Probably the most interesting function of Virus Boot Detector. This function tries to analyse the current bootblock using an 'Expert System' method. First, Virus Boot Detector displays the total length of boot, the length of code and the length of data. Then it tries to analyse data and code in the boot and display actions that it finds (if there is any) and the offset where VBD found it.
Then, Virus Boot Detector calculates the different probabilities that the boot is a virus, a virus protector, a loader, a utility bootblock, an intro, or a harmless bootblock, and displays its results with a histogram.
This analysis function comes to the right conclusion in 901f cases. The diagnostic can be altered or simply wrong by a miss of informations bootblock, or simply if the virus creator has included analysis protection in his virus (encrypted viruses, useless functions, no direct vectors captured...).