Anti-Virus Scan Tool Procedures version 201407
Introduction Introduction We have experienced an increasing customer concern relating to IT security in general leading to a demand for virus scanning of RADIOMETER analyzers. According to our warranty and service policy it is not permitted to install third party anti-virus software on RADIOMETER analyzers as it may influence analyzer performance or stability. We have therefore developed an Anti-Virus Scan Tool for RADIOMETER analyzers. Purpose The purpose of this tool is to enable a virus scan on a RADIOMETER analyzer in case it is suspected that it may be infected, e.g. in case it has become slow, acts strangely, or crashes or reboots sporadically, or upon customer request. The tool: Runs from an external USB stick and scans the CF-card or hard disk for malware, virus and any other unwanted code. Requires the analyzer application software and Windows XPE to be shut down prior to execution. Detects malware, virus and unwanted code, but it does not remove it. Depending on type CF-card or HDD must be replaced if virus is found. The Anti-Virus Scan Tool is intended for use by RADIOMETER representatives only. Do not make the tool available for customers. Which Analyzers Currently the RMED Anti-Virus Scan Tool may be used on the following analyzers: Analyzer ABL800FLEX and Basic ABL90FLEX AQT90FLEX Analyzer PC Configuration DMS910 only (hence not MB662) UIM2743 and UIM910 UIM2743 and UIM910 The tool requires 1 Gb of memory to run, for which reason it will only run on analyzers/configurations mentioned above. McAfee Runtime License The tool is based on a McAfee product and requires the purchase of a runtime license to use the tool. Ideally, each field service engineer should have a RMED Anti-Virus Scan Tool in the toolbox and it is the subsidiaries/distributors responsibility to acquire and renew the required number of runtime licenses. Update of Virus Database It is important that the virus database incorporated with the tool is updated on a regular basis. For this reason the tool has been setup such that it will not run in case the age of the database has exceeded 3 months. 2
Required Equipment PC running Windows 7 or higher, with o Internet access o Updated anti-virus software Windows7 USB DVD Download Tool USB 2.0 stick >= 2Gb McAfee runtime license RMED Anti-Virus Tool, 933-326 3
Anti-Virus Scanning Procedure Purpose This paragraph describes how to perform a virus scan on an analyzer. As it appears from the description below it is a six step procedure. 1. Update the virus database on the USB stick 2. Disconnect the analyzer from the IT network 3. Change the boot sequence of the analyzer 4. Perform the anti-virus scanning 5. Reset the boot sequence to the standard setting 6. Reconnect the analyzer to the IT network The anti-virus scanning process lasts up to one hour. Please note that the sensors in ABL90 are not conditioned during this time. Update Virus Database Please note the Anti-Virus Scan Tool will only run if the virus database has been updated less than three months ago. Please refer to the procedure for updating the virus database. Disconnect the Analyzer from the IT Network If the analyzer is connected to an IT network, make sure it is now disconnected. That is: Pull out the network cable (LAN), or Remove the WiFi network adapter (WLAN). Change Boot Sequence The analyzer needs to boot from the USB stick with the Anti-Virus Scan Tool to perform the anti-virus scanning. Therefore the boot sequence in the BIOS setup needs to be changed. Please refer to the individual service manuals for procedures for changing the boot sequence. The table below gives an overview of the required BIOS setup for running the Anti-Virus Scanning: Analyzer PC Configuration BIOS Setup ABL800 ABL90 / AQT90 ABL90 / AQT90 DMS910 UIM2743 UIM910 First Boot Device: Change to USB-FDD. Hard Disk Boot Priority: USB-FDD must be first item on the list. First Boot Device: Change to USB-HDD. First Boot Device: Change to USB-FDD. Select Enable Other Boot Device and change to Enable 4
Perform Virus Scan 1. Connect the USB stick with the Anti-Virus Scan Tool to one of the USB ports on the rear of the analyzer. The USB port on the front (ABL800 and AQT90) and on the top (ABL90) are not bootable for which reason they cannot be used for this purpose. 2. Reboot the analyzer PC (Ctrl + Alt + Del) to start the virus scanning. During the scanning the following screen appears: 3. When the scanning is complete and no abnormalities are found the message Scan completed, device OK! (on a green background) will be displayed. 4. Disconnect the USB stick. NB! If Virus found on device! (on a red background) is displayed proceed to the last page of this document. Reset Boot Sequence Having completed the anti-virus scanning successfully the boot sequence needs to be reset to the standard setting. Please refer to the individual service manuals for procedures for changing the boot sequence. The table below gives an overview of the required BIOS setup for running the Anti-Virus Scanning: Analyzer PC Configuration BIOS Setup ABL800 ABL90 / AQT90 ABL90 / AQT90 DMS910 UIM2743 UIM910 First Boot Device: Change to Harddisk. First Boot Device: Change to HDD-0. First Boot Device: Change to Hard Disk. Select Enable Other Boot Device and change to Disabled Reconnect the Analyzer to the IT Network If the analyzer was previously disconnected from the IT network, then reconnect. That is: Reconnect the network cable (LAN), or Re-insert the WiFi network adapter (WLAN). 5
Virus Database Update Purpose The procedure describes how to update the virus database of the Anti-Virus Scan Tool. What Happens if the Virus Database is not Updated? The Anti-Virus Scanning will not run if age of the virus database exceeds three months. If an anti-virus scanning is attempted the following screen is displayed: Update Anti-Virus Database This procedure describes how to update the virus database of the Anti-Virus Scan Tool. Once started the procedure runs automatically, hence the updated virus database is downloaded, installed, and verified. 1. Connect the USB stick with the Anti-Virus Scan Tool to a PC, which: a. Runs an updated virus protection software and hence is free from malware, virus or any other unwanted code b. Has access to the internet 2. Browse the USB stick with the Anti-Virus Scan Tool to locate the script file update_avdatabase.cmd found in the RMED folder. 3. Run the script file from a command prompt or Windows Explorer. The following screen appears: 4. Wait for the database download to complete. The database will be installed and verified automatically. 5. Upon completion of the update the following screen is displayed: 6. Disconnect the USB stick from the PC. It is now ready for use. 6
Creating a Bootable USB Stick Purpose This paragraph describes how to download the required tools and create a bootable USB stick including the RMED Anti-Virus Scan Tool. Purchase McAfee Runtime Licenses As mentioned above a Runtime License for the McAfee product is required for using the Anti-Virus Scan Tool. The license required is for: McAfee Endpoint Protection Suite (EPS) You may read about the product here: http://www.mcafee.com/hk/products/endpoint-protection/endpoint-protection-suites.aspx 1. Determine how many licenses are required and then purchase as suggested in the table below. Your location Within the EU Outside the EU How to purchase Send an email with the order to the following address: license.dk@crayon.com Go to the following web address: http://www.mcafee.com/uk/purchase.aspx 2. Having purchased and received the grant number(s), go to www.mcafee.com under Support, then Downloads & Support to register the grant number(s). 3. Download the product. Download Remaining Tools 4. Obtain the Windows7 USB DVD Download Tool. Go to: http://www.microsoftstore.com/store/msusa/html/pbpage.help_win7_usbdv d_dwntool#installation and then download the Windows7 USB DVD Download Tool. 5. Obtain the Windows MD5 Utility Tool. Go to: http://www.winmd5.com/ and then download the Windows MD5 Utility Tool. 6. Download the RMED AVScan iso file as well as the RMED AVScan md5 file from RMED and save it on your PC (a separate e-mail including a download link was distributed at the time of the release of the tool). 7
Create a Bootable USB Stick 7. Start the Windows MD5 Utility Tool. The following screen appears: 8. Click Browse to locate the RMED AVScan iso file and then double-click on the file. The program starts to compute the MD5 checksum value on the file downloaded from RMED. The value will be displayed in the Current file MD5 checksum value field. 9. Open the RMED AVScan md5 file and copy the checksum. 10. Switch to the Windows MD5 Utility Tool, paste the checksum into the Original file MD5 checksum value field and click Verify when the Current file MD5 checksum value is displayed. The program will now compare the original MD5 checksum value with the one just computed. 11. Verify that the program concludes that the two checksum values match, which is indicated by the following: It has now been verified that the original and the downloaded files are identical and you can continue the process. 12. Click OK and shut down the program. 13. Insert the USB stick into a USB port on the PC. 8
14. Start the Windows7 USB DVD Download Tool. The following screen appears: 15. Click Browse to locate the RMED AVScan iso file and then double-click on the file. 16. Click Next. The following screen appears: 17. Click USB device. 18. Click Next. The following screen appears: 19. Select the USB stick from the drop-down menu and click Begin copying. Please note that the current contents of the USB stick will be erased during this process. 20. Click Erase USB Device and then Yes. The program now creates a bootable USB stick containing the RMED AVScan installation files. 21. When Bootable USB device created successfully is displayed close the program. 9
22. Verify that the folders and files listed below are found on the USB stick is (the dates may be different): 23. Disconnect the USB stick. The bootable USB stick has now been created including the Anti-Virus Scan Tool. 24. Proceed to Virus Database Update to ensure that the tool has the latest database. 25. Upon update the tool is ready for an Anti-Virus scan of an analyzer. 10
What to do if Virus is Found Purpose This procedure describes what to in case malware, virus or any other unwanted code is found on an analyzer. It is important to mention that the tool detects the malware, virus or any other unwanted code, but it does NOT remove the infection. What happens if Virus is Found? The following screen appears in case the Anti-Virus Scan Tool finds malware, virus or any other unwanted code on the analyzer: What to do on the Analyzer? The following procedure applies in case malware, virus or any other unwanted code is found on the analyzer: 1. Switch the analyzer off and disconnect the USB stick with the Anti-Virus Scan Tool. 2. Remove the device containing the Windows installation (CF-card or HDD). 3. Install a brand new CF-card or HDD in the analyzer and perform a complete software installation. DO NOT: Install back-up files and restore set-up from a file Re-install software on the existing CF-card or HDD. What to do with the infected CF-card or HDD? The infected device must be returned to RMED for investigation. 1. Raise a TechLine TM case and escalate to RMED. 2. Return the CF-card or HDD to RMED with reference to the TechLine number. Inform the customer In case malware, virus or any other unwanted code is found on the analyzer the customer must be informed to ensure that other devices on the network are scanned as well. 11