home *** CD-ROM | disk | FTP | other *** search
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- NETSCAN Version 91B
- Copyright (C) 1989-1992 by McAfee Associates.
- All Rights Reserved.
-
- Documentation by Aryeh Goretsky.
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- McAfee Associates (408) 988-3832 office
- 3350 Scott Blvd. Bldg 14 (408) 970-9727 fax
- Santa Clara, CA 95054-3107 (408) 988-4004 BBS (32 lines)
- U.S.A. USR HST v.32/v.42bis/MNP 1-5
- CompuServe GO VIRUSFORUM
- InterNet mcafee@netcom.com
-
-
- SYNOPSIS
-
- NETSCAN is a virus detection and identification program for
- local and wide area networks. NETSCAN will search any networked
- drive accessible as a DOS device, searching the networked drives
- for known viruses.
- NETSCAN works by searching the system for instruction sequences
- or patterns that are unique to each computer virus, and then reporting
- their presence if found.
- NETSCAN Version 91B, when used in conjunction with the VIRUSCAN
- program on workstations, can identify all known computer virus strains
- and their varieties.
- For a complete listing of viruses detected, please read the
- accompanying VIRLIST.TXT file.
- NETSCAN can be run off of any workstation with 360Kb and DOS 2.0
- or above (Some options may require DOS 3.1 or above). In order for
- NETSCAN to check all areas of the server for computer viruses,
- NETSCAN should be run under an account with global read, write, and
- create privileges. NETSCAN works with 3Com 3/Share and 3/Open, Artisoft
- Lantastic, Novell NetWare, Banyan VINES, DEC DECNet, Microsoft LAN
- Manager, PC/SA, and NFSNet as well as IBMNET and NETBIOS compatible
- networks. If you do not see your network listed, contact McAfee
- Associates.
-
-
- AUTHENTICITY
-
- NETSCAN runs a self-test when executed. If NETSCAN has been
- modified in any way, a warning will be displayed. The program will
- still continue to check for viruses, though. If NETSCAN reports that
- it has been damaged, it is recommended that a clean copy be
- obtained.
- NETSCAN versions 51 and above are packaged with the VALIDATE
- program to ensure the integrity of the NETSCAN.EXE file. The
- VALIDATE.DOC instructions tell how to use the VALIDATE program.
- The VALIDATE program distributed with NETSCAN may be used to check
- all further versions of NETSCAN.
-
- The validation results for Version 91 should be:
-
- FILE NAME: NETSCAN.EXE
- SIZE: 75,118
- DATE: 5-28-1992
- FILE AUTHENTICATION
- Check Method 1: CC02
- Check Method 2: 17FD
-
- If your copy of NETSCAN.EXE differs, it may have been modified.
- Always obtain your copy of NETSCAN from a known source. The
- latest version of NETSCAN and validation data for NETSCAN.EXE can
- be obtained off of McAfee Associates' bulletin board system at
- (408) 988-4004.
-
- Beginning with Version 72, all McAfee Associates programs for
- download are archived with PKWare's PKZIP Authentic File
- Verification. If you do not see the "-AV" message after every file
- is unzipped and receive the message "Authentic Files Verified!
- # NWN405 Zip Source: McAFEE ASSOCIATES" when you unzip the files
- then do not run them. If your version of PKUNZIP does not have
- verification ability, then this message may not be displayed.
- Please contact McAfee Associates if your .ZIP file has been
- tampered with.
-
-
-
-
- COMMANDS
-
- IMPORTANT NOTE: NETSCAN SHOULD ALWAYS BE RUN FROM A WRITE-PROTECTED FLOPPY
- DISK TO PREVENT NETSCAN FROM BECOMING INFECTED.
-
- To run NETSCAN type:
-
- NETSCAN d1: ... d26: /A /AF filename /BELL /CF filename /CHKHI
- /D /E .xxx .yyy .zzz /EXT filename /FR /H
- /HELP /HISTORY filename /M /NLZ /NOBREAK
- /NOEXPIRE /NOMEM /NOPAUSE /NPKL
- /RF filename /REPORT filename /SP /SUB /
- UNATTEND /? @filename
-
- Options are:
-
- /A - Scan all files for viruses
- /AF filename - Store recovery data/validation codes to file
- /BELL - Beep whenever a virus is found
- /CHKHI - Scan workstation memory from 0 to 1088Kb
- /D - Overwrite and delete infected files
- /E .xxx .yyy .zzz - Scan overlay extensions .xxx .yyy .zzz
- /EXT filename - Scan using external virus data file
- /FR - Display messages in French
- /H or /HELP - Display help screen
- /HISTORY filename -Create or append to existing infection report
- /M - Scan memory for all viruses
- (see below for specifics)
- /NLZ - Skip internal scan of LZEXE compressed files
- /NOBREAK - Disable Ctrl-C / Ctrl-Brk during scanning
- /NOEXPIRE - Do not display expiration notice
- /NOMEM - Skip memory checking
- /NOPAUSE - Disable screen pause when scanning
- /NPKL - Skip internal scan of PKLITE compressed files
- /REPORT filename - Create report of infected files
- /RF filename - Remove recovery data/validation codes
- stored in filename
- /SP - Display messages in Spanish
- /SUB - Scan subdirectorires
- /UNATTEND - Scan network using error handler
- /? - Display help screen
- @filename - Scan using options from configuration file
-
- (d1: ... d26: indicate network drives to be scanned)
-
- The /A option will cause NETSCAN to go through all files on the
- referenced drive. This should be used if a file-infecting virus has already
- been detected. Otherwise the /A option should only be used when checking a
- new program. The /A option will add a substantial time to scanning. This
- option takes priority over the /E option.
-
- The /AF option logs recovery data and validation codes
- for .COM and .EXE files to a user-specified file that can be
- located on any drive. The size of the file is about 20K per
- 1,000 files validated. The syntax is /AF filename, where
- "filename" is the patch and file where recovery data and
- validation codes are stored.
-
-
- The /BELL option will cause NETSCAN to beep each time a computer
- virus is found.
-
- The /CHKHI option checks memory on the workstation NETSCAN is being
- run on above 640Kb that can be used on AT (286) and 386 systems for
- computer viruses on the workstation it is being run from. This includes
- the 384Kb Upper Memory Area from 640Kb to 1024Kb, and the 64Kb High
- Memory Area from 1024Kb to 1088Kb. On XT systems with extended memory
- cards installed, this will cause the first 64K of RAM to be scanned
- again. This option can not be used with the /NOMEM option.
-
- The /D option tells NETSCAN to prompt the user to overwrite
- and delete an infected file when one is found. If the user selects
- "Y" the infected file will be overwritten with hex code C3 [the
- Return-to-DOS instruction] and then deleted. A file erased by the
- /D option can not be recovered. If the McAfee Associates' CLEAN-
- UP program is available, it is recommended that CLEAN be used to
- remove the virus instead of NETSCAN, since in most cases it will
- recover the infected file. Boot sector and partition table
- infectors can not be removed by the /D option and require the
- CLEAN-UP virus disinfection program.
-
- The /E option allows the user to specify an extension or set
- of extensions to scan. Extensions should include the period
- character "." and be separated by a space after the /E and between
- each other. Up to three extensions may be added with the /E. For
- more extensions, use the /A option.
-
- The /EXT option allows NETSCAN to serach for viruses from a
- text file conatning user-defined search strings in addition to the
- viruses that NETSCAN already checks for. For instructions on how
- to create and use an external virus data file, please refer to the
- VIRUSCAN documentation.
-
- The /FAST option will speed NETSCAN up by displaying less
- inforation on the screen during scanning, skipping scanning inside
- of LZEXE- and PKLITE-compressed files, and examining a smaller portion
- of files during scanning. This may cause some viruses to be missed.
-
- The /FR option tells NETSCAN to output all messages in French
- instead of English.
-
- The /HISTORY option save a list of infected files to
- disk. The list is saved to disk as an ASCII text file. If a
- list exists, then the results of the current scan will be added
- to its end. The syntax is /HISTORY filename, where "filename"
- is the path and name of the report file.
-
- The /M option tells NETSCAN to check system memory of the
- workstation it is running off of for all known computer viruses that
- can inhabit memory. NETSCAN by default only checks memory for
- critical and "stealth" viruses, which are viruses which can cause
- catastrophic damage or spread the infection during the scanning
- process. For a list of viruses, please refer to the VIRUSCAN
- documentation. If a critcial virus is found in memory, NETSCAN
- will stop and warn the user to power down, and reboot the system from a
- virus-free system disk. Using the /M option with another
- anti-viral software package may result in false alarms if the other
- package does not remove its virus search strings from memory. The
- /M option will add 3 to 15 seconds to the scanning time.
-
- The /NLZ option tells NETSCAN not to look inside files
- compressed with the LZEXE file compression program. NETSCAN will
- still check the programs for external infections.
-
- The /NOBREAK option disables Control-C or Control-Break from
- stopping NETSCAN while running. The /NOBREAK option only works if
- BREAK=OFF has been added to the CONFIG.SYS file.
-
- The /NOMEM option is used to turn off all memory checking for
- viruses. It should only be used when a system is known to be free
- of viruses.
-
- The /NOPAUSE option disables the "More..." prompt that appears
- when NETSCAN fills up a screen with data. This allows NETSCAN to run
- on a machine with multiple infections without requiring operator
- intervention when the screen fills up with messages from the NETSCAN
- program.
-
- The /NPKL option tells NETSCAN not to look inside files
- compressed with the PKLITE file compression program. NETSCAN will
- still check the programs for external infections.
-
- The /REPORT option is used to generate a listing of infected
- files. The resulting list is saved to disk as an ASCII text file.
- To use the report option, specify /REPORT on the command line,
- followed by the device and filename.
-
- The /RF option removes recovery data and validation codes for
- for files from the recovery data and validation code file. The
- syntax is /RF filename, where "filename" is the path and file
- where the recovery data and validation codes are stored.
-
- The /SP option tells NETSCAN to output all messages in Spanish
- instead of English.
-
- The /SUB option allows NETSCAN to scan all subdirectories under
- a subdirectory (a subdirectory tree). Previously, NETSCAN would only
- recyursively check subdirectories if a logical device (e.g., F:)
- was scanned.
-
- The /UNATTEND option allows NETSCAN to continue scanning when a
- non-shareable open file is scanned.
-
- NOTE: The /UNATTEND options requires DOS 3.1 and above. If your PC
- is running an older version, then the /UNATTEND option will not
- work.
-
- The @filename option allows the system administrator to store a
- list of preferred options and/or areas of the system to be scanned in a
- configuration file and then have NETSCAN read the options in and execute
- them. Options need to be separated by spaces on the first line of the
- file, while systems areas (a disk, subdirectory, or files) need to be
- listed on a separate line for each entry. A sample file might look
- like this:
-
- /A /BELL /CERTIFY /REPORT C:\NETSCAN\SCAN.LOG
- F:
- G:\PUBLIC
-
- The configuration file should be an ASCII text file. If a word
- processor is used to create the file, be sure to save the file as
- ASCII.
-
- OPERATION
-
- NETSCAN should be run while only the supervisor account is active
- on the network.
- NETSCAN will require approximately 3 minutes of run time for each
- 1,000 files on the designated drive.
-
-
- EXIT CODES
-
- NETSCAN will set the DOS ERRORLEVEL upon program termination
- to:
-
- ERRORLEVEL │ DESCRIPTION
- ───────────┼────────────────────────────────────────
- 0 │ No viruses found
- 1 │ One or more viruses found
- 2 │ Abnormal termination (program error)
-
- If a user stops the scanning process, NETSCAN will set the ERRORLEVEL
- to 0 or 1 depending on whether or not a virus was discovered prior
- to termination of the scan.
-
-
- LICENSE
-
- NETSCAN may be copied and distributed for testing on a trial basis.
- If you choose to use NETSCAN, a license is required. Licenses are available
- for internal use within a business, organization, government agency, or
- for external use by repair centers or other service organizations. License
- fees will vary depending on the size of the network or number of copies of
- NETSCAN required. Information on licensing can be obtained from McAfee
- Associates or any of the Authorized Agents listed in the accompanying
- AGENTS.TXT.
-
- McAfee Associates (408) 988-3832 office
- 3350 Scott Blvd. Bldg. 14 (408) 970-9727 fax
- Santa Clara, CA 95054-3107 (408) 988-4004 BBS (32 lines)
- U.S.A. USR HST v.32/v.42 bis/MNP 1-5
- CompuServe GO VIRUSFORUM
- Internet mcafee@netcom.com