home *** CD-ROM | disk | FTP | other *** search
- NETSCAN Version V84
- Copyright (C) 1989, 1990, 1991 by McAfee Associates.
- All Rights Reserved.
- Documentation by Aryeh Goretsky.
-
-
-
-
-
-
- McAfee Associates (408) 988-3832 office
- 4423 Cheeney Street (408) 970-9727 fax
- Santa Clara, CA 95054-0253 (408) 988-4004 BBS 2400 bps
- U.S.A. (408) 988-5138 BBS HST 9600
- (408) 988-5190 BBS v32 9600
- CompuServe GO VIRUSFORUM
- InterNet mcafee@netcom.com
-
- SYNOPSIS
-
- NETSCAN is a virus detection and identification program for local
- and wide area networks. NETSCAN will search any networked drive
- accessible as a DOS device, searching the networked drive(s) for
- known viruses.
- NETSCAN works by searching the system for instruction sequences
- or patterns that are unique to each computer virus, and then reporting
- their presence if found.
- NETSCAN version V84, when used in conjunction with the VIRUSCAN
- program on workstations, can identify all 301 computer virus strains
- and the 897 varieties.
- For a complete listing of viruses detected, please read the
- accompanying VIRLIST.TXT file.
- NETSCAN can be run off of any workstation with 256Kb and DOS 2.0
- or above (Some options may require DOS 3.1 or above). In order for
- NETSCAN to check all areas of the server for computer viruses,
- NETSCAN should be run under an account with global read, write, and
- create privileges. NETSCAN works with 3Com 3/Share and 3/Open, Novell
- NetWare, Banyan VINES, DEC DECNet, Microsoft LAN Manager, PC/SA,
- and NFSNet as well as IBMNET and NETBIOS compatible networks. If you
- do not see your network listed, contact McAfee Associates.
-
-
- AUTHENTICITY
-
- NETSCAN runs a self-test when executed. If NETSCAN has been
- modified in any way, a warning will be displayed. The program will
- still continue to check for viruses, though. If NETSCAN reports that
- it has been damaged, it is recommended that a clean copy be
- obtained.
- NETSCAN versions 51 and above are packaged with the VALIDATE
- program to ensure the integrity of the NETSCAN.EXE file. The
- VALIDATE.DOC instructions tell how to use the VALIDATE program.
- The VALIDATE program distributed with NETSCAN may be used to check
- all further versions of NETSCAN.
-
- The validation results for Version 84 should be:
-
- FILE NAME: NETSCAN.EXE
- SIZE: 50,347
- DATE: 10-07-1991
- FILE AUTHENTICATION
- Check Method 1: 04F9
- Check Method 2: 1773
-
- If your copy of NETSCAN.EXE differs, it may have been modified.
- Always obtain your copy of VIRUSCAN from a known source. The
- latest version of NETSCAN and validation data for NETSCAN.EXE can
- be obtained off of McAfee Associates' bulletin board system at
- (408) 988-4004 or CompuServe Forum GO VIRUSFORUM.
-
- Beginning with Version 72, all McAfee Associates programs for
- download are archived with PKWare's PKZIP Authentic File
- Verification. If you do not see the "-AV" message after every file
- is unzipped and receive the message "Authentic Files Verified!
- # NWN405 Zip Source: McAFEE ASSOCIATES" when you unzip the files
- then do not run them. If your version of PKUNZIP does not have
- verification ability, then this message may not be displayed.
- Please contact McAfee Associates if your .ZIP file has been
- tampered with.
-
-
-
-
- COMMANDS
-
- IMPORTANT NOTE: NETSCAN SHOULD ALWAYS BE RUN FROM A WRITE-PROTECTED FLOPPY
- DISK TO PREVENT NETSCAN FROM BECOMING INFECTED.
-
- To run NETSCAN type:
-
- NETSCAN d1: ... d10: /A /CHKHI /D /E .xxx .yyy .zzz
- /FR /M /NLZ /NOBREAK /NOMEM /NOPAUSE
- /REPORT d:filename /UNATTEND
-
- Options are:
-
- /A - Scan all files for viruses
- /CHKHI - Scan memory from 0 to 1088Kb
- /D - Overwrite and delete infected files
- /E .xxx .yyy .zzz - Scan overlay extensions .xxx .yyy .zzz
- /FR - Display messages in French
- /M - Scan memory for all viruses
- (see below for specifics)
- /NLZ - Skip scanning of LZEXE compressed files
- /NOBREAK - Disable Ctrl-C / Ctrl-Brk during scanning
- /NOMEM - Skip memory checking
- /NOPAUSE - Disable screen pause when scanning
- /REPORT d:filename - Create report of infected files
- /UNATTEND - Scan network using error handler
-
- (d1: ... d10: indicate drives to be scanned)
-
- The /A option will cause NETSCAN to go through all files on the
- referenced drive. This should be used if a file-infecting virus has already
- been detected. Otherwise the /A option should only be used when checking a
- new program. The /A option will add a substantial time to scanning. This
- option takes priority over the /E option.
-
- The /CHKHI option checks memory above 640Kb that can be used on
- AT (286) and 386 systems for computer viruses on the workstation it is
- being run from. This includes the 384Kb Upper Memory Area from 640Kb
- to 1024Kb, and the 64Kb High Memory Area from 1024Kb to 1088Kb. On XT
- systems with extended memory cards installed, this will cause the first
- 64K of RAM to be scanned again. This option can not be used with the
- /NOMEM option.
-
- The /D option tells NETSCAN to prompt the user to overwrite
- and delete an infected file when one is found. If the user selects
- "Y" the infected file will be overwritten with hex code C3 [the
- Return-to-DOS instruction] and then deleted. A file erased by the
- /D option can not be recovered. If the McAfee Associates' CLEAN-
- UP program is available, it is recommended that CLEAN be used to
- remove the virus instead of NETSCAN, since in most cases it will
- recover the infected file. Boot sector and partition table
- infectors can not be removed by the /D option and require the
- CLEAN-UP virus disinfection program.
-
- The /E option allows the user to specify an extension or set
- of extensions to scan. Extensions should include the period
- character "." and be separated by a space after the /E and between
- each other. Up to three extensions may be added with the /E. For
- more extensions, use the /A option.
-
- The /FR option tells NETSCAN to output all messages in French
- instead of English.
-
- The /M option tells NETSCAN to check system memory of the
- workstation it is running off of for all known computer viruses that
- can inhabit memory. NETSCAN by default only checks memory for
- critical and "stealth" viruses, which are viruses which can cause
- catastrophic damage or spread the infection during the scanning
- process. NETSCAN will check memory for the following viruses
- in any case:
-
- 1024 1253 1554 1963
- 1971 2100 2560 337
- 3445-Stealth 4096 512 Anthrax
- Anti-Tel Brain Dark Avenger Darth Vader
- Disk Killer Doom2 EDV Empire
- Fish6 Form Greemlin Invader
- Joshi Microbes Mirror Murphy
- Nomenclature Phantom Plastique Polish-2
- P1R (Phoenix) Sentinel Stoned Tequila
- Taiwan-3 Whale Zero-Hunt
-
- If one of these viruses is found in memory, NETSCAN will stop and
- advise the user to power down, and reboot the system from a
- virus-free system disk. Using the /M option with another
- anti-viral software package may result in false alarms if the other
- package does not remove its virus search strings from memory. The
- /M option will add 3 to 15 seconds to the scanning time.
-
- The /NLZ option tells NETSCAN not to look inside files
- compressed with the LZEXE file compression program. NETSCAN will
- still check the programs for external infections.
-
- The /NOBREAK option disables Control-C or Control-Break from
- stopping VIRUSCAN while running. The /NOBREAK option only works if
- BREAK=OFF has been added to the CONFIG.SYS file.
-
- The /NOMEM option is used to turn off all memory checking for
- viruses. It should only be used when a system is known to be free
- of viruses.
-
- The /NOPAUSE option disables the "More..." prompt that appears
- when NETSCAN fills up a screen with data. This allows VIRUSCAN to run
- on a machine with multiple infections without requiring operator
- intervention when the screen fills up with messages from the NETSCAN
- program.
-
- The /REPORT option is used to generate a listing of infected
- files. The resulting list is saved to disk as an ASCII text file.
- To use the report option, specify /REPORT on the command line,
- followed by the device and filename.
-
- The /UNATTEND option allows NETSCAN to continue scanning when a
- non-shareable open file is scanned.
-
- NOTE: The /UNATTEND options requires DOS 3.1 and above. If your PC
- is running an older version, then the /UNATTEND option will not
- work.
-
-
- OPERATION
-
- NETSCAN should be run while only the supervisor account is active
- on the network.
- NETSCAN will require approximately 3 minutes of run time for each
- 1,000 files on the designated drive.
-
-
- EXIT CODES
-
- NETSCAN will set the DOS ERRORLEVEL upon program termination
- to:
-
- ERRORLEVEL | DESCRIPTION
- -----------+--------------------------
- 0 | No viruses found
- 1 | One or more viruses found
- 2 | Abnormal termination (program error)
-
- If a user stops the scanning process, NETSCAN will set the ERRORLEVEL
- to 0 or 1 depending on whether or not a virus was discovered prior
- to termination of the scan.
-
-
- LICENSE
-
- NETSCAN may be copied and distributed for testing on a trial basis.
- If you choose to use NETSCAN, a license is required. Licenses are available
- for internal use within a business, organization, government agency, or
- for external use by repair centers or other service organizations. License
- fees will vary depending on the size of the network or number of copies of
- NETSCAN required. For information contact:
-
- McAfee Associates (408) 988-3832 office
- 4423 Cheeney Street (408) 970-9727 fax
- Santa Clara, CA 95054-0253 (408) 988-4004 BBS 2400 bps
- U.S.A. (408) 988-5138 BBS HST 9600
- (408) 988-5190 BBS v32 9600
- CompuServe GO VIRUSFORUM
- Internet mcafee@netcom.com