From mramey@u.washington.edu Tue Sep 3 11:07:28 1996 Received: from saul7.u.washington.edu by lists.u.washington.edu (5.65+UW96.06/UW-NDC Revision: 2.33 ) id AA39432; Tue, 3 Sep 96 11:07:27 -0700 Received: from localhost by saul7.u.washington.edu (5.65+UW96.08/UW-NDC Revision: 2.33 ) id AA13906; Tue, 3 Sep 96 11:06:58 -0700 Date: Tue, 3 Sep 1996 11:06:58 -0700 (PDT) From: 'Mike' M Ramey Reply-To: 'Mike' M Ramey To: CIVE Faculty email list , CIVE Staff email list , CIVE Students List -- CIVE Grad Students List , CIVE Undergrad Students List Subject: F-PROT 2.24 problems ... Message-Id: Mime-Version: 1.0 Content-Type: MULTIPART/MIXED; BOUNDARY="0-772625358-841773409=:12136" Content-Id: This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. Send mail to mime@docserver.cac.washington.edu for more info. --0-772625358-841773409=:12136 Content-Type: TEXT/PLAIN; CHARSET=US-ASCII Content-ID: --0-772625358-841773409=:12136 Content-Type: MULTIPART/DIGEST; BOUNDARY="0-260536207-841773409=:12136" Content-ID: Content-Description: Digest of 4 messages This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. Send mail to mime@docserver.cac.washington.edu for more info. --0-260536207-841773409=:12136 Content-Type: MESSAGE/RFC822 Content-ID: Content-Description: F-PROT 2.24b problems. (fwd) Date: Sat, 31 Aug 1996 10:42:34 -0700 (PDT) From: 'Mike' M Ramey To: F-PROT Vesselin Bontchev Subject: F-PROT 2.24b problems. Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Vess - First, thanks for the work of everyone at Frisk Software International to improve the F-PROT programs! Thanks also for providing automatic email notification of new versions of F-PROT. This will be a great help to users, and ensure that they always have the latest version. The documents VIRUS.DOC, SCAN.DOC, NEW_VIR.DOC, and ANALYSE.DOC are excellent introductions to the topic! VIRUS.DOC has been greatly improved since the last time I read it. I hope you will grant me permission to use these files in anti-virus education here on the University of Washington campus -- with full credit to Frisk, of course. ---------------------------------------------------------------------- In VIRUS.DOC: Please add to your description of Boot Sector Viruses that even "non-bootable data diskettes" can be infected with Boot Sector Viruses and will infect the computer's hard disk if they are in the A: drive when the machine is rebooted (unless special precautions are taken, such as changing the CMOS boot sequence, or using VIRSTOP). If the "non-bootable" diskette is infected with a BSV, the hard disk will be infected *before* you see the messages: Non-system disk or disk error. Replace and press any key when ready. [ perhaps I'm wrong on this point; see below. ] In VIRUS.DOC insert two words in the following: "Program viruses, the second type of computer viruses, infect executable programs, usually .COM and .EXE files, but +they+ sometimes also +infect+ overlay files, device drivers or even object files." In VIRUS.DOC: "Reading data from an infected diskette cannot cause an infection." but in the next paragraph: "... just by the act of reading an infected Microsoft Word document..." [actually 'processing' that document with the Word or Excel program]. ??? In VIRUS.DOC: .... Not a system disk. .... but may not have infected the hard disk yet. [ I didn't know this was possible. ] add: .... turn the computer off +and remove the diskette from the A: drive+ In VIRUS.DOC at the end add: "And be sure to update your anti-virus software regularly. New viruses appear at the rate of ... and an outdated anti-virus program may not detect new viruses." [ Choose wording carefully so it doesn't give comfort to Zvi! ] ====================================================================== Yesterday I tried installing FP-2.24b (from your /betas directory at Frisk's suggestion) in my computer lab. Here's what I discovered. ====================================================================== VIRSTOP.DOC paragraph 2 says: Virstop may cause compatibility problems when run under Windows. In most cases, switching to the VIRSTOP2 program will fix those problems. Please describe what kind of problems. What will the user see? I had serious problems with F-MACRO.EXE, but when I switched from VIRSTOP to VIRSTOP2, I found other equally serious problems. Vague descriptions of problems are not helpful to users. ---------------------------------------------------------------------- F-MACROW.EXE ============ F-MACROW worked fine on a couple of machines, but on a third computer running F-MACROW.EXE caused 4 of the 6 icons in the Main group to be *seriously* damaged; only small squiggles remained. If I moved the F-MACROW window while the program was running, this damage was already visible. The next time I tried to start Windows, I got the message: ! Program-group file 'C:\WINDOWS\MAIN.GRP' is invalid or damaged. Recreate the group. [OK] When I clicked [OK], Windows restarted without the Main group. ----------------------------------------------------------------- F-MACROW also caused the following error messages: PROGMAN An error has occurred in your application. If you choose Ignore, you should save your work in a new file. If you choose Close, your application will terminate. [Close] [Ignore] If I moved the F-MACROW window while the program was running, this error message was already visible Clicking [Ignore] returned to this same message; no change. Clicking [Close] gave the following error: Application Error PROGMAN caused a General Protection Fault in module PROGMAN.EXE at 0002:0651 [Close] Clicking [Close] gave me a totally grey screen and froze the computer; no response from mouse or keyboard. Pressing CTL-ALT-DEL twice caused the computer to reboot. ---------------------------------------------------------------------- I installed F-MACROW in the C:\V_FPROT\ directory, following the instructions in the F-MACROW.DOC file. When creating the icon for F-MACROW, the Working Directory is automatically set to C:\V_FPROT, which causes the program to fail with a message about CTL3DV2.DLL (or OLE2.DLL ?) not being correctly installed. If I change the Working Directory to empty/blank/null, the program runs. I don't know if there is any way for you to change this. If not, you could add a note to the installation instructions. I set the icon Description: to "Word/Excel Macro-Virus Scanner". ---------------------------------------------------------------------- I want to configure F-MACROW on all lab computers the same way: Scan directory - C:\ Scan - All files Scan subdirectories Ask each time Report file - C:\USER\F-MACROW.REP Append to Can I install a pre-configured C:\WINDOWS\F-MACROW.INI file along with the other program files to accomplish this? It seems reasonable, but with all the problems I had, I don't know what works and what doesn't. ---------------------------------------------------------------------- When I scanned a group of files known to be infected with Concept.A virus, the F-MACROW.REP file shows one line for each infected file (indicating each one has been disinfected), and ends with: Results of virus scanning: Scanned: 6 Infected: 5 Time: 00:10 There is no indication - in this summary - that the files have been disinfected -- which they have. Please indicate the number of files disinfected (and the number still infected!) in the summary info. ---------------------------------------------------------------------- The only way to know if F-MACROW has finished is to look at the timer in the lower right-hand corner and see if it is counting. It would be helpful if a 'run-finished' block came on the screen (like in F-PROT), possibly containing summary information about the number of files scanned, infected, and disinfected (see above). Grey for 'All-OK' and red for 'You-got-problems' (like F-PROT). ---------------------------------------------------------------------- VIRSTOP and VIRSTOP2 ==================== I was using: :: rem AUTOEXEC.BAT file ... LH ... VIRSTOP /BOOT /COPY /FREEZE /WARM When I switched from VIRSTOP to VIRSTOP2, the problems with F-MACROW described above went away. But I found a whole new set of problems with VIRSTOP2. ---------------------------------------------------------------------- When VIRSTOP2 loads (as above), I get the messages: Enabling boot sector scanning. Enabling file scan on access. Enabling Ctrl-Alt_Del boot sector scanning. VIRSTOP2 version 2.24a now installed. This is very good documentation for the user. Thank you. Unfortunately, this message is *not* shown on the printer when I use to obtain a hard-copy record of the boot process! Please use standard DOS calls (rather than direct to screen?) for all screen messages from VIRSTOPx, F-TEST, and F-PROT (command-line mode). The VIRSTOP program *does* display its output to the printer when is in effect: VIRSTOP version 2.24a now installed. ---------------------------------------------------------------------- When VIRSTOP2 is loaded: LH ... VIRSTOP /BOOT /COPY /FREEZE /WARM and the computer is rebooted by pressing , VIRSTOP2 does ***NOT*** check drive A: for an infected diskette !!! This is a major failure, and renders VIRSTOP2 unusable in my labs. It does not display the message "...Virus-checking A:", which was the first clue I had it was not working. ---------------------------------------------------------------------- With VIRSTOP2 loaded, F-TEST returns a non-zero DOS 'exit code'. This is different from the results with VIRSTOP, and results in display of a virus-warning message in my AUTOEXEC.BAT file. VIRSTOP2 should give the same 'exit codes' as the VIRSTOP program. ---------------------------------------------------------------------- With the old VIRSTOP loaded, entering the VIRSTOP command again gives a detailed report of VIRSTOP status. But with the new VIRSTOP2 loaded, entering the VIRSTOP2 command again gives only the message "VIRSTOP is already installed". Although VIRSTOP2 displays detailed status information when it loads (from AUTOEXEC.BAT [or CONFIG.SYS?]), it is very useful to be able to see this information at any time (after AUTOEXEC.BAT is finished). Please restore this function to VIRSTOP2. ---------------------------------------------------------------------- The command: 'VIRSTOP2 /?' gives the following output: VIRSTOP is already installed VIRSTOP2 supports the following command-line switches: /OLD Do not produce a warning message even if the program is considered to be too old. /BELL Sound an alarm when a virus is found. /KEY Do not sound an alarm when a virus is found. /FREEZE Stop the computer when a virus is found. /[NO]COPY [Do not] check files when they are accessed/copied. /[NO]BOOT [Do not] check boot sectors when a diskette is accessed. - What are the default settings for these switches? - How is '/KEY' different from 'NOBELL'? What does /KEY mean? - What about the old '/DISK', '/NOMEM' and '/[NO]WARM' switches? What are their settings in the VIRSTOP2 program? ---------------------------------------------------------------------- Are the viruses listed in F-MACROW.DOC *detected* (even tho' they might not be *removed*) by F-PROT 2.24 ??? This is important, because it determines whether F-PROT is an adequate *scanning* tool for macro viruses. If so, then users would need F-MACROW only for *removing* macro viruses (after they had been detected by F-PROT). This would also mean that a daily scan by F-PROT is an adequate scanning check. If not, then *both* F-PROT and F-MACROW must be run to guarantee a clean hard disk. This would be a real pain! ---------------------------------------------------------------------- Please keep me posted. Thanks very much, --Mike Ramey --0-260536207-841773409=:12136 Content-Type: MESSAGE/RFC822 Content-ID: Content-Description: Re: F-MACROW; scan *all* local [fixed] disks ? (fwd) From: bontchev@complex.is (Vesselin Bontchev) Subject: Re: F-MACROW; scan *all* local [fixed] disks ? To: mramey@u.washington.edu ('Mike' M Ramey) Date: Mon, 2 Sep 1996 13:33:30 +0000 (GMT) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit > Please add an option to F-MACROW to scan *all* local [fixed] disks This is on our "to-do" list. A future version of the program will be able to scan also a list of paths specified in the config file. However, I don't know when exactly we'll implement this. I got your other (long) bug report; I will examine it in detail later and will send you a separate reply. Regards, Vesselin -- Vesselin Vladimirov Bontchev, not speaking for FRISK Software International, Postholf 7180, IS-127, Reykjavik, Iceland producers of F-PROT. e-mail: bontchev@complex.is, tel.: +354-561-7273, fax: +354-561-7274 PGP 2.6.2i key fingerprint: E5 FB 30 0C D4 AA AB 44 E5 F7 C3 18 EA 2B AE 4E --0-260536207-841773409=:12136 Content-Type: MESSAGE/RFC822 Content-ID: Content-Description: Re: F-PROT 2.24b problems. (fwd) Return-Path: Received: from mx4.u.washington.edu by saulfs01.u.washington.edu (5.65+UW96.08/UW-NDC Revision: 2.33 ) id AA10829; Mon, 2 Sep 96 13:09:14 -0700 Received: from melona.complex.is (melona.complex.is [193.4.210.100]) by mx4.u.washington.edu (8.7.5+UW96.08/8.7.3+UW96.08) with ESMTP id NAA11540 for ; Mon, 2 Sep 1996 13:09:11 -0700 Received: by melona.complex.is (8.7.5/ISnet/09-july-95); Mon, 2 Sep 1996 20:09:09 GMT From: bontchev@complex.is (Vesselin Bontchev) Message-Id: <199609022009.UAA01297@melona.complex.is> Subject: Re: F-PROT 2.24b problems. To: mramey@u.washington.edu ('Mike' M Ramey) Date: Mon, 2 Sep 1996 20:09:09 +0000 (GMT) In-Reply-To: from "'Mike' M Ramey" at Aug 31, 96 10:42:34 am Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit > In VIRUS.DOC: > Please add to your description of Boot Sector Viruses that even Right now we're too busy fixing more important things; I don't believe that we'll have the time for minor documentation fixes before we publish the new release. > VIRSTOP.DOC paragraph 2 says: > > Virstop may cause compatibility problems when run under Windows. > In most cases, switching to the VIRSTOP2 program will fix those > problems. > > Please describe what kind of problems. What will the user see? I had System crashes and unpredictable behaviour of *some* programs. It is difficult to describe the unpredictable. :-) VirStop does really attrocious (IMHO) things to memory it doesn't own - which is bound to cause all sorts of problems especially in multitaskers like Windoze. Can't give any particular examples, sorry. > F-MACROW worked fine on a couple of machines, but on a third computer > running F-MACROW.EXE caused 4 of the 6 icons in the Main group to be > *seriously* damaged; only small squiggles remained. If I moved the > F-MACROW window while the program was running, this damage was already > visible. The next time I tried to start Windows, I got the message: > > ! Program-group file 'C:\WINDOWS\MAIN.GRP' is invalid or > damaged. Recreate the group. Could not reproduce this problem, sorry. > If I moved the F-MACROW window while the program was running, this > error message was already visible Neither this one. It moves perfectly here (although, of course, the scanning stops while the window is being moved). > I installed F-MACROW in the C:\V_FPROT\ directory, following the > instructions in the F-MACROW.DOC file. When creating the icon for > F-MACROW, the Working Directory is automatically set to C:\V_FPROT, > which causes the program to fail with a message about CTL3DV2.DLL (or > OLE2.DLL ?) not being correctly installed. If I change the Working > Directory to empty/blank/null, the program runs. I don't know if there > is any way for you to change this. If not, you could add a note to the > installation instructions. The part which is really missing from the documentation (simply because I didn't know it when I wrote the documentation) is that you MUST NOT keep a copy of the DLL in the same directory where F-MACROW.EXE resides. The place of the DLL is in the SYSTEM directory. Delete it from F-MACROW's directory and all will be fine, regardless of whether you have explicitely set the working directory or not. (However, the MACRO.DEF file should be either in what you have set as "working directory" or in the directory where F-MACROW.EXE is, if you have left the "working directory" field blank. > I want to configure F-MACROW on all lab computers the same way: > > Scan directory - C:\ > Scan - All files > Scan subdirectories > Ask each time > Report file - C:\USER\F-MACROW.REP > Append to > > Can I install a pre-configured C:\WINDOWS\F-MACROW.INI file along with > the other program files to accomplish this? Yes, you can. > When I scanned a group of files known to be infected with Concept.A > virus, the F-MACROW.REP file shows one line for each infected file > (indicating each one has been disinfected), and ends with: > > Results of virus scanning: > Scanned: 6 > Infected: 5 > Time: 00:10 Cannot confirm this. Here the number of infected files was the same as the number of scanned files - provided that all files in the path being scanned were infected, of course. > > There is no indication - in this summary - that the files have been > disinfected -- which they have. Please indicate the number of files > disinfected (and the number still infected!) in the summary info. Will do, although it might not make it in the next release which is supposed to be this week. > The only way to know if F-MACROW has finished is to look at the timer > in the lower right-hand corner and see if it is counting. There is another way: the word "Done" appears after "Scanning:" on the line beneath the buttons. > It would be helpful if a 'run-finished' block came on the screen (like > in F-PROT), possibly containing summary information about the number > of files scanned, infected, and disinfected (see above). Grey for > 'All-OK' and red for 'You-got-problems' (like F-PROT). I'lll think about it when/if we begin rewriting the user interface of F-MACROW. We disagree with Frisk on the subject whether this should be done. I have made a nice design full of features while he's not convinced that F-MACROW was that a good idea after all and is reluctant to spend much efforts on developing it. > When I switched from VIRSTOP to VIRSTOP2, the problems with F-MACROW > described above went away. Then they were not problems in F-MACROW but in VirStop. > When VIRSTOP2 loads (as above), I get the messages: > > Enabling boot sector scanning. > Enabling file scan on access. > Enabling Ctrl-Alt_Del boot sector scanning. > VIRSTOP2 version 2.24a now installed. > > This is very good documentation for the user. Thank you. > Unfortunately, this message is *not* shown on the printer when I use > to obtain a hard-copy record of the boot process! > Please use standard DOS calls (rather than direct to screen?) for all > screen messages from VIRSTOPx, F-TEST, and F-PROT (command-line mode). I talked with Frisk about this. He sounded annoyed and said that there has been a good reason why he has decided to use BIOS screen output instead of DOS functions, that he doesn't remember what the reason was, and that he doesn't intend to waste his time on changing it. Sorry. > When VIRSTOP2 is loaded: > LH ... VIRSTOP /BOOT /COPY /FREEZE /WARM > and the computer is rebooted by pressing , > VIRSTOP2 does ***NOT*** check drive A: for an infected diskette !!! According to Frisk, VirStop2 does not support the /WARM switch yet. > With VIRSTOP2 loaded, F-TEST returns a non-zero DOS 'exit code'. This > is different from the results with VIRSTOP, and results in display of > a virus-warning message in my AUTOEXEC.BAT file. VIRSTOP2 should give > the same 'exit codes' as the VIRSTOP program. VirStop2 does not support F-TEST at all. We thought that since it supports the EICAR Test File, supporting F-TEST is not necessary. But Frisk said that such a support can be easily added and that he'll probably do it, when he gets the time. > VIRSTOP2 supports the following command-line switches: > /OLD Do not produce a warning message even if > the program is considered to be too old. > /BELL Sound an alarm when a virus is found. > /KEY Do not sound an alarm when a virus is found. > /FREEZE Stop the computer when a virus is found. > /[NO]COPY [Do not] check files when they are accessed/copied. > /[NO]BOOT [Do not] check boot sectors when a diskette is accessed. > > - How is '/KEY' different from 'NOBELL'? What does /KEY mean? There is no NOBELL switch. The /KEY switch means "if a virus is found, report this and wait for the user to press a key". > - What about the old '/DISK', '/NOMEM' and '/[NO]WARM' switches? > What are their settings in the VIRSTOP2 program? They are not supported by VirStop2 yet. We're working on it. In particular, the current VirStop2 does not scan the memory for viruses at all and crashes if loaded as a device driver from CONFIG.SYS (loading it from AUTOEXEC.BAT works fine). > Are the viruses listed in F-MACROW.DOC *detected* (even tho' they might > not be *removed*) by F-PROT 2.24 ??? No, they are not. Do *not* use F-PROT for macro virus detection. > This is important, because it determines whether F-PROT is an adequate > *scanning* tool for macro viruses. No, it is not. Even those macro viruses which F-PROT can detect are not detected properly - e.g., there can be ghost positives. In the near future we intend to remove all macro virus support from F-PROT. Use F-MACROW instead. > If so, then users would need F-MACROW only for *removing* macro > viruses (after they had been detected by F-PROT). No, F-MACROW should be used for macro virus scanning as well. It works *much* better than F-PROT in this aspect. > This would also mean that a daily scan by F-PROT is an adequate > scanning check. No, it is not. > If not, then *both* F-PROT and F-MACROW must be run to guarantee a > clean hard disk. Only if you are worried about macro viruses - which means that you're running Windoze. If you want a single Windoze program which can detect both DOS and macro viruses, you'll have to buy the Professional version. Regards, Vesselin -- Vesselin Vladimirov Bontchev, not speaking for FRISK Software International, Postholf 7180, IS-127, Reykjavik, Iceland producers of F-PROT. e-mail: bontchev@complex.is, tel.: +354-561-7273, fax: +354-561-7274 PGP 2.6.2i key fingerprint: E5 FB 30 0C D4 AA AB 44 E5 F7 C3 18 EA 2B AE 4E --0-260536207-841773409=:12136 Content-Type: MESSAGE/RFC822 Content-ID: Content-Description: Re: F-PROT 2.24b problems. (fwd) Date: Tue, 3 Sep 1996 08:55:21 -0700 (PDT) From: 'Mike' M Ramey To: Vesselin Bontchev Subject: Re: F-PROT 2.24b problems. In-Reply-To: <199609022009.UAA01297@melona.complex.is> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Vess -- Thanks for your detailed reply and your advocacy for improvements to the F-PROT suite of programs. I appreciate your concern for getting macro-virus protection (via F-MACROW) to users quickly, and the priority given to *functional* improvements over documentation changes. The removal of macro-virus *detection* from F-PROT means that users must now use *2* programs to scan (and disinfect) their hard-disk and diskettes; even diskettes can contain a boot- or file-virus *and* a macro-virus. Indeed it is likely that if a diskette has been used in a computer without any virus protection installed (at someone's home), then the diskette would have both boot- and macro-viruses. I believe a single program is all we can expect users to deal with when they want to scan (and disinfect) their computer -- both hard- and floppy-disks. The evaluation version of FindVirus from Dr. Solomon does the whole job with a single program. I hope you will consider adding (at least) macro-virus detection to the F-PROT program; disinfection would be desirable also, of course. See other comments below, one of which I'm including here also, because I feel it is so important: I think requiring users to run *2* programs (on both hard disks and diskettes!) to ensure they are free of virus infections is a serious mistake; users will simply *not* run both programs, and F-PROT now becomes a marginally useful product. I might use it for a 'second opinion', but I cannot recommend it to ordinary users as their primary anti-virus tool -- which I used to do! This saddens me (and inconveniences my users). Thanks again for your help, -Mike Ramey 685-0940 FAX:685-3836 Wilcox-171 Box:352700 UofW 98195 On Mon, 2 Sep 1996, Vesselin Bontchev wrote: > ... > > When I scanned a group of files known to be infected with Concept.A > > virus, the F-MACROW.REP file shows one line for each infected file > > (indicating each one has been disinfected), and ends with: > > > > Results of virus scanning: > > Scanned: 6 > > Infected: 5 > > Time: 00:10 > > Cannot confirm this. Here the number of infected files was the same as > the number of scanned files - provided that all files in the path being > scanned were infected, of course. The problem was not with the file counts (one file was *not* infected); the problem was the absence of any indication that disinfection had been done, and how many files (if any) are *still* infected. -mr > ... > > Are the viruses listed in F-MACROW.DOC *detected* (even tho' they might > > not be *removed*) by F-PROT 2.24 ??? > > No, they are not. Do *not* use F-PROT for macro virus detection. > > > This is important, because it determines whether F-PROT is an adequate > > *scanning* tool for macro viruses. > > No, it is not. Even those macro viruses which F-PROT can detect are not > detected properly - e.g., there can be ghost positives. In the near > future we intend to remove all macro virus support from F-PROT. Use > F-MACROW instead. As I said above, I think requiring users to run *2* programs (on both hard disks and diskettes!) to ensure they are free of virus infections is a serious mistake; users will simply *not* run both programs, and F-PROT now becomes a marginally useful product. I might use it for a 'second opinion', but I cannot recommend it to ordinary users as their primary anti-virus tool -- which I used to do! This saddens me (and inconveniences my users). =end -mr= --0-260536207-841773409=:12136-- --0-772625358-841773409=:12136-- .