                        Updates to F-PROT

The F-PROT package will need to be updated in the future, mostly because
new viruses will continue to appear.  I also expect to improve the
programs in the package - making them easier to use and more powerful.

When a new virus appears, several programs need to be changed:

                F-DRIVER.SYS
                F-DISINF.EXE or F-FCHK.EXE
                F-SYSCHK.EXE

If you look at the file SIGN.TXT, you will see that it contains one line
of text for each virus.  This line contains an encrypted signature string,
with checksums and some additional information.  When a new virus appears,
one line must be added to this file.  That will enable F-DISINF, F-FCHK and
F-SYSCHK to detect the virus.

Since the encryption algorithm must remain a secret, I will have to
provide this line, at least for the time being.  This line will be
instantly (well - as soon as I obtain a copy of the virus) distributed
on comp.virus (on USENET) and the VIRUS-L mailing list (on BITNET).

The programs will not be able to remove the virus unless they are modified,
and some changes must also be made to the F-DRIVER.SYS program so it can
stop new program viruses.  (It should be able to stop any new boot sector
virus, however.)

I will put new versions of the F-PROT package on SIMTEL as soon as they are
finished.  The package will (I hope) also appear (irregularly) on
comp.binaries.ibm.pc (on USENET).  A number of Bulletin Board Systems and
FTP sites will also make the package available.

You can either obtain new versions from one of those sources or directly
from the author if you are a registered user.

To obtain an update later, just use one of the sources mentioned above
or send me a blank, formatted diskette + $5 (to cover postage and
handling).

If you would like automatic updates as soon as new viruses appear, please
contact me for details (see AUTHOR.TXT).

