method used by default for the majority of drives. Disk sectors are read by direct calls to BIOS virtual image for Windows’95 16-bit tasks.
· Access via Int13h
Sectors are read via the 13h interruption. This method is used when a disk cannot be accessed via BIOS.
· Access via VWIN32
The sectors are read through calls to vwin32 virtual driver that provides 32-bit applications with an interface for direct access to logical drive sectors. This method can be used to access compressed drives or drives that, for some reason, cannot be accessed via BIOS or Int13h.

Under Windows NT ADinf32 supports two access methods:

· Physical Drive Access
Disk sectors are read via calls to a physical disk driver. This method is the fastest and most reliable. It is used by default for the majority of drives.
· Logical Drive Access
Disk sectors are read via calls to a logical disk driver. This method is used when a disk cannot be accessed as Physical Drive.

Notes.

1.*To perform disk scan under Windows NT, you must have the Administrator’s privilege.

2.*ADinf32 sets optimal access methods for logical drives. Change these settings only if a drive cannot be accessed via the default method.

=== end quotes ===
Attached Images
 
  #11  
Old March 22nd, 2005, 10:22 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The menu for the exclusions:
Attached Images
 
  #12  
Old March 22nd, 2005, 10:27 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The menu for so-called stable files.

Any change in files marked as Stable, are treated as suspicious.
Attached Images
 
  #13  
Old March 22nd, 2005, 10:29 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The menu for more common settings
Attached Images
 
  #14  
Old March 22nd, 2005, 10:37 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The menu for your log settings.

I myself move my logs manually to another place where I give them a date, and -depending on how important the changes were- some more info.
Attached Images
 
  #15  
Old March 22nd, 2005, 10:39 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The type of Analysis I want ADinf32 to perform.
Attached Images
 
  #16  
Old March 22nd, 2005, 10:43 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The menu where you can tell ADinf32 to cooperate with an Anti-Virus program.
Attached Images
 
  #17  
Old March 22nd, 2005, 10:47 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Well, so far I have shown you the menus where you can set up your ADinf32.

Now I am going back to the actual scanning.

Here is a screenshot of ADinf32 doing its scanning.
Attached Images
 
  #18  
Old March 22nd, 2005, 10:53 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The scanning is ready.

ADinf32 pops up with a warning that there might be a virus.

Well, I knew that there wasn't a virus, but it gives you an impression of a warning.

As with all these kind of scanners:
It is the user who has to decide whether a change is legit or not !!!
Attached Images
 
  #19  
Old March 22nd, 2005, 10:57 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Now I click away that previous screen, and I get the main summary info window of ADinf32 after its scanning.
Attached Images
 
  #20  
Old March 22nd, 2005, 11:11 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

Now I want to see the changes, so I click All.

Part of the screen is shown in the following screenshot.
Some parts are edited out by me (I told you before that I would do that).

You see two files marked with a red !.
Those are the files that ADinf32 warned me about.
Both files are Outlook Express folders.
I knew already that there was nothing wrong with them.
But once again: as with all these kind of scanners, it is the user who has to decide whether a change is legit or not.

BTW: the Dutch word "verzonden" is in English "sent".
Attached Images
 
  #21  
Old March 22nd, 2005, 11:21 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

OK, let's say I want to have more info about that changed OE file "Verzonden items.dbx"
(sent items in English).

I right click on it and get a new window.
Attached Images
 
  #22  
Old March 22nd, 2005, 11:23 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

The changes info tab for it:
Attached Images
 
  #23  
Old March 22nd, 2005, 11:25 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

And the Warning tab for it.
Attached Images
 
  #24  
Old March 22nd, 2005, 11:36 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

I could go on with other examples about file changes (changed files, new added files, deleted files).
But once you know how things work for different programs, you will be quite familiar with changes.
  #25  
Old March 22nd, 2005, 11:38 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,799
Default Re: ADinf32

OK, I have seen all changes.
So now it is time to exit it.

I get this screen
Attached Images
 
 

Wilders Security Forums > Software, Hardware and General Services > other software & services « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:33 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums