Addendum.Doc ============ You will find the following information in this file: 1) Documentation of TbLanMsg 2) Documentation of TbLog 3) Renaming Anti-Vir.Dat 4) New command line options 1) Documentation of TbLanMsg ============================ TbLanMsg is a program that forwards TBAV messages to other machines. Its purpose is to notify helpdesks or supervisors automatically of a possible virus. If one of the resident TBAV utilities detects a virus, an on-line message will be send to the specified machine. Also TbScan sends a message to the specified machine or user if it detects a virus. TbLanMsg currently only works on Lantastic networks. Versions for other networks will be available soon! Usage: TbLanMsg should be installed on any workstation from where TBAV messages should be broadcasted in case of a virus alert. There is no limit on the number of workstations connected. The receiving machine (i.e. the supervisor or helpdesk) does not has to load any TBAV software, the LANtastic (R) redirector is sufficient. Just like the other TBAV utilities TbLanMsg can be loaded in the Config.Sys or AutoExec.Bat file, after the TbDriver invokation. TbLanMsg becomes activated once the Lantastic (R) redirector (REDIR.EXE) has been installed. It is NOT required that the workstation or supervisor have been logged on to the network. TbLanMsg is always able to send its messages, even when all servers are down! Command line options: help ? =display a helpscreen remove r =remove TbLanMsg from memory on e =enable TbLanMsg off d =disable TbLanMsg test t =send test message Options available at initial startup: user = u =user to send messages to dest = m =machine to send messages to Test (t) This option can be used to transmit a test message. If you use option 'test' at the initial invocation of TbLanMsg, it will notify the supervisor/helpdesk that TbLanMsg has been activated. User (u) If you use this option, the TBAV messages will be send to the user specified. The receiving user has to be logged on somewhere on the network, otherwise the destination machine is is unknown. Option 'dest' is recommeded, as in this case the receiving user does not has to be logged on in order to receive the messages. Note: The use of one of the options 'user' or 'dest' is highly recommended, otherwise TbLanMsg will send its messages to ALL users! If you specify both options the TBAV messages will be send to the specified machine only if the specified user has been logged on. Dest (m) If you use this option, the TBAV messages will be send to the machine specified. You have to specify the name of the machine of the user who should RECEIVE the TBAV messages. (The LANtastic (R) 'NET SHOW' command will show you the name of the machine). TbLanMsg will not check whether the entered name exists because it might be possible that that machine is to be powered up later. Note: The use of one of the options 'user' or 'dest' is highly recommended, otherwise TbLanMsg will send its messages to ALL users! If you specify both options the TBAV messages will be send to the specified machine only if the specified user has been logged on. Example: Suppose you have four machines: WORK1, WORK2, HELPDESK and SERVER. If one of the TBAV utilities detects a virus, a message has to be send to machine HELPDESK. Machine WORK1: TbDriver.Exe TbScanX.Exe TbCheck.Exe TbLanMsg.Exe dest=HELPDESK AEX Ailanbio Redir.Exe WORK1 /Logins=2 Machine WORK2: TbDriver.Exe TbCheck.Exe TbMem.Exe TbLanMsg.Exe dest=HELPDESK TbFile.Exe AEX Ailanbio Redir.Exe WORK2 /Logins=2 Machine HELPDESK: AEX Ailanbio Redir.Exe HELPDESK /Logins=2 Machine SERVER: (Server is powered down) Of course all users may connect to servers and log on, but it is not required. The configuration above is sufficient to send all TBAV messages to the helpdesk. Of course the helpdesk and server may also load the TBAV utilities, but it is not required. 2 Documentation of TbLog ======================== TbLog is a TBAV log file utility. It writes a record into a log file whenever one of the resident TBAV utilities pops up with an alert message. Also when TbScan detects a virus a record will be written. This utility is primarily intended for network users. If all workstations have TbLog installed and configured to maintain the same log file, the supervisor is able to keep track of what is going on easily. When a virus enters the network he is able to determine which machine introduced the virus, and he can take action in time. A TbLog record consists of the timestamp on which the event took place, the name of the machine on which the event occured, and an informative message about what happenend and which files were involved. The information is very comprehensive and takes just one line. Usage: Just like the other TBAV utilities TbLog can be loaded in the Config.Sys or AutoExec.Bat file, after the TbDriver invokation. TbLog should be installed on every workstation. If you want to use all workstations to maintain the same log file, it is recommended to load TbLog after the network has been started. TbLog will by default maintain a log file with the name TbLog.Log in the TBAV directory. If you want to use another filename or in on another disk or directory you can specify a filename on the command line of TbLog. Command line options: help ? =display this helpscreen remove r =remove TbLog from memory on e =enable TbLog off d =disable TbLog test t =log test message Options available at initial startup: machine = m =name of your machine Test (t) This option can be used to record a test message. If you use option 'test' at the initial invocation of TbLog, it will record the time and machinename into the log file. Machine (m) With this option you can specify the name of the machine on which TbLog is loaded. This machine name will appear in the log file. On NetBios compatible machines TbLog will by default use the network machine name. On other networks - such as Novell - you have to enter the network name on the TbLog command line. 3) Renaming Anti-Vir.Dat ======================== Most of the TBAV utilities use a 'fingerprint' file named Anti-Vir.Dat. These files are generated by TbSetup. Some users are afraid that a virus might anticipate and delete the Anti-Vir.Dat files, and have requested to make the name configurable. To our opinion, renaming the Anti-Vir.Dat filename isn't the ultimate solution: since the TBAV utilities have to find out the name somehow, a virus could use the same method too and find out the Anti-Vir.Dat filename also. Secondly, it would be confusing for novice users, especially after a boot from a diskette, as the TBAV utilities will by default assume that the fingerprint files are named Anti-Vir.Dat. Third, if you use TbCheck, it will warn you automatically when the Anti-Vir.Dat file is deleted. However, if you feel you really must use a different name for security reasons, you can do so by changing the keyword "AvFile" in the [TBAV] section of the TBAV.INI file. All TBAV utilities will use the specified name automatically. The support for this keyword is limited, so the keyword can not be set from within the TBAV menu. Use an ASCII editor to enter this keyword in the [TBAV] section. Although all TBAV utilities will correctly use the specified filename, they will continue to use the name 'Anti-Vir.Dat in the error messages and on the screen, for consistency with the user manual. NOTE! If you boot from a diskette once in a while to scan your system, make sure that you have a TBAV.INI file on your diskette with the same filename specification! 4) New command line options =========================== TbUtil: - Option 'GetBoot '. You can use this option to copy the bootsector of the specified disk into a file. TbClean: - Option 'NoHeur'. This option can be used to prevent TbClean to use heuristic cleaning. TbScan: - Option 'Exec'. This option can be used to specify additional executable extensions to TbScan. TbScan considers the extensions .COM.EXE.OV?.SYS.BIN.BOO as executable, and scans files with these extensions by default. However, there are some additional files which have an internal layout that makes them suitable for infection by viruses. Although it is not likely that you will ever execute most of these files, you may want to scan them anyway. Some filename extensions (known to us) that may indicate an executable format are: .DLL.SCR.MOD.CPL.00?.APP The first four extensions indicate Windows executable files. They normally display "This program requires Microsoft Windows" when you try to execute them, so you probably won't run these files often under DOS. Even when they are infected by a DOS virus, they are not likely a threat as you don't execute them. Therefore TbScan does not scan these files by default. To make TbScan scan these files by default, specify the following command on the command-line or in the [TbScan] section of the TBAV.INI file: Exec=.DLL.SCR.MOD.CPL.00?.APP The question mark as wildcard is allowed. Warning! Be carefull about which extensions you specify: scanning a non-executable file causes unpredictable results, and may result in false alarms. To minimize the false alarms, TbScan will not apply heuristic analysis on the added executable extensions.