background image

Dr Solomon’s Anti-Virus

Administrator’s
Guide

Version 8.5

Summary of Contents for DR SOLOMON S ANTI-VIRUS 8.5

Page 1: ...Dr Solomon s Anti Virus Administrator s Guide Version 8 5 ...

Page 2: ...an WebShield WebSniffer WebStalker WebWall and ZAC 2000 are registered trademarks of Network Associates and or its affiliates in the US and or other countries All other registered and unregistered trademarks in this document are the sole property of their respective owners LICENSE AGREEMENT NOTICE TO ALL USERS CAREFULLY READ THE FOLLOWING LEGAL AGREEMENT AGREEMENT FOR THE LICENSE OF SPECIFIED SOFT...

Page 3: ...e limitations or other requirements described herein Upon any termination or expiration of this Agreement you must destroy all copies of the Software and the Documentation You may terminate this Agreement at any point by destroying all copies of the Software and the Documentation 3 Updates For the time period specified in the applicable price list or product packaging for the Software you are enti...

Page 4: ... McAfee s option either i return of the purchase price paid for the license if any or ii replacement of the defective media in which the Software is contained You must return the defective media to McAfee at your expense with a copy of your receipt This limited warranty is void if the defect has resulted from accident abuse or misapplication Any replacement media will be warranted for the remainde...

Page 5: ...n by the United States Government shall be governed solely by the terms of this Agreement and shall be prohibited except to the extent expressly permitted by the terms of this Agreement 9 Export Controls Neither the Software nor the Documentation and underlying information or technology may be downloaded or otherwise exported or re exported i into or to a national or resident of Cuba Iran Iraq Lib...

Page 6: ... This Agreement is governed by the laws of the United States and the State of California without reference to conflict of laws principles The application of the United Nations Convention of Contracts for the International Sale of Goods is expressly excluded This Agreement sets forth all rights for the user of the Software and is the entire agreement between the parties This Agreement supersedes an...

Page 7: ...xii Chapter 1 About Dr Solomon s Anti Virus 25 Introducing Dr Solomon s Anti Virus 25 How does Dr Solomon s Anti Virus work 27 What comes with Dr Solomon s Anti Virus 29 What s new in this release 33 Chapter 2 Installing Dr Solomon s Anti Virus 37 Before you begin 37 System requirements 37 Installing Dr Solomon s Anti Virus software on a local computer 38 Installation steps 38 Using the Emergency ...

Page 8: ...ing false detections 84 Responding to viruses or malicious software 85 Submitting a virus sample 97 Using the SendVirus utility to submit a file sample 97 Capturing boot sector file infecting and macro viruses 100 Chapter 4 Using Dr Solomon s Anti Virus 105 Using the WinGuard scanner 105 Using the Dr Solomon s Anti Virus application 105 Scheduling scan tasks 106 Using specialized scanning tools 10...

Page 9: ...n 153 Alert Manager 156 Dr Solomon s Anti Virus control panel files 157 ScreenScan 158 Dr Solomon s Anti Virus Emergency Disk files 160 Dependent and related files for the E Mail Scan extension 162 Appendix C Using Dr Solomon s Anti Virus Command line Options 167 Adding advanced Dr Solomon s Anti Virus engine options 167 Running the Dr Solomon s Anti Virus Command Line program 167 Running the on d...

Page 10: ... plan 202 PrimeSupport options for home users 204 How to reach international home user support 206 Ordering a PrimeSupport plan for home users 206 Network Associates consulting and training 207 Professional Services 207 Total Education Services 208 Appendix F Understanding iDAT Technology 209 Understanding incremental DAT files 209 How does iDAT updating work 210 What does Dr Solomon s post each w...

Page 11: ...y authenticity availability and non repudiation of information and information processing systems Virus payloads had always threatened or damaged data integrity but by the time she wrote her survey article newer viruses had already begun to mount sophisticated attacks that struck at the remaining underpinnings of information security Denning s classification recognized that newer viruses no longer...

Page 12: ...efiller infection Throughout much of 1999 virus and worm attacks suddenly stepped up in intensity and in the public eye Part of the reason for this of course is that many of the more notorious viruses and worms took full advantage of the Internet beginning a long predicted assault by flooding e mail transmissions websites newsgroups and other available channels at an almost exponential rate of gro...

Page 13: ...y W32 FunLove 4099 which infected ActiveX OCX files among others This meant that it could lurk on web pages with ActiveX content and infect systems with low or nonexistent browser security settings as they downloaded pages to their hard disks If a Windows NT computer user had logged into a system with administrative rights the infecting virus would patch two critical system files that gave all use...

Page 14: ...er lists secure credit card data and purchase verification reliable communications and hundreds of other computer aided transactional details The costs from these virus attacks in the digital economy now cut directly into the bottom line Because they do protecting that bottom line means implementing a total solution for information and network security one that includes comprehensive anti virus pr...

Page 15: ...top workstations for example can spread viruses by any of a variety of means via floppy disks by downloading them from the Internet by mapping server shares or other workstations hard disks E mail servers by contrast rarely use floppy disks and tend not to use mapped drives the Melissa virus showed however that they are quite vulnerable to e mail borne infections even if they don t execute the vir...

Page 16: ...okes or hoaxes With the help of the WinGuard Internet Filter module it also blocks hostile ActiveX and Java objects many of which can lurk unnoticed on websites waiting to deploy sophisticated virus like payloads The Internet Filter module can even block entire websites preventing network users from visiting sites that pose a threat to network integrity Dr Solomon s Anti Virus ties these powerful ...

Page 17: ... discovery Early detection contains infections saves on the costs of virus eradication and in many cases can prevent a destructive virus payload from triggering Dr Solomon s anti virus research Even the best anti virus software is only as good as its latest update Because as many as 200 to 300 viruses and variants appear each month the DAT files that enable Dr Solomon s software to detect and remo...

Page 18: ...d security solutions including the PGP data security and encryption product line the Gauntlet firewall product line the WebShield E ppliance hardware line and the CyberCop Scanner and Monitor product series Sniffer Technologies This division supplies the industry leading Sniffer network monitoring reporting and analysis utility and related software Network Associates continues to market and suppor...

Page 19: ...rus information If you do not find what you need or do not have web access try one of our automated services If the automated services do not have the answers you need contact Network Associates at one of the following numbers Monday through Friday between 8 00 A M and 8 00 P M Central time to find out about Network Associates technical support plans For corporate licensed customers For retail lic...

Page 20: ...on s websites or FTP sites call Network Associates training For information about scheduling on site training for any Dr Solomon s or Network Associates product call Network Associates Customer Service at 972 308 9960 Comments and feedback Dr Solomon s Software appreciates your comments and reserves the right to use any information you supply in any way it believes appropriate without incurring an...

Page 21: ... office in Japan use one of these e mail addresses virus_research nai com Use this address to send questions or virus samples to our North America and South America offices vsample nai com Use this address to send questions or virus samples gathered with Dr Solomon s Anti Virus Toolkit software to our offices in the United Kingdom virus_research_europe nai com Use this address to send questions or...

Page 22: ...e Phone 0032 2 478 10 29 Fax 0032 2 478 66 21 Network Associates do Brasil Rua Geraldo Flausino Gomez 78 Cj 51 Brooklin Novo São Paulo SP 04575 060 Brasil Phone 55 11 5505 1009 Fax 55 11 5505 1006 Network Associates Canada 139 Main Street Suite 201 Unionville Ontario Canada L3R 2G6 Phone 905 479 4189 Fax 905 479 4540 Network Associates People s Republic of China New Century Office Tower Room 1557 ...

Page 23: ...t Palazzo D 1 Via Brescia 28 20063 Cernusco sul Naviglio MI Italy Phone 39 02 92 65 01 Fax 39 02 92 14 16 44 Network Associates Japan Inc Toranomon 33 Mori Bldg 3 8 21 Toranomon Minato Ku Tokyo 105 0001 Japan Phone 81 3 5408 0700 Fax 81 3 5408 0780 Network Associates Latin America 1200 S Pine Island Road Suite 375 Plantation Florida 33324 United States Phone 954 452 1731 Fax 954 236 8031 Network A...

Page 24: ...0 7255 Network Associates Spain Orense 4 4a Planta Edificio Trieste 28020 Madrid Spain Phone 34 9141 88 500 Fax 34 9155 61 404 Network Associates Sweden Datavägen 3A Box 596 S 175 26 Järfälla Sweden Phone 46 0 8 580 88 400 Fax 46 0 8 580 88 405 Network Associates AG Baeulerwisenstrasse 3 8152 Glattbrugg Switzerland Phone 0041 1 808 99 66 Fax 0041 1 808 99 77 Network Associates Taiwan Suite 6 11F N...

Page 25: ...venue as more businesses move into e commerce and online sales and as virus attacks proliferate Dr Solomon s Anti Virus first honed its technological edge as one of a handful of pioneering utilities developed to combat the earliest virus epidemics of the personal computer age It has developed considerably in the intervening years to keep pace with each new subterfuge that virus writers have unleas...

Page 26: ... the sun coverage from its Anti Virus Emergency Response Team AVERT Even with the rise of viruses and worms that use e mail to spread that flood e mail servers or that infect groupware products and file servers directly the individual desktop remains the single largest source of infections and is often the most vulnerable point of entry Dr Solomon s Anti Virus acts as a tireless desktop sentry gua...

Page 27: ...le a boot sector or a master boot record that viruses tend to infect either because they can hide within them or because they can hijack their execution routines This way the scanner avoids having to examine the entire file for virus code it can instead sample the file at well defined points to look for virus code signatures that indicate an infection The development environment brings as much spe...

Page 28: ...istics analysis As a further engine enhancement Dr Solomon s researchers have honed early heuristic scanning technologies originally developed to detect the astonishing flood of macro virus variants that erupted after 1995 into a set of precision instruments Heuristic scanning techniques rely on the engine s experience with previous viruses to predict the likelihood that a suspicious file is an as...

Page 29: ... away from your system The WinGuard scanner that comes with Dr Solomon s Anti Virus has three modules that concentrate on agents that arrive from the Internet that spread via e mail or that lurk on Internet sites It can look for particular Java and ActiveX objects that pose a threat or block access to dangerous Internet sites Meanwhile an E Mail Scan extension to Microsoft Exchange e mail clients ...

Page 30: ...nti virus protection from viruses that arrive on floppy disks from your network or from various sources on the Internet The WinGuard scanner starts when you start your computer and stays in memory until you shut down A flexible set of property pages lets you tell the scanner which parts of your system to examine what to look for which parts to leave alone and how to respond to any infected files i...

Page 31: ...ity This essential utility helps you to create a floppy disk that you can use to boot your computer into a virus free environment then scan essential system areas to remove any viruses that could load at startup Command line scanners This component consists of a set of full featured scanners you can use to run targeted scan operations from the MS DOS Prompt or Command Prompt windows or from protec...

Page 32: ...ons but if you have trouble starting Windows or if the Dr Solomon s Anti Virus GUI components will not run in your environment you can use the command line scanners as a backup Documentation Dr Solomon s Anti Virus documentation includes A printed Getting Started Guide which introduces the product provides installation instructions outlines how to respond if you suspect your computer has a virus a...

Page 33: ...le to the specific topic that describes the entire dialog box A LICENSE TXT file This file outlines the terms of your license to use Dr Solomon s Anti Virus Read it carefully by installing Dr Solomon s Anti Virus you agree to its terms A README TXT file This file contains last minute additions or changes to the documentation lists any known behavior or other issues with the product release and oft...

Page 34: ...k user base To learn more about using ePolicy Orchestrator software for Dr Solomon s Anti Virus distribution and configuration consult the ePolicy Orchestrator Administrator s Guide This Dr Solomon s Anti Virus version also includes package description information for other distribution tools including Microsoft System Management Server and Tivoli Systems software management products Interface enh...

Page 35: ...95 and Windows 98 systems This option lets you determine how the Prompt for user action alert appears Changes in product functionality A new Alert Manager Client configuration utility allows you to choose an Alert Manager server installed on your network as an alert message destination or to select a network share as a destination for Centralized Alerting messages You can also supplement either of...

Page 36: ...e of DAT file releases The latest versions of the AutoUpdate and AutoUpgrade utilities come with transparent support for the new updates downloading and installing only those virus definitions you don t already have installed on your system This means a substantial reduction in download and rollout time along with similar reductions in network bandwidth demand ...

Page 37: ...trator privileges for the workstation on which you plan to install the program Review the items shown in System requirements to determine whether your target workstations can run Dr Solomon s Anti Virus software System requirements Dr Solomon s Anti Virus software installs and runs on any IBM PC or PC compatible computer equipped with A processor equivalent to an Intel Pentium class or compatible ...

Page 38: ...the infected computer and remove the virus To learn more see If you suspect you have a virus on page 69 If your copy of Dr Solomon s Anti Virus software came on a CD ROM insert that disc into your computer s CD ROM drive If you inserted a CD ROM you should see a Dr Solomon s Anti Virus welcome image appear automatically To install Dr Solomon s Anti Virus software immediately click Install then ski...

Page 39: ...lick OK Here X represents the drive letter for your CD ROM drive or the path to the folder that contains your extracted Dr Solomon s Anti Virus files To search for the correct files on your hard disk or CD ROM click Browse NOTE If your Dr Solomon s Anti Virus software copy came on an Active Virus Defense or a Total Virus Defense CD ROM you must also specify which folder contains the Dr Solomon s A...

Page 40: ...ady exists on your system If your computer runs an earlier Windows release you might still have this MSI version on your system if you previously installed other software that uses MSI If you have the correct MSI version on your computer and do not have any previous Dr Solomon s Anti Virus versions installed on your system Setup will display its first wizard panel immediately Skip to Step 5 to con...

Page 41: ...you do not agree to the license terms select I do not agree to the terms of the License Agreement then click Cancel Setup will quit immediately Otherwise click I agree to the terms of the License Agreement then click Next to continue Setup next checks to see whether incompatible software exists on your computer If you have no other anti virus software on your system Setup then moves to the Securit...

Page 42: ...Settings if the option is available then click Next to continue If Setup finds incompatible software it will display a wizard panel that gives you the option to remove the conflicting software see Figure 2 5 on page 43 If you have no incompatible software on your system and your computer runs Windows 95 or Windows 98 skip to Step 10 on page 45 to continue with the installation If you have no incom...

Page 43: ...tes at a very low level within your system two anti virus programs that compete for access to the same files or that perform critical operations can make your system very unstable If your computer runs Windows NT Workstation v4 0 or Windows 2000 Professional Setup next asks you which security mode you want to use to run Dr Solomon s Anti Virus software on your system see Figure 2 6 on page 44 The ...

Page 44: ...duled tasks Users who do not have administrative rights may still configure and run their own scan operations with the Dr Solomon s Anti Virus application and save settings for those operations in a VSC file but they cannot change default Dr Solomon s Anti Virus application settings To learn more about how to configure and save Dr Solomon s Anti Virus application settings see Chapter 5 Using the D...

Page 45: ...ck any object on your hard disk to start a scan operation the Dr Solomon s Anti Virus Console the WinGuard System Scan module the Alert Manager Client configuration utility the Send Virus utility the Emergency Disk utility the Dr Solomon s Anti Virus Command Line scanner software Custom Installation This option starts with the same components as the Typical setup but allows you to choose from amon...

Page 46: ...k beside a component name then choose This feature will be installed on local hard drive from the menu that appears To add a component and any related modules within the component choose This feature and all subfeatures will be installed on local hard drive instead You can choose this option only if a component has related modules Remove a component from the installation Click beside a component n...

Page 47: ...ficient space 13 When you have chosen the components you want to install click Next to continue Setup will show you a wizard panel that confirms its readiness to begin installing files Figure 2 9 Figure 2 9 Ready to Install panel 14 Click Install to begin copying files to your hard drive Otherwise click Back to change any of the Setup options you chose Setup first removes any incompatible software...

Page 48: ...on s Anti Virus software is ready for use NOTE If you had a previous Dr Solomon s Anti Virus version installed on your computer you must restart your system once again in order to start the WinGuard scanner Setup will prompt you to restart your system Choose configuration options for your installation You can choose to scan your system create an emergency disk or update your virus definition files...

Page 49: ...he first of two configuration panels see Figure 2 11 on page 49 Figure 2 11 Configuration panel 16 If your computer runs Windows 95 or Windows 98 you can choose any of the configuration options shown here These are Scan boot record at startup Select this checkbox to have Setup write these lines to your Windows AUTOEXEC BAT file C PROGRA 1 NETWOR 1 DRSOLO 1 SCAN EXE C IF ERRORLEVEL 1 PAUSE This tel...

Page 50: ...peration NOTE If you told Setup to remove any previous Dr Solomon s Anti Virus versions from your system it will run the scan operation after it restarts your computer The Dr Solomon s Anti Virus application will appear immediately after startup If your computer runs Windows NT Workstation v4 0 or Windows 2000 Professional you may not choose Scan boot record at startup but you may choose either of...

Page 51: ...utomatic Update dialog box where you can add or configure an update site from which to download new files Select this option if your company has designated a server for DAT file updates somewhere on your network or if you want to change some aspect of how your computer connects to the Network Associates website firewall or proxy server settings for example To learn more about how to configure the ...

Page 52: ...ose Setup next displays its final panel and asks if you want to start the WinGuard scanner and the Dr Solomon s Anti Virus Console immediately see Figure 2 13 on page 52 Figure 2 13 Successful Installation panel 20 To do so select the Start Dr Solomon s Anti Virus checkbox then click Finish The Dr Solomon s Anti Virus software splash screens will appear and the WinGuard scanner and Dr Solomon s An...

Page 53: ...footprint command line scanner that can scan your hard disk boot sectors and Master Boot Record MBR BOOTSCAN EXE works with a specialized set of DAT files that focus on ferreting out boot sector viruses If you have already installed Dr Solomon s Anti Virus software with default Setup options you can find these DAT files in this location on your hard disk C Program Files Common Files Network Associ...

Page 54: ...nel appears Figure 2 15 Figure 2 15 Second Emergency Disk panel If your computer runs Windows NT Workstation or Windows 2000 Professional the wizard tells you that it will format your Emergency Disk with the NAI OS You must use these operating system files to create your Emergency Disk because Windows NT Workstation v4 0 and Windows 2000 Professional system files do not fit on a floppy disk If you...

Page 55: ...ese substeps to continue a Insert an unlocked and unformatted 1 44MB floppy disk into your floppy drive then click Next The Emergency Disk wizard will copy its files from a disk image stored in the Dr Solomon s Anti Virus program directory As it does so it will display its progress in a wizard panel b Click Finish to quit the wizard when it has created your disk Next remove the disk from your flop...

Page 56: ...AT files and support files to the floppy disk Skip to Step 3 on page 57 to continue If you do not have a virus free floppy disk formatted with DOS or Windows system files you must create one in order to use the Emergency Disk to start your computer Follow these substeps a Insert an unlocked and unformatted floppy disk into your floppy drive Dr Solomon s Software recommends that you use a completel...

Page 57: ...area are both selected Next click Start Windows will format your floppy disk and copy the system files necessary to start your computer e Click Close when Windows has finished formatting your disk then click Close again to return to the Emergency Disk panel 3 Click Next to continue Setup will scan your newly formatted disk for viruses see Figure 2 19 on page 57 Figure 2 19 Scanning Emergency Disk ...

Page 58: ...d floppy disk shows two holes near the edge of the disk opposite the metal shutter If you don t see two holes look for a plastic sliding tab at one of the disk corners then slide the tab until it locks in an open position Determining when you must restart your computer In many circumstances you can install and use this Dr Solomon s Anti Virus release immediately without needing to restart your com...

Page 59: ...and no incompatible software No restart required unless you have Novell Client32 for NetWare installed then restart required Restart required Installation on computer with previous Dr Solomon s Anti Virus version Restart required Restart required Installation on computer with incompatible software No restart required but Setup will ask if you wish to restart You can safely click No No restart requ...

Page 60: ... directly from the Testing your installation section of the README TXT file which you can find in your Dr Solomon s Anti Virus program directory If you copy the line from either of these sources be sure to delete any carriage returns or spaces 2 Save the file with the name EICAR COM The file size will be 69 or 70 bytes 3 Start your Dr Solomon s Anti Virus software and allow it to scan the director...

Page 61: ...e Dr Solomon s Anti Virus software follow these steps 1 Click Start in the Windows taskbar point to Settings then choose Control Panel 2 Locate and double click the Add Remove Programs control panel 3 In the Add Remove Programs Properties dialog box choose Dr Solomon s Dr Solomon s Anti Virus v4 5 0 in the list then click Add Remove Setup will start and display the first Maintenance wizard panel F...

Page 62: ...6 Start with Step 12 on page 46 to choose the components you want to add or remove NOTE This panel differs from the one shown on page 46 It will not allow you to change your Dr Solomon s Anti Virus program directory nor will it display disk usage statistics To install Dr Solomon s Anti Virus software in a different directory or on a different drive you must first remove then reinstall the software...

Page 63: ...l Dr Solomon s Anti Virus software over your network to many workstations at once and with various custom configurations You can run Setup from a command prompt to choose many of these configuration options Using Active Directory and Group Policies If you use Active Directory services in Windows 2000 you must distribute the software per machine not per user Set up the installation in the Microsoft...

Page 64: ...mand line NOTE You can run Setup from the command line only to install Dr Solomon s Anti Virus software to a local computer To install the software over a network you must use Management Edition or ePolicy Orchestrator software To do so click Start in the Windows taskbar then choose Run Next enter the command line you want to use in the Run dialog box then click OK The Setup command line syntax lo...

Page 65: ...ns By default its value is True REBOOT This property tells Setup whether it should restart your computer You can either force the computer to restart or prevent it from restarting REMOVE This property tells Setup to remove one or more program components You can specify a particular component or use the value ALL to remove all components If you combine this property with the ADDLOCAL property you c...

Page 66: ...ws or offer the end user any configuration options Instead you pre configure these choices and run Setup in the background on each target workstation If you want you can install Dr Solomon s Anti Virus software on any unattended workstation with or without the end user s knowledge provided you have all the necessary administrative privileges setup q i Use q to run a silent installation The i shoul...

Page 67: ...e shown in the command line example with one or more of these parameters to limit the type of data that the log file records qb shows a small progress bar during installation with a cancel button q shows a success failure installation complete dialog box qb shows both the progress and completed dialog boxes qf shows the full progress bar screen from the regular installation i status messages w non...

Page 68: ...installs those components according to a preexisting hierarchy This means that if you choose to install only the Dr Solomon s Anti Virus shell extensions for example Setup knows that you must have SCAN32 EXE the Dr Solomon s Anti Virus application installed in order to use the extensions It therefore will install both this file and any related files To specify the components you want to install Se...

Page 69: ...mponents except for one the SendVirus component in this example type this line at the command prompt setup exe ADDLOCAL ALL REMOVE SendVirus q i You can also choose different components for an installation that you do not run silently If for example you leave off the q option in any of the command line examples shown above the Custom Setup wizard panel see Figure 2 8 on page 46 will show only the ...

Page 70: ...oftware on Windows NT Workstation v4 0 or Windows 2000 Professional systems you can choose to run the software with regular or maximum security To set this value from the command line run Setup with the USEADMINONLYSECURITY property and the value you want to use To run the software with standard security give the property the value 0 USEADMINONLYSECURITY 0 To run the software with maximum security...

Page 71: ...ithout previous settings add the PRESERVESETTINGS property to the command line with the value False setup PRESERVESETTINGS False Running Setup from a login script To install Dr Solomon s Anti Virus software at the time each of your target computers starts you can add a Setup command line to your login script and include any logic you think necessary to ensure that the installation will run once ch...

Page 72: ... install Dr Solomon s Anti Virus software from a remote location on the network use Management Edition or ePolicy Orchestrator management software NOTE If you plan to install Dr Solomon s Anti Virus software to a Windows NT Workstation v4 0 or a Windows 2000 system via login scripts you do not need to include the LSCRIPT option in your command line Using Management Edition software Management Edit...

Page 73: ...eps 1 Use WinZip PKZip or a similar utility to extract the files VSC_9X INI and VSC_NT INI from the Dr Solomon s Anti Virus package 2 Locate this line in each file REGSETVAL LOCAL VS_EXEC_KEY ExecCmdLine SZ I_CMD_LINE Change the macro reference I_CMD_LINE so that it reads I_CMD_LINE_ALL When you have finished the entire line in both the VSC_9X INI and the VSC_NT INI files should read REGSETVAL LOC...

Page 74: ...ction menu and then click Install The Select a Software Package dialog box displays your network Locate the Dr Solomon s Anti Virus software package that you want to place in the repository 3 Click Dr Solomon s Anti Virus 4 Click Open Dr Solomon s Anti Virus software is loaded in your repository For more information see the ePolicy Orchestrator Administrator s Guide Installing via System Managemen...

Page 75: ...ware to users workstations To learn how to use ZENworks to deploy the Dr Solomon s Anti Virus installation package consult your Novell ZENworks documentation Exporting Dr Solomon s Anti Virus custom settings Dr Solomon s Software provides a small utility that you can use to put a Dr Solomon s Anti Virus installation package together with all of the configuration settings you want to use for each t...

Page 76: ...1 MSI_INST EXE command line switches Option Purpose Usage IMPORT Import settings into a Dr Solomon s Anti Virus installation from an INI file you designate IMPORT path and filename EXPORT Export settings from a Dr Solomon s Anti Virus installation to an INI file you designate EXPORT path and filename EXPOPTIONS Export certain settings from Dr Solomon s Anti Virus Use this option in conjunction wit...

Page 77: ...mal values for these settings together in a logical OR operation 0x00000001h 0x00000008h 0x00000010h 0x00000019h Next take the resulting value and change the hexadecimal number to a decimal number 0x00000019h 25 Add the decimal value to the command line msi_inst exe EXPOPTIONS 25 RESTART Start Dr Solomon s Anti Virus after the MSI_INST EXE utility finishes importing or exporting settings RESTART P...

Page 78: ...s v4 0 2 and v4 0 3 settings PREVIOUS path and filename PREVIOUS_EXCLUDE Preserves the exclusion settings from previous WinGuard scanner installations This option tells MSI_INST EXE to read the exclusion settings from a previous INI file and set new installation appropriately You must use this option with the PREVIOUS option NOTE You may use this option only to preserve Dr Solomon s Anti Virus v4 ...

Page 79: ...l help eliminate one potential cause of your computer problems The safest course of action you can take is to install Dr Solomon s Anti Virus then scan your system immediately and thoroughly When you install Dr Solomon s Anti Virus Setup starts the Dr Solomon s Anti Virus application to examine your computer s memory and your hard disk boot sectors in order to verify that it can safely copy its fi...

Page 80: ...n Using the Emergency Disk Creation utility on page 53 3 Wait at least 15 seconds then start your computer again NOTE If you have your computer s BIOS configured to look for its boot code first on your C drive you should change your BIOS settings so that your computer looks first on your A or B drive Consult your hardware documentation to learn how to configure your BIOS settings After it starts y...

Page 81: ...iles of that number are clean or uninfected How many files contain potential infections How many files of that number the scanner cleaned How many boot sector and MBR files the scanner examined How many boot sector and MBR files contain potential infections If the scanner detects a virus it beeps and reports the name and location of the virus on the screen 6 When the scanner finishes examining you...

Page 82: ... or shut down your computer each day Use the WinGuard scanner to examine your computer s memory and maintain a constant level of vigilance between scan operations Under most circumstances this should protect your system s integrity If you connect to the Internet frequently or download files often you might want to supplement regular scan operations with tasks based on certain events Use the Dr Sol...

Page 83: ...hen your problem really results from an interrupt conflict it does allow you to eliminate one possible cause With that knowledge you can then go on to troubleshoot your system with a full featured system diagnosis utility More serious is the confusion that results from virus like programs virus hoaxes and real security breaches Anti virus software simply cannot detect or respond to such destructiv...

Page 84: ... the computer down and turn off the power Wait a few seconds before you start the computer again so that the system can clear the other program s code signature strings from memory You have a BIOS chip with anti virus features Some BIOS chips provide anti virus features that can trigger false detections when Dr Solomon s Anti Virus runs Consult the user s guide for your computer to learn about how...

Page 85: ...try points each has a different set of default responses Responding when the System Scan module detects a virus How this module reacts when it finds a virus depends on which operating system your computer runs and on Windows 95 and Windows 98 systems on which prompt option you chose in the module s Action page By default on Windows 95 and Windows 98 systems this module looks for viruses each time ...

Page 86: ...ull screen Warning System Scan response options This alert message brings your system to a complete halt as it awaits your response No other programs or system operations run on your system until you choose one of the response options shown The BIOS prompt type also allows you to substitute a Continue option for the Move File option To do so select the Continue access checkbox in the module s Acti...

Page 87: ...of which files it flagged as infected You can then restore deleted files from backup copies Move the file to a different location Click Move File to in the dialog box This opens a browse window you can use to locate your quarantine folder or another folder you want to use to isolate infected files Once you select a folder the System Scan module moves the infected file to it immediately This option...

Page 88: ...the virus has damaged the file beyond repair it will record the incident in its log file and suggest alternative responses In the example shown in Figure 3 3 the module failed to clean the EICAR test file a mock virus written specifically to test whether your anti virus software installed correctly Here Clean is not an available response option In most cases you should delete such files and restor...

Page 89: ...ns or through similar channels In its initial configuration the module will prompt you to choose a response from among three options whenever it detects a virus Figure 3 4 A fourth option provides you with additional information Figure 3 4 Download Scan response options Click the button that corresponds to the response you want Your choices are Continue Click this to tell the Download Scan module ...

Page 90: ...nternet sites In its initial configuration the module will ask you whenever it encounters a potentially harmful object whether you want to Deny the object access to your system or you want to Continue and allow the object access It will offer you the same choice when you try to connect to a potentially dangerous website Figure 3 5 Figure 3 5 Internet Filter response options Responding when the Dr ...

Page 91: ...o the virus Once the application finishes examining your system you can right click each file listed in the main window then choose an individual response from the shortcut menu that appears Figure 3 7 Dr Solomon s Anti Virus main window Stop Click this button to stop the scan operation immediately The Dr Solomon s Anti Virus application will list the infected files it has already found in the low...

Page 92: ...le to Click this to open a dialog box that you can use to locate your quarantine folder or another suitable folder Once you have located the correct folder click OK to transfer the file to that location Info Click this to connect to the Network Associates Virus Information Library This choice does not take any action against the virus that the application detected See Viewing virus information on ...

Page 93: ...nsion will continue until it finds another virus on your system or until it finishes the scan operation Once it has finished examining your system you can right click each file listed in the main window then choose an individual response from the shortcut menu that appears Stop Click this button to stop the scan operation immediately The E Mail Scan extension will list the infected files it has al...

Page 94: ...ail Scan extension will record the name of the infected file in its log so that you can restore the file from a backup copy Move Click this button to open a dialog box that you can use to locate your quarantine folder or another suitable folder Once you have located the correct folder click OK to transfer the file to that location Info Click this to connect to the Network Associates Virus Informat...

Page 95: ...ce tables technical documents and white papers and gives you access to technical data you can use to remove viruses from your system To connect directly to the library visit the site at http vil nai com villib alpha asp You can also connect directly to the Library from the Dr Solomon s Anti Virus Console choose Virus List from the View menu in the Console window To learn more about the Console see...

Page 96: ...ular weekly DAT and SuperDAT updates and new incremental virus definition files UPD Beta and first look software Viewing file information If you right click a file listed either in the Dr Solomon s Anti Virus main window or the E Mail Scan window see Figure 3 9 on page 94 then choose File Info from the shortcut menu that appears Dr Solomon s Anti Virus will open an Infected Item Information dialog...

Page 97: ...o submit a file sample Because the majority of later generation viruses tend to infect document and executable files Dr Solomon s Anti Virus comes with SENDVIR EXE a utility that makes it easy to submit an infected file sample to Dr Solomon s researchers for analysis To submit a sample file follow these steps 1 If you must connect to your network or Internet Service Provider ISP to send e mail do ...

Page 98: ...ntact you about your submission enter your name e mail address and any message you would like to send along with your submission in the text boxes provided then click Next to continue NOTE You may submit samples anonymously if you prefer simply leave the text boxes in this panel blank You are under no obligation to supply any information at all here The Choose Files to Submit panel appears Figure ...

Page 99: ...t to submit click Next to continue The Choose Upload Options panel appears Figure 3 15 Figure 3 15 Choose Upload options panel If the file you want to submit is a Microsoft Office document or another file that contains information you want to keep confidential select the Remove my personal data from file checkbox then click Next to continue This tells the SENDVIR EXE utility to strip everything ou...

Page 100: ... any remedy or respond in any way to you SENDVIR EXE will use the e mail client you specified to send your sample You must have connected to your network or ISP in order for this process to succeed Capturing boot sector file infecting and macro viruses If you suspect you have a virus infection you can collect a sample of the virus then either create a floppy disk image to send via e mail or mail t...

Page 101: ... that has infected any of your Microsoft Word Excel or PowerPoint files send these files to Dr Solomon s anti virus researchers either with the SENDVIR EXE utility via e mail as floppy disk images or through the mail on floppy disk If you suspect that a virus has infected executable files on your system copy COMMAND COM to a formatted floppy disk then change its file extension to a non executable ...

Page 102: ...ou must use RWFLOPPY to send your samples electronically otherwise you must send your samples physically on a diskette If you send them electronically without using RWFLOPPY the samples will be incomplete or unusable as boot viruses often hide beyond the last sectors of a diskette and other diskette image creation programs cannot obtain this data Once you create images of the disks you want to sen...

Page 103: ...r created a file archive for your samples send them to Dr Solomon s researchers at one of these e mail addresses In your message include this information Which symptoms cause you to suspect that your machine is infected Which product and version number detected the virus if any did and what the results were Your Dr Solomon s Anti Virus and DAT file version numbers Details about your system that mi...

Page 104: ...ubmit a sample AVERT cannot return it to you AVERT does not accept or process Iomega Ditto or Jazz cartridges Iomega Zip disks or other types of removable media In the United States Network Associates Inc Virus Research 20460 NW Von Neumann Drive Beaverton OR 97006 In the United Kingdom Network Associates Inc Virus Research Gatehouse Way Aylesbury Bucks HP19 3XU UK In Germany Network Associates In...

Page 105: ... learn how to configure WinGuard properties and how to start and stop the WinGuard scanner see Chapter 4 Using the WinGuard Scanner in the Dr Solomon s Anti Virus User s Guide Using the Dr Solomon s Anti Virus application The Dr Solomon s Anti Virus name applies both to the entire set of desktop anti virus program components described in the User s Guide and to a particular component of that set S...

Page 106: ... scan operation in your absence when it causes the least disruption to your work as part of a series of automated tasks or in other ways that suit your needs To learn how to configure Dr Solomon s Anti Virus Console properties see Chapter 6 Creating and Configuring Scheduled Tasks in the Dr Solomon s Anti Virus User s Guide Using specialized scanning tools In addition to the continuous background ...

Page 107: ...k at all You also need a method to collect and manage alert messages from all over the network in a central repository so that you can respond whenever any workstation detects an infected file McAfee provides Alert Manager server software for just such a need The software allows you to centralize alert message collection and processing assign priority designations and custom messages to those mess...

Page 108: ...tie alert messages into the Network Associates Magic HelpDesk application for trouble ticket generation and other features Alert Manager messages also contain much richer data than do those sent via Centralized Alerting Enabling SNMP traps for Alert Manager will collect a host of information about the computer that generates the alert message and its software configuration The Dr Solomon s Anti Vi...

Page 109: ...s Anti Virus Alerting Configuration The Alert Manager Client Configuration page appears 2 Figure 5 1 Alert Manager Client Configuration dialog box 2 Verify that the Disable Alerting checkbox is clear This activates the remaining options in this dialog box Select this checkbox only if you want the Alert Manager Client Configuration utility not to pass alert messages from your anti virus software to...

Page 110: ...e computer name The Alert Manager Client Configuration utility will validate the form of the name you enter here but will not verify that the Alert Manager server exists on the target computer This allows laptop and other remote users to designate an Alert Manager server even when they are not connected to your network If you have Active Directory Services installed on your computer clicking Brows...

Page 111: ...hosen a destination click OK to close the dialog box You can designate any directory on your network as a destination for Centralized Alerting messages but the directory must contain a copy of the file CENTALRT TXT in order for an Alert Manager server to relay the alert messages you send there If you enable Centralized Alerting Dr Solomon s Anti Virus sends alert messages as text files with the ex...

Page 112: ...r network Dr Solomon s Anti Virus comes packaged with a Management Information File AMG MIF that identifies Dr Solomon s Anti Virus alerting attributes to your DMI client application The DMI client in turn assigns an identifying number to the Dr Solomon s Anti Virus so that it can collect Dr Solomon s Anti Virus alert events and send them to a DMI administrative application In order for Dr Solomon...

Page 113: ...virus signatures and other information that Dr Solomon s anti virus products use to protect your computer against the thousands of computer viruses in circulation Dr Solomon s Software releases new DAT files weekly to provide protection against the approximately 500 new viruses that appear each month With this Dr Solomon s Anti Virus release Dr Solomon s Software has introduced a new incremental D...

Page 114: ... includes two utilities that you can use to schedule regular DAT file updates and product file upgrades directly from the Dr Solomon s Anti Virus Console AutoUpdate and AutoUpgrade Dr Solomon s Software recommends that you use these utilities as your primary methods to update or upgrade your software for workstations on your network after you download your files from the Network Associates website...

Page 115: ...tion to the weekly SuperDAT package that contains both current DAT files and a current scan engine Dr Solomon s Software will make available a SuperDAT package that consists only of DAT files This executable file minimizes the need for you to closely manage your DAT file updates It takes care of shutting down any active scan operations services or other memory resident software components that mig...

Page 116: ...rus free environment The Emergency Disk you create uses specialized DAT files that target boot sector and memory resident viruses which pose the greatest infection risk to software if they activate before your anti virus software can Dr Solomon s provides updates for these files that you can download directly from the AVERT website at http www mcafeeb2b com asp_set anti_virus avert tools asp Dr So...

Page 117: ... your remaining network nodes to pull the updated files from those servers you can Schedule network wide DAT file roll outs for convenient times and with minimal intervention from either administrators or network users Use the AutoUpdate Task Properties dialog box to determine when each network node will check your network server for updated files You might for example specify one convenient updat...

Page 118: ...er an update or run a program after an update whether you want it to keep track of its actions in a log file Property pages in the Automatic Update Properties dialog box control the options for your update task You can click each tab in turn to configure this task To display the Automatic Update dialog box follow these steps 1 Double click the AutoUpdate task in the Console task list to open its T...

Page 119: ...nge whether or not the AutoUpdate utility can connect with the site Initially the utility comes configured to connect only to the Network Associates FTP site You can add as many different sites as you need and alter the order in which AutoUpdate tries to connect to them from this dialog box The utility will try each site in turn starting from the top of the list until it successfully downloads new...

Page 120: ...in which the AutoUpdate utility should connect to the listed sites To position a site so that the utility tries it earlier select the site then click Move Up To designate a site as lower in priority select the site then click Move Down Update your files immediately from the sites listed in the update list using default configuration options or the options you chose for this task Click Update now T...

Page 121: ...ITY LOG TXT in the Dr Solomon s Anti Virus program directory whenever you stop the task or when you shut your system down If you would prefer to log this data to a different text file enter its path and filename in the text box provided or click Browse to locate the file The AutoUpdate utility will not generate a text file it will write only to an existing file 6 To minimize the log file size sele...

Page 122: ...an existing site click Add in the Automatic Update dialog box see Figure 6 1 on page 119 or select a listed site then click Edit Either action will open the Automatic Update Properties dialog box Figure 6 4 Figure 6 4 Automatic Update Properties dialog box Update Options page Next follow these steps 1 Enter a descriptive name in the Site Name text box that clearly identifies the new site An exampl...

Page 123: ... UNC notation you must either use the same account you used to log into your network or specify a user name and password to log into your network To use the current account select the Use Logged In Account checkbox NOTE On Windows NT Workstation v4 0 and Windows 2000 Professional systems selecting the Use Logged In Account checkbox has slightly different effects If you ve scheduled your file updat...

Page 124: ...e target server If your network uses a proxy server select the Use proxy server checkbox then enter the server name and the logical port it uses in the text boxes provided You can enter the name in UNC notation or as a domain name whichever is appropriate for your environment NOTE The AutoUpdate utility will not allow proxy connections that require challenge response proxy authentication Configuri...

Page 125: ...EAN DAT for example will become CLEAN DAT SAV Retrieve the Update file but do not perform the update Select this checkbox to have the utility download the ZIP archive that contains the new DAT files then save it in a location you specify instead of extracting it and installing it Selecting this checkbox also selects the Save the Update file for later usage checkbox in the After a Successful Update...

Page 126: ...of your Dr Solomon s Anti Virus and expose your computer or network to infection from newly emerging viruses and other malicious software Upgrades to Dr Solomon s Anti Virus program components can also cause incompatibilities with older DAT file versions These incompatibilities can in turn cause Dr Solomon s Anti Virus to behave unpredictably 2 Tell the AutoUpdate utility what you want it to do af...

Page 127: ...e dialog box click OK To close the dialog box without saving your changes click Cancel Understanding the AutoUpgrade utility Dr Solomon s Software revises Dr Solomon s Anti Virus and the Olympus scan engine regularly to add new detection and repair capabilities new features for manageability and flexibility and other enhancements that make it a better anti virus security tool Dr Solomon s Anti Vir...

Page 128: ...ify one convenient update time when you first deploy Dr Solomon s Anti Virus but set the AutoUpgrade utility to trigger at a random interval within 60 minutes of that time or set a schedule that phases in or rotates program file upgrades among different parts of the network To learn how to schedule the AutoUpdate task or other tasks see Enabling tasks on page 223 of the Dr Solomon s Anti Virus Use...

Page 129: ...de dialog box follow these steps 1 Double click the AutoUpgrade task in the Console task list to open its Task Properties dialog box Figure 6 6 Figure 6 6 AutoUpgrade Task Properties dialog box To learn how to set a password for this task see Working with the AutoUpgrade and AutoUpdate tasks on page 218 of the Dr Solomon s Anti Virus User s Guide To learn how to set a schedule for the task see Ena...

Page 130: ... not change whether or not the AutoUpgrade utility can connect with the site You will not see any sites listed initially because the AutoUpgrade utility does not come configured to connect to any upgrade site You must add the sites you need from the information you received when you purchased Dr Solomon s Anti Virus The AutoUpgrade utility can download new program files from any network share or F...

Page 131: ...e the changes you want to make then click OK to save them and return to this dialog box To see descriptions and instructions for configuring the available options see Configuring upgrade options on page 133 Remove an existing site from the update site list Select a site shown in the upgrade site list then click Delete Specify the order in which the AutoUpgrade utility should connect to the listed ...

Page 132: ...e 6 9 Automatic Upgrade dialog box Log Activity page 5 Select the Log activity into the Activity Log File checkbox By default the AutoUpgrade utility records what happens during update attempts and saves the record in the file UPDATE UPGRADE ACTIVITY LOG TXT in the Dr Solomon s Anti Virus program directory whenever you stop the task or when you shut your system down If you would prefer to log this...

Page 133: ...Click OK to save your changes and close the Automatic Upgrade dialog box Click Cancel to close the dialog box without saving your changes Configuring upgrade options To create a new update site or change the settings for an existing site click Add in the Automatic Upgrade dialog box see Figure 6 7 on page 130 or select a listed site then click Edit Either action will open the Automatic Upgrade Pro...

Page 134: ...t stops the connection attempt Next use Universal Naming Convention UNC notation to enter the path to the computer that holds the new files you want to download in the text box labeled Select a Computer and Directory You can also click Browse to locate the directory you want To use UNC notation you must either use the same account you used to log into your network or specify a user name and passwo...

Page 135: ...onymous FTP login checkbox To specify an account clear the Use anonymous FTP login checkbox then click FTP login information to enter a user name and password for an account that has access rights to the target server If your network uses a proxy server select the Use proxy server checkbox then enter the server name and the logical port it uses in the text boxes provided You can enter the name in ...

Page 136: ... checkbox also selects the Save the Upgrade files for later usage checkbox To tell AutoUpgrade where to save the program file archive enter a path and folder name in the text box below this checkbox or click Browse to locate a suitable folder You might want to use this option if you download new program files to a central server on your network and want individual client computers to download extr...

Page 137: ...XX refers to the SuperDAT version number included as part of the file name 2 Download the file AUTOUPG ZIP which you will find on the Network Associates FTP site in this location ftp username password ftp nai com licensed antivirus superdat tools NOTE Here username is your Network Associates corporate site access username and password is your corporate site access password To download these files ...

Page 138: ...restart the target computer if it must do so in order to finish updating or upgrading your anti virus software If you do not want the target computer to restart after it updates your files set the value of bReboot to zero or remove the statement from SETUP ISS If you do not tell the SuperDAT utility to restart the target computer either with this statement in the SETUP ISS file from the command li...

Page 139: ...tutes a medium on watch or high risk or about AVERT risk assessment in general visit the AVERT website at http www mcafeeb2b com asp_set anti_virus alerts ara asp A high prevalence virus threatens an outbreak situation IMPORTANT AVERT does not guarantee that it will make EXTRA DAT files available in all such situations AVERT researchers reserve the right to assess each situation and determine an a...

Page 140: ... s Anti Virus 140 Dr Solomon s Anti Virus For Dr Solomon s Anti Virus v4 5 and later releases copy any EXTRA DAT files you download to this directory C Program Files Common Files Network Associates Dr Solomon s Anti Virus Engine 4 0 xx ...

Page 141: ... components with a single button tell the WinGuard scanner and Dr Solomon s Anti Virus Console to load as soon as your computer starts set a ceiling for the number of scan targets the Dr Solomon s Anti Virus application can examine or exclude during a scan session limit the number of scan tasks that you can create configure and run from the Dr Solomon s Anti Virus Console You can also choose wheth...

Page 142: ...rus control panel options The control panel consists of two tabbed property pages that set out its options To choose your options follow these steps 1 Open the control panel then click the Service tab 2 To stop all active Dr Solomon s Anti Virus components click Stop If all Dr Solomon s Anti Virus components that normally load into memory the Console and the WinGuard scanner normally are inactive ...

Page 143: ... this service appears in the Services dialog box as AvSync Manager If your computer runs Windows 95 or Windows 98 this service is not directly accessible NOTE Dr Solomon s Software strongly recommends that you set the Dr Solomon s Anti Virus management service to load at startup If you do not you might not be able to start some Dr Solomon s Anti Virus components and you will lose the benefit of da...

Page 144: ...in the Dr Solomon s Anti Virus Console By default 100 items can appear in the list If you add more than 100 unique items to the exclusion list the Dr Solomon s Anti Virus application might affect your system performance You may not set the value here to fewer than five items 8 Select the Load on startup checkbox in the Console area to have the Dr Solomon s Anti Virus Console start as soon as you s...

Page 145: ...145 Using Dr Solomon s Anti Virus Administrative Utilities NOTE The Dr Solomon s Anti Virus management service must restart itself and all active Dr Solomon s Anti Virus components in order to implement any changes you make ...

Page 146: ...Using Dr Solomon s Anti Virus Administrative Utilities 146 Dr Solomon s Anti Virus ...

Page 147: ...support files to function including some that enable its various modules This table lists WinGuard scanner and related files Program files These files run directly as WinGuard components or are dedicated WinGuard library or support files Table B 1 WinGuard scanner program files File Function Location VSTAT EXE Handles program communication among WinGuard components displays WinGuard icon C Program...

Page 148: ...ws 2000 systems C Program Files Common Files Network Associates McShield MCSHIELD DLL Resource file for System Scan module Runs only on Windows NT and Windows 2000 systems C Program Files Common Files Network Associates McShield Res09 NAIANN DLL Support file for System Scan module Runs only on Windows NT and Windows 2000 systems C Program Files Common Files Network Associates McShield NAIFILTR SYS...

Page 149: ...Windows virtual device driver only on Windows 95 and Windows 98 systems C Windows System VSHINIT VXD WinGuard support file Initializes services for DOS protected mode interface Runs only on Windows 95 and Windows 98 systems C Windows System MCSCAN32 VXD Dr Solomon s scan engine Runs only on Windows 95 and Windows 98 systems C Windows System MCUTIL VXD Support file for System Scan module Runs only ...

Page 150: ... CCM_SCAN EXE Scans e mail you receive via Lotus cc Mail v7 x and earlier cc Mail systems C Program Files Network Associates Dr Solomon s Anti Virus WEBSCANX EXE Provides functionality for WinGuard Download Scan and Internet Filter modules Initializes WBHOOK32 DLL C Program Files Network Associates Dr Solomon s Anti Virus WBHOOK32 DLL Provides functionality for WinGuard Download Scan and Internet ...

Page 151: ...utilities for components C Program Files Network Associates Dr Solomon s Anti Virus AVSMCPA CPL Dr Solomon s Anti Virus control panel applet C Windows System or C Winnt System 32 RESDLL DLL Resource file for all components C Program Files Common Files Network Associates McPal MCSCAN32 DLL Dr Solomon s Scan engine file C Program Files Common Files Network Associates Dr Solomon s Anti Virus Engine 4...

Page 152: ...les Network Associates Dr Solomon s Anti Virus DAV_EXCL MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DAV_SCAN MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DEXCLDEF MFF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DSCANDEF MMF Memory map file for SYNCU...

Page 153: ...re dedicated Dr Solomon s Anti Virus application library or support files Dependent files The Dr Solomon s Anti Virus application requires these files to run at various points during its operation but these are not Dr Solomon s Anti Virus application program files or are not dedicated solely to Dr Solomon s Anti Virus application support Table B 4 Dr Solomon s Anti Virus application program files ...

Page 154: ... Program Files Network Associates Dr Solomon s Anti Virus VSUTIL DLL Provides common utilities for components C Program Files Network Associates Dr Solomon s Anti Virus AVSMCPA CPL Dr Solomon s Anti Virus control panel applet C Windows System or C Winnt System 32 RESDLL DLL Resource file for all Dr Solomon s Anti Virus components C Program Files Common Files Network Associates McPal MCSCAN32 DLL D...

Page 155: ...n Location SYNC_MAP MMF Memory map file for AVSYNCH DLL C Program Files Network Associates Dr Solomon s Anti Virus AVCONSOLE MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DAV_CONS MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DAV_EXCL MMF Memory map file for SYNCUTIL DLL C Program Files Network Asso...

Page 156: ...es Common Files Network Associates McPal AMG MIF Management Information File for use with Desktop Management Interface client application software C Program Files Common Files Network Associates McPal NAARCHIV DLL Library file for Dr Solomon s Anti Virus data compression routines C Program Files Common Files Network Associates McPal NAEVENT DLL Library file Handles event processing from desktop cl...

Page 157: ... Files Network Associates McPal Table B 8 Dr Solomon s Anti Virus control panel files File Function Location AVSYNMGR EXE The Dr Solomon s Anti Virus management service Initializes starts and stops all Dr Solomon s Anti Virus services and components Must run to enable all Dr Solomon s Anti Virus components C Program Files Network Associates Dr Solomon s Anti Virus AVSYNCH DLL Handles inter compone...

Page 158: ...OLE MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DAV_CONS MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DAV_EXCL MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DAV_SCAN MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomo...

Page 159: ... Program Files Network Associates Dr Solomon s Anti Virus SCRSCANP DLL ScreenScan control panel extension Provides the ScreenScan configuration property page in the Windows Display Properties dialog box C Program Files Network Associates Dr Solomon s Anti Virus Table B 11 ScreenScan dependent files File Function Location RESDLL DLL Resource file for all Dr Solomon s Anti Virus components C Program...

Page 160: ...DLL Support file for scan engine C Program Files Common Files Network Associates Dr Solomon s Anti Virus Engine 4 0 xx MESSAGES DAT Support file for scan engine Provides virus detection messages to engine C Program Files Common Files Network Associates Dr Solomon s Anti Virus Engine 4 0 xx Table B 12 Dr Solomon s Anti Virus Emergency Disk files File Function Location AUTOEXEC BAT MS DOS batch file...

Page 161: ...ncy Disk A COMMAND COM Command interpreter This file is a command shell that responds to command line input A GETREPLY EXE Application file This file processes output from the scan operation A KERNEL SYS System file A LICENSE DAT Dr Solomon s License file The command line scanner uses this to track use eligibility for this product A MESSAGES DAT Dr Solomon s resource file This file stores applicat...

Page 162: ...luding some related to the Dr Solomon s scan engine This table lists extension and related files NAMES DAT Dr Solomon s virus definition file This file is a smaller specialized version of the NAMES DAT file that other Dr Solomon s Anti Virus components use You may not use a NAMES DAT file from the Dr Solomon s Anti Virus program directory for the Emergency Disk A SCAN DAT Dr Solomon s virus defini...

Page 163: ... Exchange or Outlook extension that loads into the e mail client application This same file provides scan services for the WinGuard E Mail Scan module C Program Files Network Associates Dr Solomon s Anti Virus Table B 14 E Mail Scan dependent files File Function Location AVSYNMGR EXE Dr Solomon s Anti Virus management service Initializes starts and stops all Dr Solomon s Anti Virus services and co...

Page 164: ...nti Virus components C Program Files Common Files Network Associates McPal MCSCAN32 DLL Dr Solomon s Scan engine file C Program Files Common Files Network Associates Dr Solomon s Anti Virus Engine 4 0 xx RWABS16 DLL Support file for scan engine C Program Files Common Files Network Associates Dr Solomon s Anti Virus Engine 4 0 xx RWABS32 DLL Support file for scan engine C Program Files Common Files...

Page 165: ... Files Network Associates Dr Solomon s Anti Virus DSCANDEF MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus DVS_EXCL MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus VSCANGEN MMF Memory map file for SYNCUTIL DLL C Program Files Network Associates Dr Solomon s Anti Virus VSCANOAS MMF Memory map file for SY...

Page 166: ...Installed Files 166 Dr Solomon s Anti Virus ...

Page 167: ... your Dr Solomon s Anti Virus User s Guide or Creating and Configuring Scheduled Tasks in Chapter 6 of your Dr Solomon s Anti Virus User s Guide Running the Dr Solomon s Anti Virus Command Line program A typical installation of Dr Solomon s Anti Virus includes the Dr Solomon s Anti Virus Command Line program You can run Dr Solomon s Anti Virus Command Line either from a Windows MS DOS Prompt windo...

Page 168: ...er in DOS mode type win to start Windows or restart your computer as you would normally The tables on the following pages list all of the Dr Solomon s Anti Virus options available NOTE When you specify a file name as part of a command line option you must include the full path to the file if it is not located in the Dr Solomon s Anti Virus program directory The following table lists the options th...

Page 169: ...to use its full heuristics both program and macro MANALYZE targets macro viruses only PANALYZE targets program viruses only ANYACCESS On access scanning only Scans the boot sector whenever a disk is either read or written to executables any newly created files APPEND On demand scanning only Used with REPORT to append report message text to the specified report file instead of overwriting it BOOT O...

Page 170: ...scanning only Do not scan or add validation codes to the files listed in filename Use this option to exclude specific files from a scan operation List the complete path to each file that you want to exclude on its own line You may use wildcards and FILEACCESS On access scanning only Scans executable files when you modify them in any way including executing them This scan operation will not check t...

Page 171: ...o contact if Dr Solomon s Anti Virus locks the system MANALYZE On demand scanning only Extended memory required Sets the scanner s heuristic scanning features to target macro viruses only PANALYZE targets program viruses only ANALYZE targets both program and macro viruses MANY On demand scanning only Scans multiple disks consecutively in a single drive The scanner will prompt you for each disk Use...

Page 172: ...whenever the scanner finds a virus NOBREAK On demand scanning only Disables CTRL C and CTRL BREAK during scans Users will not be able to halt scans in progress with NOBREAK in use Use this option with LOG to create a meaningful audit trail of regularly scheduled scans NOCOMP On demand scanning only Extended memory required Skips checking of compressed executables created with the LZEXE or PkLite f...

Page 173: ...IRE On demand scanning only Disables the expiration date message if the Dr Solomon s Anti Virus data files are out of date NOMEM None Does not scan memory for viruses This greatly reduces scan time Use NOMEM only when you are absolutely certain that your computer is virus free NOREMOVE On access scanning only Prevents users from removing the WinGuard scanner from memory with the REMOVE switch NOWA...

Page 174: ...date does not change as the result of scanning RECONNECT On access scanning only Restores the WinGuard scanner after it has been disabled by certain drivers or memory resident programs REMOVE On access scanning only Unloads the WinGuard scanner from memory REPORT filename On demand scanning only Creates a report of infected files and system errors and saves the data to filename in ASCII text file ...

Page 175: ...ing or writing to a disk or hard disk file system or network problems problems creating reports and other system related problems Dr Solomon s recommends omitting PAUSE when using any report option SAVE On access scanning only Saves the command line options to the WinGuard INI file SUB On demand scanning only Scans subdirectories inside a directory By default when you specify a directory to scan r...

Page 176: ...st one screen at a time To redirect the VIRLIST output to a text file At the command prompt type scan VIRLIST filename txt Because the scanner can detect many viruses this file will be over 250 pages long This is too large for the MS DOS Edit program to open Dr Solomon s recommends using Notepad or another text editor to open the virus list XMSDATA On access scanning only Loads WinGuard data files...

Page 177: ...the Dr Solomon s Anti Virus on demand scanner follow these steps 1 Open an MS DOS Prompt window from within Windows or restart your computer in DOS mode 2 Change to the Dr Solomon s Anti Virus program directory in which the file SCAN32 EXE is located If you installed Dr Solomon s Anti Virus with its default options type this line at your command prompt to locate the correct directory C progra 1 ne...

Page 178: ...dow will open for you to set configuration options If you set the user interface option to UICONFIG the application will default to NOAUTOSCAN If you set the user interface option to UINONE the application will run with AUTOSCAN enabled Enter NOAUTOSCAN to suppress this behavior If you set the user interface option to UIEXONLY the application will run with AUTOSCAN enabled Enter NOAUTOSCAN to supp...

Page 179: ...pplication to scan only those files stored in the subfolders themselves The application will not scan files stored at the root level of the folder you designate To scan those files run the application with the NOSUB option NOSUB This option tells the Dr Solomon s Anti Virus application not to look for viruses in any subfolders inside the directory you specified as your scan target Note This option...

Page 180: ...lomon s Anti Virus application to automatically clean any infected files it finds The application cleans a file by removing virus code from it DELETE This option tells the Dr Solomon s Anti Virus application to automatically delete any infected files it finds MOVE This option tells the Dr Solomon s Anti Virus application to automatically move any infected files it finds to a predefined quarantine ...

Page 181: ...f the registry key gives you the task ID number SERVER This option tells the Dr Solomon s Anti Virus application on which computer you want it to start or stop a scan task Specify the computer name following the SERVER option on the same command line CANCEL This option adjusts the Windows registry so that it correctly records that a task is no longer running Use this option if your task fails but ...

Page 182: ...e Dr Solomon s Anti Virus application not to record an event when it moves an infected file to a quarantine folder LOGSETTINGS This option tells the Dr Solomon s Anti Virus application to record in the log file the current configuration options you ve chosen for this task NOLOGSETTINGS This option tells the Dr Solomon s Anti Virus application not to record the current task configuration options in...

Page 183: ... when the scan task began PRIORITY This option tells Dr Solomon s Anti Virus to give a higher or lower priority to this scan task relative to other system operations You must specify a priority level within the range 1 to 5 on the same command line A value of 1 assigns priority to all other system processes A value of 5 assigns the highest priority to the scan task Table C 2 SCAN32 EXE command lin...

Page 184: ...Using Dr Solomon s Anti Virus Command line Options 184 Dr Solomon s Anti Virus ...

Page 185: ... you are a corporate customer you must first have a grant number or product serial number to subscribe to the Enterprise SecureCast channel If you do not have a grant number please contact your purchasing agent your Value Added Reseller or Network Associates Customer Care at 972 308 9960 for assistance If you are already a registered Network Associates customer and do not know your grant number su...

Page 186: ...function properly with newer scan engines When the older scan engine version becomes obsolete Network Associates will discontinue development of DAT files for it You should upgrade your software before your current version becomes obsolete Which data files does the SecureCast service deliver With the SecureCast service you ll receive automatic downloads of these files New product upgrades The prod...

Page 187: ... 95 Windows 98 Windows NT or Windows 2000 At least 10MB free hard disk space plus sufficient space for product and other downloads An active Internet connection direct or dial up for a minimum of one hour per week Phase 1 Download and install BackWeb 1 To download the BackWeb client software connect to the Network Associates website at http www nai com asp_set anti_virus alerts register asp Next d...

Page 188: ... client welcome panel 3 Read the instructions and warnings on this panel then click Next to continue 4 The BackWeb license agreement appears Figure D 2 Figure D 2 BackWeb Software License Agreement panel 5 Click Yes to continue 6 The Choose Destination Location panel appears Figure D 3 on page 189 ...

Page 189: ...location for Setup to install the client software if you wish or click Browse to locate a suitable folder Click Next to continue Setup will begin to copy BackWeb program files to your computer As it does so it displays its progress When it has finished Setup displays the Connection Type panel Figure D 4 Figure D 4 Connection Type panel ...

Page 190: ...ears Figure D 5 Figure D 5 Communication Method panel 9 Choose a communication method Your choices are HTTP Choose this option if you can connect directly to the Internet without going through a proxy server Skip to Step 13 HTTP via proxy Choose this option if you connect to the Internet through a proxy server on your network Continue with Step 10 BackWeb Polite Agent Choose this option to connect...

Page 191: ...proxy server in the Proxy text box then enter the port the server uses for communication in the Port text box When you have finished click Next to continue The Proxy Authentication panel appears Figure D 7 on page 191 Figure D 7 Proxy Authentication panel 12 If the proxy server requires user authentication enter in the text boxes provided a user name and password with sufficient rights to permit y...

Page 192: ...e 2 Register with the Enterprise SecureCast service After you install the BackWeb client and start it the SecureCast service immediately opens the client application and sends its first InfoPak the SecureCast registration forms Figure D 9 Figure D 9 The Enterprise SecureCast client window InfoPaks downloaded to your system appear here SecureCast Flash Banner SecureCast channels to which you subscr...

Page 193: ...SecureCast service site or your site the window might not list any InfoPaks In that case minimize or close the BackWeb window After some time you will receive a Flash message Click the flashing message then continue with Step 2 To register for the Enterprise SecureCast channel follow these steps 1 If you see Register Now listed in the window double click it The SecureCast service Flash banner appe...

Page 194: ...rant number you received when you purchased your software or that you received from Network Associates Customer Service NOTE If your company is not a subsidiary of another company clear the Subsidiary of a Parent Company checkbox before you continue When you have entered your information click Next to continue If you did not clear the Subsidiary of a Parent Company checkbox the Parent Company Info...

Page 195: ...ur network requires you to connect to the Internet through a proxy server select the Use HTTP proxy at address checkbox then enter the server name or its Internet Protocol IP address in the text box provided Next verify that the correct port number appears in the Port text box or enter the correct port number If your proxy server requires you to sign on to use it select the Proxy requires users au...

Page 196: ...nnect to the Network Associates SecureCast service electronic customer care page If you are a corporate user the window resembles the one shown in Figure D 16 Figure D 16 SecureCast Electronic Corporate Customer Care You can use this page to download product updates and upgrades contact technical support and get other information directly from Network Associates The terms of your grant will determ...

Page 197: ...ibing from the SecureCast service You can stop the SecureCast service from delivering InfoPaks at any time you want to To do so right click the BackWeb icon in your Windows system tray then choose Start SecureCast from the shortcut menu that appears Next follow these steps 1 In the list box on the left side of the BackWeb client window see Figure D 9 on page 192 locate then select the listing for ...

Page 198: ...eCast Service to Get New Data Files 198 Dr Solomon s Anti Virus BackWeb client For a comprehensive guide to BackWeb including additional troubleshooting advice see the online BackWeb User s Manual http www backweb com ...

Page 199: ...xtended support under the Network Associates Corporate PrimeSupport program If you are a home user you can choose a plan geared toward your needs from the Home User PrimeSupport program PrimeSupport options for corporate customers The Corporate PrimeSupport program offers these four support plans PrimeSupport KnowledgeCenter plan PrimeSupport Connect plan PrimeSupport Priority plan PrimeSupport En...

Page 200: ...e PrimeSupport Connect plan gives you telephone access to essential product assistance from experienced technical support staff members With this plan you get In North America unlimited toll free telephone access to technical support from Monday through Friday 8 00 a m to 8 00 p m Central time In Europe the Middle East and Africa unlimited telephone access to technical support at standard long dis...

Page 201: ...ica unlimited telephone access to technical support at standard long distance or international rates Monday through Friday from 9 00 a m to 5 00 p m Central time Priority access to technical support staff members during regular business hours Responses within one hour for urgent issues that happen outside regular business hours including those that happen during weekends and local holidays Unrestr...

Page 202: ...ntervals you designate Committed response times from your support engineer who will respond to pages within half an hour to voice mail within one hour and to e mail within four hours Assignable customer contacts which allow you to designate five people in your organization who your support engineer can contact in your absence Optional beta site status which gives you access to the absolute latest ...

Page 203: ...T Europe Middle East Africa 9am 6pm local time Asia Pacific 8 a m 6 p m AEST Latin America 9 a m 5 p m CT Monday Friday after hours emergency access North America 8 a m 8 p m CT Europe Middle East Africa 9am 6pm local time Asia Pacific 8 a m 6 p m AEST Latin America 9 a m 5 p m CT Monday Friday after hours emergency access North America 8 a m 8 p m CT Europe Middle East Africa 9am 6pm local time A...

Page 204: ...wnload upgrade login asp Free 24 hour per day seven days per week access to online or electronic support through the Network Associates voice and fax system the Network Associates website and through such other electronic services as America Online and CompuServe To contact Network Associates electronic services Call the automated voice and fax system at 408 346 3414 Visit the Network Associates w...

Page 205: ...urs Monday through Friday from 7 00 a m to 6 00 p m Pacific time You call a toll free number use a credit card to take care of the transaction and get transferred to the technical support team within minutes Your cost will be 35 per incident Pay Per Minute Plan This plan gives you support only when you need it You get 900 number access to technical support staff members on a priority basis to mini...

Page 206: ...ay Per Minute Plan Online Upgrades Plan or Quarterly Disk CD Plan for your Network Associates products In North America call Network Associates Customer Service at 972 855 7044 In international locations contact the Network Associates retail technical support center closest to your location for more information Some support options may not be available in some locations Table E 2 International hom...

Page 207: ...s for network performance Network Associates consultants also develop and deliver custom solutions to help accomplish your project goals from lengthy large scale implementations to brief problem solving assignments Jumpstart Services For focused help with specific problem resolution or software implementation issues Network Associates offers a Jumpstart Service that gives you the tools you need to...

Page 208: ...on default asp Total Education Services Network Associates Total Education Services builds and enhances the skills of all network professionals through practical hands on instruction The Total Education Services technology curriculum focuses on network fault and performance management and teaches problem solving at all levels Network Associates also offers modular product training so that you unde...

Page 209: ...iDAT parcels that range in size from 100KB to 110KB depending on how many virus definitions come included This development means that you can download DAT file updates much faster and at a far lower cost in bandwidth than ever before Better still the AutoUpdate utility makes this process completely transparent it will download as many incremental DAT files as it needs to bring your software up to ...

Page 210: ...e be 40534054 UPD If you updated your DAT files every week the AutoUpdate utility would simply download the weekly file then install it alone to bring your DAT files up to date If you have not updated your software for three or four weeks however the AutoUpdate utility would need to download a number of UPD packages from which it could extract and install all of the virus definition files it neede...

Page 211: ...ile the AutoUpdate utility decodes the existing DAT files patches the downloaded iDAT files into them validates the data then re encodes the newly updated DAT files for use with your software NOTE Because the iDAT files patch the existing DAT files you may not download the iDAT files through the AutoUpdate utility and use the utility to save them for later updates You can download the UPD packages...

Page 212: ...the SuperDAT utility to a central server on your network then configure the AutoUpdate copies on your network computers to download and install the complete DAT set and the current scan engine This brings your network to a workable baseline state You can then download and install iDAT files to keep current 2 From the baseline state use a web browser or FTP client software each week to download new...

Page 213: ...e this feature to send out a standard AutoUpdate configuration with a standard update schedule but still prevent network traffic bottlenecks that might otherwise result when all of the computers on your network simultaneously try to update their DAT files If some of your client computers are off or if they do not have the Dr Solomon s Anti Virus Console running the AutoUpdate utility will resume i...

Page 214: ...tal vs full DAT update Q What happens if my existing DAT files are very old Will incremental DAT file updating still work A The AutoUpdate utility decides which process to use It downloads iDAT files only if your existing DAT file set is no more than 15 weeks out of date After that point it becomes more efficient to download a full DAT file set Network configuration issues Q Do all the machines I ...

Page 215: ...ormally Dr Solomon s posts updated DAT files on a weekly basis You may however check more or less often as your network security needs require Be aware that your risk of virus infection grows as the period between updates to the virus data files grows ...

Page 216: ...Understanding iDAT Technology 216 Dr Solomon s Anti Virus ...

Page 217: ...17 128 using iDAT files with 209 AutoUpgrade advanced options for configuring 135 to 137 number of connection attempts made for update sites 134 options for configuring 127 to 137 use of with SuperDAT utility 137 to 139 B batch files running after successful updates 127 BIOS possible VirusScan conflicts with anti virus features of 84 BOOTSCAN EXE use of on Emergency Disk 80 C Command line options ...

Page 218: ...les 163 program files 163 temporary files 164 E Mail Scan program component default responses when virus found 92 to 94 Emergency DAT files location and use of 116 Emergency Disk creating on uninfected computer 80 use of BOOTSCAN EXE on 80 use of to reboot system 80 Enterprise SecureCast 185 features of 187 setting up 197 support resources for 197 system requirements for 187 troubleshooting 197 un...

Page 219: ...tion aborting if virus detected during 79 logging 67 silent 66 specific features 68 testing effectiveness of 59 installation customization 75 installing to a custom directory 68 installing via SMS 74 installing via Tivoli 74 installing via ZENworks 75 Internet Filter module default response options for 90 L log file limiting size of 121 132 UPDATE UPGRADE ACTIVITY TXT as 121 132 M Management Editi...

Page 220: ...ute plan 205 Quarterly Disk CD plan 205 Small Office Home Office Annual Plan 205 Professional Consulting Services description of 207 program components included with VirusScan 29 to 33 programs running after successful updates 127 proxy servers working through to obtain updates and upgrades 124 135 R rebooting 70 rebooting with the McAfee Emergency Disk 80 registry keys installed 147 remover actio...

Page 221: ...ng 107 Setup silent and record modes using 66 aborting if virus detected during 79 SETUP EXE renaming SuperDAT packages for use with AutoUpgrade 139 SETUP ISS file use of for SuperDAT utility upgrades 139 software conflicts as potential cause for computer problems 83 software updates and upgrades website address for obtaining 204 SuperDAT utility use of for upgrade strategy 115 use of in conjuncti...

Page 222: ...vices 204 testing your installation 59 Tivoli installing VirusScan 74 Total Education Services description of 207 Total Service Solutions contacting 207 Total Virus Defense VirusScan as component of 26 training for Network Associates products xx 207 scheduling xx troubleshooting SecureCast firewall problems 197 registration problems 197 U uninfected computer use of to create Emergency Disk 80 Univ...

Page 223: ...ult from 83 removing before installation necessity of and steps for 79 from infected files 79 to 94 reporting new strains to McAfee xx viewing information about 94 to 96 VirusScan as component of Total Virus Defense suite 26 BIOS anti virus features potential conflicts with 84 command line options 167 command line examples 177 command line options 167 components included with 29 to 33 default resp...

Page 224: ...tions for 89 to 90 E mail Scan module default response options for 88 to 89 Internet Filter module default response options for 90 System Scan module default response options for 85 to 87 what it does 105 Vshield components included with VirusScan 29 to 33 VShield scanner dependent files 150 program files 147 temporary files 152 W website Network Associates technical support via 204 Z ZENworks ins...

Reviews: