home *** CD-ROM | disk | FTP | other *** search
-
- Addendum.Doc
- ============
-
- You will find the following information in this file:
-
- 1) Documentation of TbLanMsg
- 2) Documentation of TbLog
- 3) Renaming Anti-Vir.Dat
- 4) New command line options
-
-
- 1) Documentation of TbLanMsg
- ============================
-
- TbLanMsg is a program that forwards TBAV messages to other machines.
- Its purpose is to notify helpdesks or supervisors automatically of a
- possible virus. If one of the resident TBAV utilities detects a virus,
- an on-line message will be send to the specified machine. Also TbScan
- sends a message to the specified machine or user if it detects a virus.
-
- TbLanMsg currently only works on Lantastic networks. Versions for other
- networks will be available soon!
-
- Usage:
-
- TbLanMsg should be installed on any workstation from where TBAV messages
- should be broadcasted in case of a virus alert. There is no limit on
- the number of workstations connected. The receiving machine (i.e. the
- supervisor or helpdesk) does not has to load any TBAV software, the
- LANtastic (R) redirector is sufficient.
-
- Just like the other TBAV utilities TbLanMsg can be loaded in the
- Config.Sys or AutoExec.Bat file, after the TbDriver invokation.
-
- TbLanMsg becomes activated once the Lantastic (R) redirector
- (REDIR.EXE) has been installed. It is NOT required that the workstation
- or supervisor have been logged on to the network. TbLanMsg is always
- able to send its messages, even when all servers are down!
-
-
- Command line options:
- help ? =display a helpscreen
- remove r =remove TbLanMsg from memory
- on e =enable TbLanMsg
- off d =disable TbLanMsg
- test t =send test message
- Options available at initial startup:
- user = <username> u =user to send messages to
- dest = <machine> m =machine to send messages to
-
-
- Test (t)
-
- This option can be used to transmit a test message. If you use option
- 'test' at the initial invocation of TbLanMsg, it will notify the
- supervisor/helpdesk that TbLanMsg has been activated.
-
-
- User (u)
-
- If you use this option, the TBAV messages will be send to the user
- specified. The receiving user has to be logged on somewhere on the
- network, otherwise the destination machine is is unknown. Option
- 'dest' is recommeded, as in this case the receiving user does not
- has to be logged on in order to receive the messages.
-
- Note: The use of one of the options 'user' or 'dest' is highly
- recommended, otherwise TbLanMsg will send its messages to ALL users!
- If you specify both options the TBAV messages will be send to the
- specified machine only if the specified user has been logged on.
-
-
- Dest (m)
-
- If you use this option, the TBAV messages will be send to the machine
- specified. You have to specify the name of the machine of the user who
- should RECEIVE the TBAV messages. (The LANtastic (R) 'NET SHOW'
- command will show you the name of the machine). TbLanMsg will not check
- whether the entered name exists because it might be possible that that
- machine is to be powered up later.
-
- Note: The use of one of the options 'user' or 'dest' is highly
- recommended, otherwise TbLanMsg will send its messages to ALL users!
- If you specify both options the TBAV messages will be send to the
- specified machine only if the specified user has been logged on.
-
-
- Example:
-
- Suppose you have four machines: WORK1, WORK2, HELPDESK and SERVER. If
- one of the TBAV utilities detects a virus, a message has to be send to
- machine HELPDESK.
-
- Machine WORK1:
- TbDriver.Exe
- TbScanX.Exe
- TbCheck.Exe
- TbLanMsg.Exe dest=HELPDESK
- AEX
- Ailanbio
- Redir.Exe WORK1 /Logins=2
-
- Machine WORK2:
- TbDriver.Exe
- TbCheck.Exe
- TbMem.Exe
- TbLanMsg.Exe dest=HELPDESK
- TbFile.Exe
- AEX
- Ailanbio
- Redir.Exe WORK2 /Logins=2
-
- Machine HELPDESK:
- AEX
- Ailanbio
- Redir.Exe HELPDESK /Logins=2
-
- Machine SERVER:
- (Server is powered down)
-
- Of course all users may connect to servers and log on, but it is not
- required. The configuration above is sufficient to send all TBAV
- messages to the helpdesk. Of course the helpdesk and server may also
- load the TBAV utilities, but it is not required.
-
-
-
- 2 Documentation of TbLog
- ========================
-
- TbLog is a TBAV log file utility. It writes a record into a log file
- whenever one of the resident TBAV utilities pops up with an alert
- message. Also when TbScan detects a virus a record will be written.
-
- This utility is primarily intended for network users. If all
- workstations have TbLog installed and configured to maintain the same
- log file, the supervisor is able to keep track of what is going on
- easily. When a virus enters the network he is able to determine which
- machine introduced the virus, and he can take action in time.
-
- A TbLog record consists of the timestamp on which the event took place,
- the name of the machine on which the event occured, and an informative
- message about what happenend and which files were involved. The
- information is very comprehensive and takes just one line.
-
- Usage:
-
- Just like the other TBAV utilities TbLog can be loaded in the
- Config.Sys or AutoExec.Bat file, after the TbDriver invokation.
-
- TbLog should be installed on every workstation. If you want to use all
- workstations to maintain the same log file, it is recommended to load
- TbLog after the network has been started.
-
- TbLog will by default maintain a log file with the name TbLog.Log in
- the TBAV directory. If you want to use another filename or in on
- another disk or directory you can specify a filename on the command
- line of TbLog.
-
-
- Command line options:
- help ? =display this helpscreen
- remove r =remove TbLog from memory
- on e =enable TbLog
- off d =disable TbLog
- test t =log test message
- Options available at initial startup:
- machine = <machine> m =name of your machine
-
-
- Test (t)
-
- This option can be used to record a test message. If you use option
- 'test' at the initial invocation of TbLog, it will record the time and
- machinename into the log file.
-
-
- Machine (m)
-
- With this option you can specify the name of the machine on which TbLog
- is loaded. This machine name will appear in the log file. On NetBios
- compatible machines TbLog will by default use the network machine name.
- On other networks - such as Novell - you have to enter the network name
- on the TbLog command line.
-
-
-
- 3) Renaming Anti-Vir.Dat
- ========================
-
- Most of the TBAV utilities use a 'fingerprint' file named Anti-Vir.Dat.
- These files are generated by TbSetup. Some users are afraid that a virus
- might anticipate and delete the Anti-Vir.Dat files, and have requested
- to make the name configurable.
-
- To our opinion, renaming the Anti-Vir.Dat filename isn't the ultimate
- solution: since the TBAV utilities have to find out the name somehow, a
- virus could use the same method too and find out the Anti-Vir.Dat
- filename also. Secondly, it would be confusing for novice users,
- especially after a boot from a diskette, as the TBAV utilities will by
- default assume that the fingerprint files are named Anti-Vir.Dat.
- Third, if you use TbCheck, it will warn you automatically when the
- Anti-Vir.Dat file is deleted.
-
- However, if you feel you really must use a different name for security
- reasons, you can do so by changing the keyword "AvFile" in the [TBAV]
- section of the TBAV.INI file. All TBAV utilities will use the specified
- name automatically. The support for this keyword is limited, so the
- keyword can not be set from within the TBAV menu. Use an ASCII editor to
- enter this keyword in the [TBAV] section.
-
- Although all TBAV utilities will correctly use the specified filename,
- they will continue to use the name 'Anti-Vir.Dat in the error messages
- and on the screen, for consistency with the user manual.
-
- NOTE! If you boot from a diskette once in a while to scan your system,
- make sure that you have a TBAV.INI file on your diskette with the same
- filename specification!
-
-
-
- 4) New command line options
- ===========================
-
-
- TbUtil:
- - Option 'GetBoot <drive>'. You can use this option to copy the
- bootsector of the specified disk into a file.
-
-
- TbClean:
- - Option 'NoHeur'. This option can be used to prevent TbClean to
- use heuristic cleaning.
-
-
- TbScan:
- - Option 'Exec'. This option can be used to specify additional
- executable extensions to TbScan.
- TbScan considers the extensions .COM.EXE.OV?.SYS.BIN.BOO as
- executable, and scans files with these extensions by default.
- However, there are some additional files which have an internal
- layout that makes them suitable for infection by viruses. Although
- it is not likely that you will ever execute most of these files,
- you may want to scan them anyway.
-
- Some filename extensions (known to us) that may indicate an
- executable format are: .DLL.SCR.MOD.CPL.00?.APP
- The first four extensions indicate Windows executable files. They
- normally display "This program requires Microsoft Windows" when
- you try to execute them, so you probably won't run these files
- often under DOS. Even when they are infected by a DOS virus, they
- are not likely a threat as you don't execute them. Therefore
- TbScan does not scan these files by default. To make TbScan scan
- these files by default, specify the following command on the
- command-line or in the [TbScan] section of the TBAV.INI file:
-
- Exec=.DLL.SCR.MOD.CPL.00?.APP
-
- The question mark as wildcard is allowed.
-
- Warning! Be carefull about which extensions you specify:
- scanning a non-executable file causes unpredictable results, and
- may result in false alarms. To minimize the false alarms, TbScan
- will not apply heuristic analysis on the added executable
- extensions.
-
-
- TbScanX:
- - Added a new undocumented option 'xmsseg=<hexnum>' (xs). You can
- use this option to specify on which address the temporary XMS
- swap buffer should be located while files are being copied. The
- default address is 6000h. If you experience troubles using the
- XMS option, try if this option can solve it. Recommended values
- are from 2000h to 8800h (default is 6000h). Let us know if this
- helps and which value you use.
-
-