All notable changes to VeraxCore Antivirus will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
- SHA-256 signature database with 65+ built-in signatures
- Byte-pattern scanner with wildcard support
- PE structural analysis engine
- Heuristic scoring engine with configurable thresholds
- Optional cloud hash lookup
- Section removal: 25+ known virus section names
- RWX suspicious section cleanup
- Inflated section trimming (Floxif technique detection)
- Overlay virus body removal with Authenticode certificate preservation
- Smart Entry Point repair (3-case detection)
- CRT startup pattern scanning for real EP discovery
- DLL vs EXE aware prologue restoration
- PE checksum recalculation
- Backup before repair with auto-restore on failure
- Floxif (.A–.H, EC!MTB), Sality, Ramnit, Virut, Neshta
- Mikcer, Parite, Expiro, Mabezat, Viking, Alman
- Generic CodeCave, TrojanDownloader, and more
- AES-256-CBC encryption via Windows BCrypt API
- HWID-derived encryption key
- 3-pass secure delete (zeros → 0xFF → random)
- Full management: restore, permanent delete, view
- Quick Scan, Full Scan, Custom Scan, Folder Scan
- USB auto-scan on device insertion
- Modern glassmorphism UI with dark/light themes
- Multi-language support (English + Arabic)
- System tray with notifications
- Real-time scan progress and threat details
- Portable UserData directory (next to executable)
- SQLite database with JSON fallback
- Rotating log files (5MB, keep 5)
- JSON scan reports
- Online signature updates
- ASLR, DEP, CFG enabled
- Administrator privileges via UAC manifest
- Encrypted quarantine vault
- Secure file deletion