8. THE TRUTH ABOUT FIND FAST
Have you ever wondered what that "Find Fast" program was under your control panel? Here's a hint: It has absolutely nothing to do with the "Find" utility located under the [Start] menu. Just to clear up any confusion before going on, Oblivion adequately explains Find Fast here:
"In any version of Word after 95, choose File Open and you'll get the Office App Open dialog. Instead of just a space for the file name, there are text boxes for file name, files of type, text or property & last modified. These are search criteria you can use to find one or more files. There is also an "Advanced" button that opens a dedicated search dialog with more options. When you use either of these dialogs to perform a search, that search process uses the indexes built by Find Fast."
But what would you say if I told you that Find Fast was scanning every single file on your hard drive? Did you know that in Office 95, the Find Fast Indexer had an "exclusion list" comprised of .exe, .swp, .dll and other extensions, but the feature was eliminated? If you were a programmer would you program Find Fast to index every single file, or just the ones with Office extensions?
FYI, If you have ever had problems with scandisk or defrag restarting due to disk writes, it is because Find Fast was indexing your hard drive in the background. It loads every time you start your computer up.
Now here is a good example of the lengths Microsoft has gone through to keep people from finding out Find Fast is constantly scanning and indexing their hard drives. (Always good to have an alibi.) Here's a snippet taken from microsoft.com:
"When you specify the type of documents to index in the Create Index dialog box, Find Fast includes the document types that are listed in the following table.
Doc Type File Name Extension
Microsoft Office files All the Microsoft Excel, Microsoft Web documents PowerPoint, Microsoft Project, and Microsoft Word document types listed in this table. Microsoft Binder (.odb, .obt) and Microsoft Access (.mdb) files. Note that in .mdb files, only document properties are indexed.
Microsoft Excel workbooks .xl* files
Microsoft PowerPoint files .ppt (presentation), .pot (template), .pps (auto-running presentation) files
Microsoft Project files .mpp, .mpw, .mpt, .mpx, .mpd files
Microsoft Word documents .doc (document), .dot (template), .ht* (Hypertext Markup Language document), .txt (text file), .rtf (Rich Text Format) files
All files *.* files
Did you get that last part? "All files?" Find Fast indexes Office Documents, Web documents, Word Documents, Power Point files, Project files, and -- oh, I forgot -- EVERY SINGLE other file on your computer.
Actually, the good news is that this isn't necessarily true. In another statement, Microsoft claims that if Find Fast deems the file "unreadable" then the file will not be included in the index. For example, your command.com probably wouldn't get indexed because it doesn't have a lot of plain text -- mostly binary.
But back to the bad news. Every single file that has legible text is going to be included in the Find Fast database. Do you understand the implication here? All text saved to your hard drive is indexed. The forensic capabilities are enormous, folks. Don't forget that "all text" also means previously visited webpages from your cache. See for yourself. Open up a DOS window and type:
CD\
DIR FF*.* /AH (This will bring up a listing of the Find Fast databases.)
EDIT /75 %ff% (insert %ff% with any of the names that were listed.)
Notice the incredible amount of disk accesses to your cache and history folders? Why do we need two indexes?
--------------------------------------------------------------------------------
8.1. REMOVING THE FIND FAST PROGRAM
You can remove Find Fast using your Office CD, but I recommend you do it manually.
1) Reboot your computer in MS-DOS Mode.
2) Delete the FindFast.CPL file from c:\windows\system\
3) Delete the shortcut (.lnk) under c:\windows\start menu\programs\startup\
4) Delete the FindFast.EXE file from c:\progra~1\micros~1\office\ 5) It's important to delete the find fast databases (c:\ff*.*). 6) You can also safely delete FFNT.exe, FFSetup.dll, FFService.dll, and FFast_bb.dll if you have them.
Feel free to check out the ffastlog.txt (which is the Find Fast error log). It's a +h[idden] file under c:\windows\system\.
--------------------------------------------------------------------------------
9. CONTACT INFO AND PGP BLOCKS
This tutorial is being updated all the time. If you have any useful input, or if you see a mistake somewhere, then please e-mail me so I can compile it into future versions. You will be able to find the most recent version of this tutorial at ****Microsoft.com. I am not directly affiliated with the site.
My e-mail address is located at the end of this note. Please let me know where you heard about this tutorial in your message. If you have something important to say to me, then please use encryption. My public key blocks are located below. Be suspicious if you send me an encrypted message but never get a reply.
Thanks for reading.
-- The Riddler
e-mail:
ther1ddler@****Microsoft.com
My PGP 2.6.3 Block:
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.3a
Comment: Compatible with PGP 2.6.x
mQCNAzvVzqgAAAEEANT+lnfVk79zr/eYkLHs+euTg/JBSQXmUWB5dMxv4Vvv4Xes
CnaNrv5Udi3hfABKb1tq41N6kPJ/n/Qz/vSW52Z4wg+Q+ZGGoITIJ1p8bDOceb2Q
EsMsY7kzCHqkBF0N53TuVt+ywhVncN+CqecVvhuQ4RXUOVUvru7gGcd76OVxAAUR
tAt0aGUgcmlkZGxlcokAlQMFEDvVzqju4BnHe+jlcQEBC14EAM3Th47aEChB0GAf
5xGlLPQnrj6zyf5uovj12PEFnCOwcEhDDAuq4Ito7Keb22DqwlJDNChIM7xLx8bZ
d9VaMpkirFzgvFmGu5eNGp18rR9EyIVY/tTdWlRcsUL/nw2XNXxw51tHE7M/O1fp
Un4qIcG0CfAQ1QCUfqOwTWbFH/Wy
=muLu
-----END PGP PUBLIC KEY BLOCK-----
My GPG 1.0.6 Block:
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.0.6 (MingW32)
mQGhBDu3TSERBACO0Fx9pjMULe6qLQwOgfvdnQconLOMyftZdp9+ZX6t29ebJ/Z5
qQOJ9ce9Xr6Lj4u+M9VDx1FK5ueoD45bUAy0HAvYDV/HEu2vCRimpbreDky/U88a
XL59Pe8qwnmfUzYc/LnH86VCr4lPmpbz6/adXj44xE6EwkhFcq6BD4isCwCg8zZO
Hk9+KEKOyPHIFWq7TUA/JdUD/jWtNrGZ0tfSAS0WDiBifsBr1HW7n2IMDFX1anqC
DN0ToM5IFWGDkOh1NUvP0RvyrnNuBOP/oWxkPLR0nVvifETF0iG9o+kfitC9NmJn
QP/iw4WhCoHRCc5wqnAAXQC9j8JdodQ8E5VnfnNGkttgWz7mNzBongrIoTdfVdtf
o5NwA/d/lwMhGE0HNXnXOgRBcPjGD0LsR8pFoSP/HJ9Hu3zms2cbQqN2O/f99H2G
s9mXR7uvicu9SbKoTwFkptLVbOQIhvBnw0fTlZGrUsaiw4vzt99PffTKq1FPIpQe
K7HcnUK2+ZSVs5PxGiDckobJEjBssSw9Lg5RSNMy9H7s9jv3tAt0aGUgcmlkZGxl
cohXBBMRAgAXBQI7t00iBQsHCgMEAxUDAgMWAgECF4AACgkQ/bqXDRMV1MxyMgCc
CH2uO/f46JgQ0pspQxi7IBv0yNQAn11ebXHbZGuADwuBun1EnQCJb8VIuQINBDu3
UOAQCADKG2mf/FW3kuSAGoFmIMBm4l6m0O7denwUIpZP2jxeNTLmLW6ntGglHP++
wEQpHjKTJfXoSHZH0euuXVZ9hOVdf1+PuRNy0DzrDDiKX7fdQ6eSbw+heSWc0kOF
AB1j3pcovG4K2+bK66039kQLIT3kNUZgh9DdMZjIFzBg90aQnaEm5LLMkv1FNVZP
YehZm3RRIpLAX5vkJJbUA/VVh/FXDG5f21iAGDHgSdKsLW2JNDAWe6/rY0GV5dgx
C0gsqBn1rxNNDyG+z6nFCQtohL/x5zdTzedLQBjIlao91mSWhBsyxiX8mjhvGO97
o6zVUG5KHBKGmvWMqlyOsGY9VSbDAAMGCADIaFAcE+ADY3ku9Fy0NIlJhbj578YY
xpsE6KvZI1OqbHSoBnN06A3Mpxp4QRBXlr9eRRl+zMTQl1VcVWkahZYNapOqq6L3
wHBmf9psggCBxqQdI9n5zxnlkphb50J7G9UevB/IGzlW2fe7WMWjo2GegIvGHVWr
qeZgyaNf/CyMtihAX3O86rpqakq//nJvQ9MPcp/Brr9KT2NxBlpBm6xWY35IL5FG
dZ2hpHaO1TC6bdmWUPhvzmSVtD9f0AnnJEgVc03vBz7xJrc1IEa1DeRdfFNvkoch
+mNjc+fBAIQrVMCQ33u+yP/DWSdThrhxz1tAGWV7SlwxVyg6JPRQJ+moiEYEGBEC
AAYFAju3UOAACgkQ/bqXDRMV1MwVnACfaGrJRv2lgWHQbQWwv55t2cT+QWEAnA/n
ckswjlC9aNcBkcFl7X1SX8JX
=pFTK
-----END PGP PUBLIC KEY BLOCK-----
My PGP 6.5.8 Block (patched ADK bug):
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: PGP 6.5.8
mQGiBDwJ3KgRBADJtGieMz/kabOMMTcSAUBn2c0majSEgnHpWSlGEIpOmnnAqOH+
xDYUxWnsMllYenXQfxwB++GBLh1D3wX/EIAlP3Y5jZ77Zt6PxOKUrecCDE8x1MZ8
Oiw57JAxzcBhE4CQaqzhLqwQe/yMJCc7plVjvUYmHb+INcnPi803XZaZjwCg/z0j
LmbVzWUtPo8V2KdbFPhfa8cD/00OrT7ijuXCjZNDvjsU6pSVAmSVPABhcpvFy0gm
oiusMASehoam6JMiqKnuDSVUe5hV07DO4dz67re3m97jdUY4veg0hcDCFQdifC57
VhjNHA406mV8a7aJDRGtb0LWIeEPm6LPw/SM+KuEaZ5ynnpaPWJifDWvds1MROrX
ktY1A/9713j5DWhpjwQum1jdVnUdXTaz5znEqPgKfJ4Q/1Sm2XI0m+J4e4KAaTfq
+ZtiY6zrVbZsooSqamU6raa+oSbPrnhCyIoCgvEHJIB34+fOoODJaVQV4q4UK9p8
yhyBoEv+76Th4UllsWT+y31whM7b4aKwQ+JYbjnScYC2S+ZXD7QLVGhlIFJpZGRs
ZXKJAE4EEBECAA4FAjwJ3KgECwMBAgIZAQAKCRBBoOtE1cld08B9AKCZ8AW5QLtd
pw/pwwVRtPPJu1sFwQCeKXDyo7L+pltVKl22L8+wRmDHOPy5AQ0EPAnc/xAEAOcJ
pboxlU3aUQC9lmwkU6yBIlS2JMUF5wVTI57ylR+Nz9qOOx1dTlf7ED6xJb/ARPAD
56yGpO4z5Ga3SPqOgWSW/+XcGmFaCbai+YAo1j2O/ljNa3LZExxWs4G1/k0yygY/
DVUV82ht8mFNzzDoD5ZwngmhWofQdIn4UqgOo3FrAAICBADNg1wB8TiGngnEZeSn
oFfBraUbxcDNGpE1doKoV2l6KT56iFdQOyvJ9/y7OQN5qkoLEZlQbbyUA9mRV70u
1AWZFcDlk5fS30ZfEULVoRqcZpjRlR0TQR/yAYE+Cf4SGmjBmDLtTsBUx7YFuOgm
Kg3tOZVw0bUrEJCAczky15Zup4kARgQYEQIABgUCPAnc/wAKCRBBoOtE1cld01hO
AJ0ZpkL6vbTT90TPDtJUe0mbQRXbwQCghEk4buWY5DFpEX2Mdon3/XumApc=
=ozdt
-----END PGP PUBLIC KEY BLOCK-----
--------------------------------------------------------------------------------
9.1. RECOMMENDED READING
http://www.theregister.co.uk/content/4/18002.html
http://www.findarticles.com/m0CGN/3741/55695355/p1/article.jhtml
http://www.mobtown.org/news/archive/msg00492.html
http://194.159.40.109/05069801.htm
http://www.yarbles.demon.co.uk/mssniff.html
http://www.macintouch.com/o98security.html
http://www.theregister.co.uk/content/archive/3079.html
http://www.fsm.nl/ward/
http://slashdot.org
http://www.peacefire.org
http://stopcarnivore.org
http://nomorefakenews.com
http://grc.com/steve.htm#project-x
--------------------------------------------------------------------------------
10. SPECIAL THANKS (and no thanks)
This version I want to give special thanks to Concerned Boss, Oblivion, and the F-Prot virus scanner.
I also want to take this time to show my dissatisfaction to the New Zealand Herald. Although partly flattering, it was more disgusting to see a newspaper try to take credit for my work.
--------------------------------------------------------------------------------
11. REFERENCES
http://support.microsoft.com/support/kb/articles/Q137/1/13.asp
http://support.microsoft.com/support/kb/articles/Q136/3/86.asp
http://support.microsoft.com/support/kb/articles/Q169/5/31.ASP
http://support.microsoft.com/support/kb/articles/Q141/0/12.asp
http://support.microsoft.com/support/kb/articles/Q205/2/89.ASP
http://support.microsoft.com/support/kb/articles/Q166/3/02.ASP
http://www.insecure.org/sploits/Internet.explorer.web.usage.logs.html
http://www.parascope.com/cgi-bin/psforum.pl/topic=matrix&disc=514&mmark=all
http://www.hackers.com/bulletin/
http://slashdot.org/articles/00/05/11/173257.shtml
http://peacefire.org/
--------------------------------------------------------------------------------
COPYRIGHT INFORMATION
This article has been under the protection of copyright laws the moment it was fixed in a tangible form. In less otherwise agreed, this article may only be distributed as a whole and without modification. Thank you.
--------------------------------------------------------------------------------
Discuss this article with the author, and with other visitors to ****Microsoft.com, in the Hidden Files discussion area of our forums!