home *** CD-ROM | disk | FTP | other *** search
Text File | 1998-07-22 | 45.8 KB | 1,529 lines |
- What's New in McAfee VirusScan for Windows 9x v3.1.9 (3107a)
- Copyright (c) 1994-1998 by Network Associates, Inc.
- and its Affiliated Companies. All Rights Reserved.
-
-
- Thank you for using McAfee VirusScan for Windows 9x. This
- What's New file contains important information regarding the
- current version of this product. Network Associates strongly
- recommends that you read the entire document.
-
- Network Associates welcomes your comments and suggestions.
- Please use the information provided in this file to contact
- us.
-
- ___________________
- WHAT'S IN THIS FILE
-
- - New Features
- - Known Issues
- - Installation
- - Documentation
- - Frequently Asked Questions
- - Contacting Network Associates
-
- ____________
- NEW FEATURES
-
- 1. This version of VirusScan includes improved cleaning
- for Microsoft Excel files infected with the Laroux
- virus.
-
- 2. The new AutoUpdate feature (corporate version only)
- allows you to configure VirusScan so that it
- effortlessly updates .DAT files and upgrades the
- entire product. VirusScan can update your .DAT files
- and upgrade itself automatically or at intervals you
- choose, either from a particular FTP site or from a
- computer on your network that you specify with a UNC
- pathname. VirusScan also functions in conjunction with
- proxy servers.
-
- Note: VirusScan comes preconfigured with a default
- AutoUpdate FTP site. You can change this site to one
- you choose or, for most of your client applications,
- to a particular server on your network. Network
- Associates recommends that you AutoUpdate one copy of
- VirusScan from a server on your network, then use that
- server to distribute updates to your client machines.
- This method guarantees you faster rollout. You must
- restart each machine you have updated in order to
- use the new .DAT files.
-
- 3. VirusScan's on-access and on-demand scanners include
- full support for floppy disk scanning on LS-120 drives.
-
- 4. VirusScan and VShield can now send Desktop Management
- Interface (DMI) alerts to desktop or network management
- applications that support the DMI standard. This
- capability supplements each program's existing alert
- options.
-
- 5. VirusScan scans files compressed in most of the popular
- file formats available on the PC platform. When it
- detects an infection in a file compressed in the ZIP,
- LHA, or UUencode format, VirusScan can clean, delete,
- or move the file. VirusScan cannot clean, delete, or
- move an infected file compressed in .CAB or in ZIP-SFX
- format, which might include an Authenticode certification.
- Network Associates recommends that you first decompress
- files encoded in either of these formats before running
- a VirusScan clean operation on them.
-
- 6. VirusScan features improved technology for detecting
- polymorphic viruses. This new technology uses the file
- POLYSCAN.DAT, which replaces the file MCALYZE.DAT.
-
- 7. VirusScan scans files embedded within Microsoft Office
- files, including Microsoft Word and Microsoft Excel
- files.
-
- 8. VirusScan can detect macro virus infections in
- password-protected Microsoft Word 97 files in all
- languages that Word supports.
-
- 9. If an infecting virus plants its own password in a
- password-protected Word 97 file, VirusScan cleans
- the file and removes the password that the virus
- planted. If, on the other hand, the infecting virus
- cannot plant its own password, VirusScan cleans the
- password-protected Word 97 file without disturbing
- its user-assigned password.
-
- * NEW VIRUSES DETECTED *
-
- The 3107a .DAT files included with this release of VirusScan
- detect the following 173 new viruses:
-
- AI22.1659
- ALEVIR.2349
- BACHKHOA.4426
- BOBO.1363
- BOOM.C:DE
- BW.709
- CAFE.667
- CAP.FP
- CAP.FQ
- CAP.FR
- CAP.FS
- CAP.FT
- CAP.FU
- CAP.FV
- CAP.FW
- CAP.FX
- CAP.FY
- CAP.FZ
- CAP.GA
- CAP.GB
- CAP.GC
- CAP.GD
- CAP.GE
- CAP.GF
- CAP.GG
- CAP.GH
- CAP.GI
- CAP.GJ
- CAP.GK
- CAP.GL
- CAP.GM
- CAP.GN
- CAP.GO
- CAP.GP
- CAP.GQ
- CAP.GR
- CAP.GS
- CAP.GT
- CAP.GU
- CAP.GV
- CHACK.B
- CHACK.C
- CLASS.A:DR DROPPER
- COLORS.CB
- CONCEPT.CK
- CONCEPT.CL
- COUNTER.C
- CRAZY.B
- DELTEXT.A
- DISCO.D
- DJIN.133
- DMV.K
- DMV.NEWVAR1
- DUNE.728
- EMT.B
- ERASER.U
- EVUL.109
- EVUL.264
- EVUL.436
- EVUL.480
- EXORCIST.212
- F117.1079
- FELIZ.1060
- FIVEA.A
- FLIP.BOOT2
- GLEW.4245
- GROOV.A
- GROOV.B
- GROOV.C
- HAZARD.A
- HELL.797
- HLLP.11712
- IVANA.A
- JOHNNY.V
- KITTY.A
- KITTY.B
- KOMPU.L
- LAMAH.B:BR
- MACARONI.C:DE
- MDMA.BE
- MDMA.BG
- MICROELEPHANT.457
- MIRC.DROPPER
- MTF.B
- MUCK.BF
- MUCK.BG
- MUCK.BH
- MUCK.BI
- MUCK.BJ
- MUCK.BK
- MUCK.BL
- NICEDAY.W
- NIKNAT.J
- NIKNAT.K
- NIKNAT.L
- NJ-WMVCK2.U:DE
- NOCHANCE.A
- NOCHANCE.B
- NOCHANCE.D
- NPAD.HL
- NPAD.HM
- NPAD.HN
- NPAD.HO
- NPAD.HP
- NPAD.HQ
- NPAD.HR
- NPAD.HS
- NPAD.HT
- NPAD.HU
- NPAD.HV
- NPAD.HW
- NPAD.HX
- NPAD.HY
- NPAD.HZ
- NPAD.IA
- NPAD.IB
- NPAD.IC
- NPAD.ID
- NPAD.IE
- NUCLEAR.AB
- OKSANA.1843
- OMED.544
- PAYCHECK.L
- POLYPOSTER.A
- PS-MPC.564
- PS-MPC.564 DROPPER
- RAZER.C
- REVENGER.505
- RS.1254
- RS.1470
- SCHUMANN.Q
- SCHUMANN.R
- SCHUMANN.S
- SCHUMANN.V
- SCHUMANN.W
- SHOWOFF.DF
- SHOWOFF.DG
- SHOWOFF.DH
- SHOWOFF.DI
- SMALLETERNITY.156
- SOLDIER.611
- SPY.B
- SRX.2304
- STUPID.A
- SUIT.1167
- TEMPLE.Q
- TEMPLE.R
- TEQUILA.2468.DROPPER
- TWNO.AB:TW
- VAMPIRE.G:TW
- VENENO.C:ES
- VMPCK1 :KIT.A
- VMPCK1 :KIT.B
- VRN.2276
- W32.CIH.SPACEFILLER
- W95/HPS
- W95/HPS.DROPPER
- WAZZU.EF
- XF/PAIX(DAMAGE)
- XM/DELTA.E
- XM/LAROUX.DK
- XM/LAROUX.DN
- XM/LAROUX.DN.DR
- XM/LAROUX.NEWVAR2
- XM/LAROUX.NEWVAR3
- XM/LAROUX.NEWVAR4
- XM/NEG.A
- XM/TRASHER.A
- XM/TRASHER.B
- XM97/POLICE.A
- XM97/RIOTS.A
- ZMK.J
- ZWICKAU.505
-
-
- * NEW VIRUSES CLEANED *
-
- The 3107a .DAT files clean these 138 new viruses:
-
- BOBO.1363
- BOOM.C:DE
- CAP.FP
- CAP.FQ
- CAP.FR
- CAP.FS
- CAP.FT
- CAP.FU
- CAP.FV
- CAP.FW
- CAP.FX
- CAP.FY
- CAP.FZ
- CAP.GA
- CAP.GB
- CAP.GC
- CAP.GD
- CAP.GE
- CAP.GF
- CAP.GG
- CAP.GH
- CAP.GI
- CAP.GJ
- CAP.GK
- CAP.GL
- CAP.GM
- CAP.GN
- CAP.GO
- CAP.GP
- CAP.GQ
- CAP.GR
- CAP.GS
- CAP.GT
- CAP.GU
- CAP.GV
- CHACK.B
- CHACK.C
- CLASS.A:DR DROPPER
- COLORS.CB
- CONCEPT.CK
- CONCEPT.CL
- COUNTER.C
- CRAZY.B
- DELTEXT.A
- DISCO.D
- EMT.B
- ERASER.U
- FIVEA.A
- GROOV.A
- GROOV.B
- GROOV.C
- HAZARD.A
- IVANA.A
- JOHNNY.V
- KITTY.A
- KITTY.B
- KOMPU.L
- LAMAH.B:BR
- MACARONI.C:DE
- MDMA.BE
- MDMA.BG
- MTF.B
- MUCK.BF
- MUCK.BG
- MUCK.BH
- MUCK.BI
- MUCK.BJ
- MUCK.BK
- MUCK.BL
- NICEDAY.W
- NIKNAT.J
- NIKNAT.K
- NIKNAT.L
- NJ-WMVCK2.U:DE
- NOCHANCE.A
- NOCHANCE.B
- NOCHANCE.D
- NOKERNEL.6000
- NPAD.HL
- NPAD.HM
- NPAD.HN
- NPAD.HO
- NPAD.HP
- NPAD.HQ
- NPAD.HR
- NPAD.HS
- NPAD.HT
- NPAD.HU
- NPAD.HV
- NPAD.HW
- NPAD.HX
- NPAD.HY
- NPAD.HZ
- NPAD.IA
- NPAD.IB
- NPAD.IC
- NPAD.ID
- NPAD.IE
- NUCLEAR.AB
- PAYCHECK.L
- POLYPOSTER.A
- RAZER.C
- SCHUMANN.Q
- SCHUMANN.R
- SCHUMANN.S
- SCHUMANN.V
- SCHUMANN.W
- SHOWOFF.DF
- SHOWOFF.DG
- SHOWOFF.DH
- SHOWOFF.DI
- SRX.2304
- STUPID.A
- TEMPLE.Q
- TEMPLE.R
- TEQUILA.2468.DROPPER
- TWNO.AB:TW
- VAMPIRE.G:TW
- VENENO.C:ES
- VMPCK1 :KIT.A
- VMPCK1 :KIT.B
- W95/HPS
- W95/HPS.DROPPER
- WAZZU.EF
- XF/PAIX(DAMAGE)
- XM/DELTA.E
- XM/LAROUX.DK
- XM/LAROUX.DN
- XM/LAROUX.DN.DR
- XM/LAROUX.NEWVAR2
- XM/LAROUX.NEWVAR3
- XM/LAROUX.NEWVAR4
- XM/NEG.A
- XM/TRASHER.A
- XM/TRASHER.B
- XM97/POLICE.A
- XM97/RIOTS.A
- ZMK.J
-
- ____________
- KNOWN ISSUES
-
- 1. If you uninstall McAfee VirusScan, Windows changes your
- default screen saver to None. To choose a screen saver
- to use, right-click anywhere on your desktop, then
- choose Properties from the shortcut menu that appears.
- Next, click the Screen Saver tab in the Display
- Properties dialog box, then choose a new screen saver
- from the Screen Saver list. Click OK to use the screen
- saver you chose.
-
- 2. Using MS-DOS memory managers might cause VirusScan to
- falsely detect viruses in memory. Since Windows 95 no
- longer requires MS-DOS memory managers, you can
- eliminate false warnings by preceding each line in your
- CONFIG.SYS file that includes settings for an MS-DOS
- memory manager with REM. This deactivates the memory
- manager. To learn more about working with your
- CONFIG.SYS file, see your MS-DOS or Windows
- documentation.
-
- 3. To create a VirusScan Emergency Disk, you must first
- create a bootable floppy disk using the following
- command at a DOS prompt:
-
- c:\>FORMAT A: /S/U
-
- 4. If you use a password to protect VShield or any scan
- task you have scheduled, VirusScan will ask you for
- that password whenever you start any program you have
- not excluded from scanning. Use your mouse to click
- inside the text box provided in order to enter the
- password--keyboard shortcuts will not work. Microsoft
- acknowledges this issue in its Knowledge Base Article
- ID #Q84133. Next, click OK to use the password you
- enter. To close the password verification dialog box
- without entering a password, click Cancel.
-
- 5. ScreenScan will stop scanning after it detects a virus
- and will prompt you to launch VirusScan. If you have
- additional viruses on your system, ScreenScan will not
- notify you until it next runs. Network Associates
- recommends that you scan and clean your entire system
- with VirusScan whenever ScreenScan detects a virus.
-
- 6. Disk defragmentation programs move files as they work
- to maximize hard disk efficiency. If you have VShield,
- VirusScan, or other applications active during a disk
- defragmentation operation, your disk defragmentation
- program might tell you that it cannot find the active
- application files. This is normal and does not mean
- that the files do not exist. To avoid error messages
- like this, close all open applications and disable
- VShield, then run your disk defragmentation operation
- again.
-
- 7. If you unzip a virus-infected file into a directory
- on a Novell server, VShield does not detect the
- infection as the file is created. For maximum security,
- use VirusScan to scan the Novell server after you have
- extracted the files to the server.
-
- 8. If you press CTRL+ALT+DEL to shut down a Windows 95
- system with VShield or any other VxD enabled, Windows
- does not shut down. Instead, Windows disables VShield
- or the active VxD. To shut down your computer, you must
- press CTRL+ALT+DEL again.
-
- 9. If you run two or more instances of Scan32.EXE, and
- scan two or more Microsoft cabinet (.CAB) files
- simultaneously, Scan32.EXE will terminate with a page
- fault.
-
- ____________
- INSTALLATION
-
- * INSTALLING VIRUSSCAN *
-
- 1. Insert the floppy disk or compact disc with your copy
- of VirusScan into your floppy disk drive or CD-ROM
- drive.
-
- If you downloaded a compressed copy of VirusScan
- from the Network Associates website or other electronic
- service, create a temporary directory on your hard disk
- or on a disk available on your network, then extract
- the files you downloaded into that directory.
-
- 2. Click Start in the Windows taskbar, then choose Run.
-
- 3. Type x:\setup.exe in the Run dialog box to start the
- installation utility from a floppy disk. To start the
- utility from a CD-ROM, type x:\win95\setup.exe. In both
- cases, x is the drive letter that designates your
- floppy drive or your CD-ROM drive.
-
- If you extracted files that you downloaded to your
- hard disk or to a disk on your network, specify the
- path to the correct directory. For example, type
- C:\DOWNLOAD\SETUP.EXE.
-
- 4. Click OK to continue.
-
- The VirusScan installation wizard will start. Follow
- the instructions shown on each wizard pane to choose
- the VirusScan options you want.
-
- 5. When you finish your installation, restart your
- computer.
-
-
- * PERFORMING A SILENT INSTALLATION *
-
- To install copies of VirusScan with a uniform configuration
- on client computers on your network, run SETUP.EXE with the
- -s option -- that is, type SETUP.EXE -s in the Run dialog
- box. This tells VirusScan to install itself with little or
- no interaction with end users. If you do not customize
- this installation, VirusScan installs itself with all of
- the default or "typical" installation settings activated.
-
- Network administrators can customize the silent installation
- feature by following these steps:
-
- 1. Check the Windows directory to ensure that a file named
- SETUP.ISS does not already exist. If one does, rename
- it, back it up, or delete it.
-
- 2. Run SETUP.EXE with the -r option, (i.e., SETUP.EXE -r)
- to install it to your computer or to a chosen server
- on your network.
-
- 3. Select the components and choose the settings you want
- each of your client computers to have. The VirusScan
- installation utility will record your choices.
-
- Note: If VirusScan detects a virus as it records your
- choices, both the recording operation and the
- installation will abort.
-
- Result: The VirusScan installation utility creates a
- SETUP.ISS file in the Windows directory. This file
- lists the options you chose during your installation.
-
- 4. Finish the installation. If you have chosen all of
- your options correctly, move to Step 5. To change
- any of the options you chose, see the following
- notes.
-
- The .ISS file specifies an installation directory
- in the szDir parameter listed beneath the
- [SdSetupType-0] header. The installation directory
- you specify here overrides the default installation
- directory on each client machine, which might vary
- on machines that run different operating systems.
- Having the same directory name on every client helps
- to ease administration; for example, you might assign
- all client machines the directory C:\ANTIVIRUS.
-
- If, however, you want to allow SETUP.EXE to determine
- where to locate the installed files, follow these steps
- to modify the SETUP.ISS file so that the target machine
- will disregard the szDir parameter:
-
- A. Locate the section [SdSetupType-0] in the SETUP.ISS
- file and go to the line: Result = xxx.
- The actual value will most likely be 301, 302,
- or 303, depending on which options you selected
- when you recorded your installation.
-
- B. Add 100 to this number so that, for example, 301
- becomes 401. This tells each target machine to
- disregard the szDir and assign a directory according
- to its own particular operating system.
-
- 5. Copy the installation files onto a local or a mapped
- network drive, then rename, back up, or delete the
- SETUP.ISS file stored in that directory. You'll use
- the new SETUP.ISS file you just created instead.
-
- Note: You cannot perform a silent installation from
- files that span more than one floppy disk or other
- storage medium because the installation utility will
- prompt the end user on each client computer for the
- next disk.
-
- 6. Copy the new SETUP.ISS from the Windows directory to
- the directory that contains the installation files.
-
- Note: The SETUP.ISS file is unique for each VirusScan
- product. You cannot, for example, use a SETUP.ISS file
- created during a VirusScan for Windows 95 installation
- to control a VirusScan for Windows NT installation.
-
- 7. Run SETUP.EXE with the -s option--that is, type
- SETUP.EXE -s in the Run dialog box.
-
- Note: If you do not specify a "recorded" answer for
- all dialog boxes during the initial installation, the
- silent installation will fail.
-
- 8. When the silent installation is complete, the computer
- reboots automatically if you did so during your
- recorded installation. The default SETUP.ISS script
- reboots the target computer automatically.
-
-
- * PRIMARY PROGRAM FILES FOR VIRUSSCAN *
-
- Note: The specific files you see on your computer will
- depend on the type of license you purchased. Your
- VirusScan copy might not include some of these files.
-
- Files located in the Install directory:
- =======================================
-
- 1. Installed for VShield/Scan32/DOS/ScreenScan:
-
- README.1ST = License and registration
- information
- CLEAN.DAT = Virus clean definition data
- POLYSCAN.DAT = Data file for advanced
- polymorphic virus detection
- NAMES.DAT = Virus names definition data
- SCAN.DAT = Virus scan definition data
- VS-MAIN.HLP = VirusScan help file
- VSCHED.EXE = VirusScan console scheduler
- file
- DMIALERT.DLL = Library file
-
- ADVGUI.DLL = Advanced interface library
- file
- MCGUI32.DLL = AV Console library file
- S95EXT.DLL = Library file
- CFGCOM32.DLL = Library file
- INETWH16.DLL = Internet library help file
- INETWH32.DLL = Internet library help file
-
- AVCONSOL.EXE = VirusScan Console program
- file
- MCECOM.EXE = Automatic product update
- program file
- CHKVXD.EXE = VShield virtual device
- CONFIG32.EXE = VirusScan configuration
- program
- SETBROWS.EXE = Set browser program
- VIRLST32.EXE = McAfee Virus List
- VALIDATE.EXE = McAfee file validation
- program
- VSECOMR.EXE = Electronic Commerce program
- file
- WCMDR.EXE = Windows Commander program
- driver checking utility
-
- AVCONSOL.HLP = AV Console help file
- SCAN32.HLP = Scan32 help file
- PHONELST.INI = Electronic commerce file
-
- AVCONSOL.INI = AV Console initialization
- file
- WCMDR.INI = Windows Commander
- configuration settings
- WCMDRSIL.INI = unInstallShield helper
- configuration
-
- DELSL?.ISU = Uninstall file
-
- PACKING.LST = Packing list
-
- FAXFORM.TXT = Fax registration form
- RESELLER.TXT = Network Associates
- authorized resellers
- WHATSNEW.TXT = What's New document
-
-
- 2. Installed for VShield/Scan32:
-
- DPMI16.DLL = 16-bit DOS protected mode
- interface library
- DPMI32.DLL = 32-bit DOS protected mode
- interface library
- POLYSCAN.DLL = Library files for advanced
- polymorphic virus detection
- MCARCHIV.DLL = Compressed file scanning
- library
- MCKRNL32.DLL = Library files
- MCSCAN32.DLL = Library files
- MCUTIL32.DLL = Library files
- VSECOM.DLL = Library files
-
- 3. Installed for VShield:
-
- CONFIG32.EXE = VShield configuration
- program
- VSHWIN32.EXE = VShield engine
- DEFAULT.VSH = Default VShield settings
-
- 4. Installed for Scan32:
-
- SHUTIL.DLL = Run-time support library
- SCAN32.EXE = VirusScan program
- DEFAULT.VSC = Default Scan32 settings
- ALLDRIVE.VSC = Scan32 settings file
- SCAN_C.VSC = Scan32 settings file
-
- 5. Installed for Emergency Disk Creation Utility:
-
- SCAN.EXE = MS-DOS scan program
- SCANPM.EXE = Protected mode scanner
- EDISK.EXE = Emergency Disk creation
- utility
- GETREPLY.EXE = Emergency diskette program
- component
- EDAT.1 = Emergency Disk batch file
- EDAT.2 = Emergency Disk program
- information file
- EDAT.3 = Emergency Disk file
- EDAT.4 = Emergency Disk file
- EDAT.5 = Emergency Disk file
- EDAT.6 = Emergency Disk file
- ESCAN.BAT = Emergency Disk file
- EDISK.SCR = Emergency Disk script
- MCKRNL16.DLL = Emergency Disk library file
- MCUTIL16.DLL = Emergency Disk library file
- EMSCAN.DAT = Virus scan definition data
- EMCLEAN.DAT = Virus clean definition data
- EMNAMES.DAT = Virus names definition data
-
- 6. Installed for ScreenScan:
-
- MCKRNL32.DLL = Library file
- MCUTIL32.DLL = Library file
- SCRSCANP.DLL = Library file
- SCRSCANR.DLL = Library file
- DUNZIP32.DLL = ScreenScan compression
- library file
- DZIP32.DLL = ScreenScan compression
- library file
- SCRSCAN.EXE = ScreenScan program file
- SCRSCAN.HLP = ScreenScan help file
-
- Files located in WINDOWS directory:
- ==========================================
-
- SECCAST.ICO = Secure Cast icon
-
-
- Files located in WINDOWS\SYSTEM directory:
- ==========================================
-
- 1. Installed for VShield/Scan32/DOS:
-
- MCAFECOM.DLL = Network Associates Electronic
- Commerce library file
-
- 2. Installed for VShield/Scan32:
-
- MCKRNL.VXD = Detection virtual device
- driver
- MCSCAN32.VXD = Detection virtual device
- driver
- MCUTIL.VXD = Support virtual device
- driver
-
- 3. Installed for VShield:
-
- VSHIELD.VXD = Detection virtual device
- driver
- VSHINIT.VXD = VShield virtual device driver
-
- Files located in the WINDOWS\HELP directory:
- ============================================
-
- 1. Installed for VShield:
-
- VSHLDCFG.HLP = VShield help
-
- 2. Installed for Scan32:
-
- SCANEXT.HLP = Scan32 Extension help
-
- * TESTING YOUR INSTALLATION *
-
- The Eicar Standard AntiVirus Test File is a combined
- effort by anti-virus vendors throughout the world to
- implement one standard by which customers can verify
- their anti-virus installations.
-
- To test your installation, copy the following line
- into its own file, then save the file with the name
- EICAR.COM.
-
- X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
-
- The file size will be 69 or 70 bytes.
-
- Next, start VirusScan and allow it to scan the
- directory that contains EICAR.COM. When VirusScan
- scans this file, it will report finding the
- EICAR-STANDARD-AV-TEST-FILE virus.
-
- Note that this file is NOT A VIRUS. Delete the file
- when you have finished testing your installation to
- avoid alarming unsuspecting users.
-
- ______________________
- UNINSTALLING VIRUSSCAN
-
- Network Associates recommends using the VirusScan
- uninstall utility provided with the program. To start
- the uninstall utility, click Start in the Windows taskbar,
- point to Programs, then to McAfee VirusScan. Next, choose
- unInstall VirusScan.
-
- To remove VirusScan without using the uninstall utility,
- follow these steps:
-
- 1. Remove references to VirusScan from your AUTOEXEC.BAT
- file. To do so, follow these steps:
-
- A. Start the Windows system editor. Click Start in the
- Windows taskbar, then choose Run. Type SYSEDIT in the
- Run dialog box, then click OK.
-
- A set of text files will open on your screen. Your
- AUTOEXEC.BAT file should appear as the first or
- topmost window in this set. If it does not, click
- the title bar for the AUTOEXEC.BAT window.
-
- B. Locate and delete the text of each line in the
- AUTOEXEC.BAT file that refers to VirusScan. Be sure
- also to delete @IF ERRORLEVEL 1 PAUSE if it appears
- in the file.
-
- To help you locate all references to VirusScan, choose
- Find from the SYSEDIT Search menu, then type VirusScan
- in the dialog box that appears.
-
- C. When you have deleted all VirusScan references, choose
- Save from the SYSEDIT File menu to save your changes,
- then choose Exit from the File menu to quit the SYSEDIT
- application.
-
- 2. Remove VirusScan icons from the Start menu. To do this,
- follow these steps:
-
- A. Click Start in the Windows taskbar, point to Settings,
- then choose Taskbar.
-
- B. Click the Start Menu Programs tab.
-
- C. Click the Remove button.
-
- D. Select the McAfee VirusScan folder in the list that
- appears in the Remove Shortcuts/Folders dialog box,
- then click Remove.
-
- E. Windows will ask you to confirm your action. Click
- Yes to continue.
-
- F. Click Close to close the Remove Shortcuts/Folders
- dialog box, then click OK to close the Taskbar
- Properties dialog box.
-
- 3. Edit the Registry. To do this, follow these steps:
-
- A. Start the Windows Registry editor. Click Start in
- the Windows taskbar, then choose Run. Type REGEDIT
- in the Run dialog box, then click OK.
-
- B. Click the title bar of the HKEY_CLASSES_ROOT window
- to bring it to the foreground, then delete the key
- "VirusScan" from these locations:
-
- comfile\\shell\\VirusScan
- Directory\\shell\\VirusScan
- Drive\\shell\\VirusScan
- exefile\\shell\\VirusScan
- Excel.Addin\\shell\\VirusScan
- Excel.Chart.5\\shell\\VirusScan
- Excel.Chart.8\\shell\\VirusScan
- Excel.Macrosheet\\shell\\VirusScan
- Excel.Sheet.5\\shell\\VirusScan
- Excel.Sheet.8\\shell\\VirusScan
- Excel.Template\\shell\\VirusScan
- Excel.Workspace\\shell\\VirusScan
- Excel.XLL\\shell\\VirusScan
- WinZip\\shell\\VirusScan
- Word.Document.6\\shell\\VirusScan
- Word.Document.8\\shell\\VirusScan
- Word.Template\\shell\\VirusScan
-
- Delete the key "VSConfigFile" and the key
- "VSHConfigFile"
-
- C. Click the title bar of the HKEY_LOCAL_MACHINE window
- to bring it to the foreground. Next, open the following
- series of folders, then delete the listed keys:
-
- 1. SOFTWARE\Microsoft\Windows\CurrentVersion\Run
-
- Delete these keys:
-
- Vshwin32.EXE
- VsSCHED.EXE
- VSCOMR.EXE
-
- 2. SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
-
- Delete this key:
-
- Vshwin32EXE
-
- 3. SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
-
- Delete this key:
-
- McAfee VirusScan
-
- 4. SOFTWARE\McAfee
-
- Delete these keys:
-
- Scan95
- ScreenScan
-
- 5. SOFTWARE\Network Associates
-
- Delete this key:
-
- McAfee VirusScan
-
- D. Choose Exit from the Registry menu to close the Registry
- Editor.
-
-
- 4. Delete VirusScan files and directories. To do so, follow
- these steps:
-
- A. Press CTRL+ALT+DEL to start the Windows Task Manager,
- then select the VSHWIN32.EXE task. Press End Task
- to stop the program from running.
-
- B. Quit any other open VirusScan components.
-
- C. Click Start, point to Programs, then choose Windows
- Explorer.
-
- D. Locate the folder that contains your copy of VirusScan.
- If you chose the default installation options, you
- should find VirusScan in this directory path:
- Program Files\Network Associates\McAfee VirusScan
-
- E. Remove the following files from the \Windows\system
- directory on your hard disk:
- MCKRNL.VXD
- MCSCAN32.VXD
- MCUTIL.VXD
- VSHIELD.VXD
-
- 5. You have now removed VirusScan from your system. Restart
- your computer to have your changes take effect.
-
- _____________
- DOCUMENTATION
-
- For more information, refer to the users guides for each
- product included on the CD-ROM or available from Network
- Associates electronic services. Each product user's guide
- is saved in Adobe Acrobat Portable Document Format (.PDF).
- You can view and print this document with Adobe's Acrobat
- Reader. PDF files can include hypertext links and other
- navigation features to assist you in finding answers to
- questions about your Network Associates product.
-
- To download Adobe Acrobat Reader from the World Wide Web,
- visit Adobe's website at:
-
- http://www.adobe.com/prodindex/acrobat/readstep.html
-
- To download Network Associates documentation, visit the
- Network Associates website at:
-
- http://www.nai.com
-
- Additional contact information appears in the following
- section.
-
- Documentation feedback is welcome. Send e-mail to
- tvd_documentation@nai.com.
-
- __________________________
- FREQUENTLY ASKED QUESTIONS
-
- Regularly updated lists of frequently asked questions
- about Network Associates products also are available on
- the Network Associates BBS and website, and on CompuServe
- and America Online.
-
-
- Q: I am installing new software on my computer, and the
- manual recommends disabling any anti-virus software.
- How do I disable VirusScan without uninstalling it?
-
- A: Right-click the VShield icon located in your system
- tray next to the system clock, then choose Disable
- from the shortcut menu that appears. After you
- install your new software, reactivate VShield by
- right-clicking the VShield icon in the system tray,
- then choosing Enable from the shortcut menu.
-
-
- Q: When VirusScan detects an infection in files compressed
- in .CAB or ZIP-SFX format, why doesn't VirusScan clean,
- delete, or move the files?
-
- A: Because files compressed in .CAB and ZIP-SFX formats can
- include a Microsoft Authenticode certificate altering them
- can render them unusable. To avoid this possibility,
- VirusScan does not clean, delete, or move infected files
- compressed in .CAB or ZIP-SFX format. Network Associates
- recommends that you decompress any infected files
- compressed in these formats, then run VirusScan again to
- clean the uncompressed files.
-
-
- Q: When my screen saver starts, I suddenly see a lot
- of activity on my hard disk. What's happening? How do
- I stop this activity?
-
- A: VirusScan includes a component called ScreenScan that
- scans for viruses on your hard disk during periods
- when your computer is idle. In order to use ScreenScan,
- you must install it separately as part of a custom
- installation. Then, during idle periods, ScreenScan
- starts the screen saver you chose in your Windows
- preferences property page and begins scanning for
- viruses.
-
- You can remove ScreenScan from your hard disk or simply
- disable its scanning function. To disable it, follow
- these steps:
-
- 1. Move your cursor to the Windows 95 desktop, then
- click your right mouse button.
-
- 2. Choose Properties from the shortcut menu that
- appears.
-
- 3. Click the ScreenScan tab in the Display Properties
- dialog box.
-
- 4. Clear the Enable Scanning While in Screen Saver Mode
- check box.
-
- 5. Click OK to close the Display Properties dialog box.
-
-
- Q: VirusScan detected a virus on my system, but it is not
- a document, spreadsheet, or executable file (.EXE, .COM,
- .DO?, .XL?). Therefore, I suspect it might be a false
- detection. What can I do to verify a detected virus?
-
- A: If you suspect a false detection on a non-executable
- file, run VirusScan's command line scanner, SCAN.EXE,
- to verify the infection. If VirusScan detects a virus
- and SCAN.EXE does not, download the latest .DAT files
- to update your virus definition files, then scan your
- system again. If VirusScan still detects a virus that
- you suspect is a false detection, please report the
- issue to Network Associates technical support.
-
-
- Q: I would like to purchase and download the latest
- version of VirusScan from one of the Network Associates
- electronic services, but I do not want to give my
- credit card information over the Internet for
- security purposes. Can I purchase VirusScan via modem
- and download the product via the Internet?
-
- A: Yes. The first time you download VirusScan, the Network
- Associates electronic Wizard will prompt you to select
- the transmission method you prefer to use to download
- your Network Associates product. It will also prompt
- you to transmit your encrypted credit card information.
-
- At the Transaction Connection Type dialog box, select
- Internet to download your order via the Internet.
- At the Security Connection Type dialog box, select
- Direct Dial Modem to transmit your credit card
- information via modem.
-
-
- Q: I have created my own Emergency diskette without using
- the Emergency Disk creation utility. How must I optimize
- my emergency disk's performance?
-
- A: To enable your own Emergency Disk, you must create a
- CONFIG.SYS file on the boot diskette, then add these
- lines:
-
- DEVICE=HIMEM.SYS
- DOS=HIGH
-
- Add the HIMEM.SYS file from the DOS directory or, if you
- are using Windows 95 system files, add HIMEM.SYS from
- the \WINDOWS\COMMAND directory to the boot diskette.
-
- Note: For detailed instructions on creating an Emergency
- diskette, refer to the instructions outlined in the
- electronic documentation (.PDF file) included in your
- VirusScan package.
-
-
- Q: I moved a .VSC file to my Startup folder. Whenever I
- turn on my computer, VirusScan starts, but does not
- begin scanning. How can I make VirusScan start scanning
- automatically?
-
- A: You need to customize your options. Follow these
- steps:
-
- 1. Location the .VSC file you saved.
-
- 2. Right-click the .VSC file, then choose Properties
- from the shortcut menu that appears.
-
- 3. Click the Detection tab.
-
- 5. Select the Start Automatically check box.
-
- 6. Click OK to close the properties dialog box.
-
-
- Q: When VirusScan starts, how does it determine its
- default settings?
-
- A: VirusScan reads its default settings from the
- DEFAULT.VSC file located in the installation directory.
-
-
- Q: What error codes can CHKVXD.EXE return?
-
- A: Possible CHKVXD.EXE error level codes, along with their
- descriptions, are:
-
- 65535(-1)= VShield not installed
-
- 0 = VShield enabled
-
- 1 = VShield disabled
-
-
- Q: How can I tell that ScreenScan is working?
-
- A: ScreenScan does not tell you when it scans your system,
- but if you enable the logging option when you configure
- it, VirusScan will record all ScreenScan activity in its
- log file.
-
-
- Q: How can I use VirusScan to scan more than one drive at a
- time or to scan network drives?
-
- A: You can configure VirusScan to scan more than one drive
- or drives elsewhere on your network from the Detection
- dialog box. To open the dialog box, start VirusScan, then
- choose Advanced from the Tools menu. Next, follow these
- steps:
-
- 1. Click the Detection tab.
-
- 2. Click Add.
-
- 3. To add all network drives to the Detection list,
- click Select Item to Scan, then select All
- Network Drives. To add local drives to the
- Detection list, click Select Drive or Folder to Scan,
- then enter a drive letter or click Browse to locate
- the drive you want to scan.
-
- 4. Click OK.
-
- 5. Choose Save Settings from the File menu to save your
- settings.
-
-
- Q: Can I update Network Associates data files to detect new
- viruses?
-
- A: Yes. If your data files are out-of-date, VirusScan will
- periodically prompt you to update them. If you have a
- modem or Internet connection, you can use VirusScan's
- new electronic update feature for easy data file
- updates, technical support, and registration.
-
- Note: VirusScan's electronic update feature applies to
- retail copies and any copies bundled with your computer.
- If you own a corporate version of VirusScan, you can
- configure AutoUpdate and AutoUpgrade from the VirusScan
- Console so that VirusScan will update and upgrade itself
- automatically.
-
- If you need additional assistance with downloading,
- contact Network Associates Download Support. Contact
- information appears later in this file.
-
-
- Q: How do I use the new AutoUpdate and AutoUpgrade features
- in VirusScan v3.1.9?
-
- A: You can use these features to update to the latest .DAT
- files and upgrade to the latest version of VirusScan
- automatically. To do so, configure VirusScan to use
- AutoUpgrade and AutoUpdate on a scheduled basis:
-
- 1. Start the VirusScan Console.
-
- 2. Double-click the AutoUpdate task.
-
- 3. Click Configure.
-
- 4. Choose a transfer method. You can also use this
- dialog box to set up AutoUpgrade options.
-
- 5. Click Update Now to test your configuration.
-
- 6. Click OK.
-
- 7. Click the Schedule tab.
-
- 8. Click Enable, then choose a schedule (.DAT files are
- updated monthly).
-
- 9. Your task is now configured and will be run on the
- schedule you chose.
-
- You may also launch the AutoUpdate and AutoUpgrade tasks
- using the on-demand method by clicking either Update Now
- in the task configuration or by clicking the Green Play
- arrow in the console toolbar.
-
-
- Q: An error occurs when VirusScan has completed 95 percent
- of its installation. Why does this occur on my system, but
- not on others?
-
- A: Using a non-standard Windows 95 WinSock will cause the
- Setup to fail on some systems at the 95 percent completed
- point. To prevent this, use the default Windows 95 WinSock.
-
-
- Q: I removed the Recycle Bin from the VirusScan exclusions
- list. How can I replace it?
-
- A: Because the Recycle Bin is a system folder, it cannot be
- added to the exclusions list using VirusScan's browse
- feature. To restore it to the list, enter the Recycle
- Bin's full path in the exclusions list:
-
- \Recycled\
-
-
- Q: Why are additional extensions added to the Program Files
- Only list?
-
- A: As the Network Associates Anti-Virus Emergency Response
- Team finds viruses that can infect new file types, it
- adds new extensions to the default extensions list to
- enhance security. For instance, new viruses can infect
- Microsoft Office binder files, so the default extensions
- list now includes the file extension for these binder
- files so that VirusScan will examine them for viruses.
-
-
- Q: I have Microsoft Office installed, but cannot use the
- right-click context menu to start a scan operation. Why?
-
- A: If you installed Microsoft Office after you installed
- VirusScan, you might need to reinstall VirusScan in order
- to be able to right-click DO?, XL, and OBD files and have
- VirusScan examine them for viruses.
-
- _____________________________
- CONTACTING NETWORK ASSOCIATES
-
- On December 1, 1997, McAfee Associates merged with
- Network General Corporation, Pretty Good Privacy, Inc.,
- and Helix Software, Inc. to form Network Associates, Inc.
- You may direct all questions, comments and technical
- support requests to the Network Associates Customer Care
- department at any of the addresses or phone numbers
- listed below.
-
- Contact the Network Associates Customer Care
- department at:
-
- 1. Phone (408) 988-3832
- Monday-Friday, 6:00 A.M. - 6:00 P.M. Pacific time
-
- 2. Fax (408) 970-9727
- 24-hour, Group III Fax
-
- 3. Fax-back automated response system (408) 988-3034
-
-
- Send correspondence to any of the following Network
- Associates locations:
-
- Network Associates Corporate Headquarters
- 3965 Freedom Circle
- McCandless Towers
- Santa Clara, CA 95054
-
- Phone numbers for corporate-licensed customers:
- Phone: (408) 988-3832
- Fax: (408) 970-9727
-
- Phone numbers for retail-licensed customers:
- Phone: (972) 278-6100
- Fax: (408) 970-9727
-
- Network Associates offices outside the United States:
-
- NA Network Associates Oy
- Kielotie 14 B
- 01300 Vantaa
- FINLAND
- Phone: 358 9 836 2620
- Fax: 358 9 836 26222
-
- Network Associates AG
- Baeulerwisenstrasse 3
- 8152 Glattbrugg
- Switzerland
- Phone: 0041 1 808 99 66
- Fax: 0041 1 808 99 77
-
- Network Associates Australia
- Level 1, 500 Pacific Highway
- St. Leonards, NSW 2065
- Phone: 61-2-9437-5866
- Fax: 61-2-9439-5166
-
- Network Associates Canada
- 139 Main Street, Suite 201
- Unionville, Ontario
- Canada L3R 2G6
- Phone: (905) 479-4189
- Fax: (905) 479-4540
-
- Network Associates Deutschland GmbH
- Industriestrasse 1
- D-82110 Germering
- Germany
- Phone: 49 8989 43 5600
- Fax: 49 8989 43 5699
-
- Network Associates International B.V.
- Gatwickstraat 25
- 1043 GL Amsterdam
- The Netherlands
- Phone: 31 20 586 6100
- Fax: 31 20 586 6101
-
- Network Associates France S.A.
- 50 rue de Londres
- 75008 Paris
- France
- Phone: 33 1 44 908 737
- Fax: 33 1 45 227 554
-
- Network Associates International Ltd.
- Minton Place, Victoria Street
- Windsor, Berkshire
- SL4 1EG
- United Kingdom
- Phone: 44 (0)1753 827500
- Fax: 44 (0)1753 827520
-
- Network Associates Japan, Inc.
- Toranomon 33 Mori Bldg.
- 3-8-21 Toranomon
- Minato-ku, Tokyo 105-0001
- Japan
- Phone: 81 3 5408 0700
- Fax: 81 3 5408 0780
-
- Network Associates Korea
- 135-090, 18th Floor, Kyoung-Am Bldg.
- 157-27 Samsung-Dong, Kangnam-Ku
- Seoul, Korea
- Phone: 82 2 555-6818
- Fax: 82 2 555-5779
-
- Network Associates Latin America
- 150 South Pine Island Road, Suite 205
- Plantation, Florida 33324
- Phone: (954) 452-1731
- Fax: (954) 236-8031
-
- Network Associates Portugal
- Rua Gen. Ferreira Marines, 10-6 C
- 1495 ALGES PORTUGAL
- Phone: 351 1 412 1077
- Fax: 351 1 412 1488
-
- Network Associates South East Asia
- 7 Temasek Boulevard
- The Penthouse
- #44-01, Suntec Tower One
- Singapore 038987
- Phone: 65 430-6670
- Fax: 65 430-6671
-
- Network Associates Spain
- Serrano 240, Plta. -1
- 28016 Madrid SPAIN
- Phone: 34 91 458 52 21
- Fax: 34 91 457 45 17
-
- Network Associates Srl
- Centro Direzionale Summit
- Palazzo D/1
- Via Brescia, 28
- 20063 - Cernusco sul Naviglio (MI)
- ITALY
- Phone: 39 (0)2 9214 1555
- Fax: 39 (0)2 9214 1644
-
- Net Tools Network Associates South Africa
- St. Andrews
- Meadowbrook Lane
- P.O. Box 7062
- Bryanston 2021
- South Africa
- Phone: 27 11 706-1629
- Fax: 27 11 706-1569
-
- Or, you can receive online assistance through any
- of the following resources:
-
- 1. Internet E-mail: support@nai.com
-
- 2. Internet FTP: ftp.nai.com
-
- 3. World Wide Web: http://support.nai.com
-
- 4. America Online: keyword MCAFEE
-
- 5. CompuServe: GO NAI
-
- To provide the answers you need quickly and efficiently,
- the Network Associates technical support staff needs
- some information about your computer and your software.
- Please have this information ready when you call:
-
- - Program name and version number
- - Computer brand and model
- - Any additional hardware or peripherals connected to
- your computer
- - Operating system type and version numbers
- - Network name, operating system, and version
- - Network card installed, where applicable
- - Modem manufacturer, model, and baud, where applicable
- - Relevant browsers or applications and their version
- numbers, where applicable
- - How to reproduce your problem: when it occurs, whether
- you can reproduce it regularly, and under what
- conditions
- - Information needed to contact you by voice, fax, or
- e-mail
-
- We also seek and appreciate general feedback.
-
-
- * FOR PRODUCT UPGRADES *
-
- To make it easier for you to receive and use Network
- Associates products, we have established a reseller's
- program to provide service, sales, and support for our
- products worldwide. For a listing of resellers, see the
- resellers.txt file or contact Network Associates
- Customer Care for resellers near you.
-
-
- * FOR REPORTING PROBLEMS *
-
- Network Associates prides itself on delivering a
- high-quality product. If you find any problems, please
- take a moment to review the contents of this file. If
- the problem you've encountered is documented, there is
- no need to report the problem to Network Associates.
-
- If you find any feature that does not appear to
- function properly on your system, or if you believe
- an application would benefit greatly from enhancement,
- please contact Network Associates with your suggestions
- or concerns.
-
-
- * FOR ON-SITE TRAINING INFORMATION *
-
- Contact Network Associates Customer Service at
- (800) 338-8754.
-
-
- * NETWORK ASSOCIATES BETA SITE *
-
- Get pre-release software, including DAT files, through
- http://beta.nai.com. You will have access to Public
- Beta and External Test Areas. Your feedback will make
- a difference.