
                   Doctor Web for Novell NetWare

                         Version 4.12
              Copyright (c) 1992-1999, Igor Daniloff

     Antiviruses laboratory of I.Daniloff, DialogueScience, Inc.


This program is a representative of the new 32-bit generation of antivirus
scanner Doctor Web (or DrWeb). This new generation (DrWeb32) includes
programs for Windows 95/98/NT, DOS/386, OS/2, and Novell NetWare.


DR.WEB FOR NOVELL NETWARE

Dr.Web for NetWare is a network loadable module (NLM) that runs on a server
under Novell NetWare 3.11, 3.12, 4.00, 4.01, 4.02, 4.10 and 4.11. The
program can be administered both from the server console and remote
workstation.


This distribution includes the following files:

drwebnw.nlm  - main module
drwebnw.imp  - module for Novell NetWare 4.xx
drweb32.dll  - main module library (engine)
drwebase.vdb - main virus database (the distribution may also include several
               "adds-on", i.e. additional virus databases)
drwebnw.rus  - Russian manual
drwebnw.txt  - English manual

To install DrWebNW, create on your server a directory, say, DRWEB32, and
unzip DRWEBNW.ZIP into it.

Note that all DrWeb32 family products can be installed in the same
directory (in our case, DRWEB32). The distribution packages of all family
products include two common files, DRWEB32.DLL (DrWeb32's engine) and
DRWEBASE.VDB (main virus database). These two files, as well as adds-on,
can be interchanged between any DrWeb32 family products with the same
version number.

The configuration file DRWEB32.INI is also common to all family members
and can be placed in the same directory (in our case, DRWEB32). However,
each product uses its own section in the INI file, excepting for DrWeb32W
and DrWebWCL that share the same section.

Log files are created in the same directory, separately for each product,
and are given the filename <program>.LOG.

Additionally, DrWeb32 distribution kit may include language resource files
named <language>.DWL (for instance, RUSSIAN.DWL, GERMAN.DWL, etc.) that
contain program messages written in the respective language. The language
resource files are common for all programs of the DrWeb32 family.

In this version of the program, language can be changed only by modifying
the language setting in the configuration file. To do this, find the
corresponding section in the configuration file DRWEB32.INI and specify
the language resource file in the LngFileName line.


To start the program, enter this command from the server or remote console:

load [full_path_on_server]drwebnw

If DrWeb directory (in our case, DRWEB32) is on the search path, you can
omit the [full_path_on_server].


SETUP AND ADMINISTRATION

To setup and administer the program, use its Main Control Panel:

 ͻ
    Dr. Web     
 ͹
  1. Setup       -> sets main options
  2. Monitor     -> controls and monitors active scans
  3. Scheduler   -> schedules scans
  4. On access   -> configures scan process "on access"
  5. Log         -> displays the event log
  6. Exit        -> terminates the program
 ͼ

Your system is protected against virus activity by the so called "scan
processes" (scans) of three types:

1) Manually run scans
2) Scheduled scans
3) "On access" scans

Normally, a scan starts with default options that depend on the scan type.
However, the options can be set individually for each scan:

 ͻ
    Scan settings     
 ͹
  1. Options           -> General options
  2. Infected files    -> Handling of infected files
  3. Suspected files   -> Handling of suspected files
  4. Incurable files   -> Handling infected files that cannot be cured
  5. File types        -> Files to scan
  6. CPU usage factor  -> Process priory in the system
 ͼ


Options

- Heuristic analysis - enables/disables the heuristic analyzer that can
  effectively detect unknown viruses;
- Check packed files - enables/disables checking of packed files;
- Unpack archives - enables/disables unpacking of archives;
- Check E-mail files - enables/disables checking of UUENCODE and/or MIME
  BASE64 encoded files (not supported in this version).


Infected files

This option tells the scan process how to handle an infected file:

- Report - reports the filename and infecting virus of an infected file.
- Move - moves an infected file to a special directory. To specify the
  directory, select the [Setup | Move Files, where] item. The directory is
  shared by all scan processes.
- Delete - deletes an infected file.
- Rename - renames an infected file. The renamed file is given the same name
  but a different extension. To specify the mask for generating the
  extensions, select the [Setup | Rename files, to] item. The mask is common
  for all scan processes.
- Cure - removes the virus code from an infected file.


Suspected and Incurable files

Suspected files are the files reported by the heuristic analyzer as possibly
infected by an unknown virus. Incurable files are the files that were
infected by a familiar virus, however, they cannot be cured.

The options for "Suspected" and "Incurable" files are similar to those for
"Infected" files, but the "Cure" option is disabled.


File types

This option specifies file types to be scanned by the process. Choose one of
the following:

- All - scans all files;
- By format -
  1) always checks a file with an executable file extension (.COM, .EXE,
     .SYS) or MS Office document extension (.DOC, .DOT, .XLS, etc.);
  2) checks a file regardless its extension if its internal structure
     (format) is that of an executable file or MS Office document;
- By type - scans files by a list of extensions. The list can be viewed and
  edited. To add a new extension to the list, press Ins. To delete an
  extension, press Del. You can use masks when specifying an extension.

The Options menu can be separately invoked for each scan process that is
included in the schedule, or invoked "on access" ([On access | Scan
settings]).

If you invoke this menu from the Main Control Panel ([Setup | Scan
settings]), you can set options for manually run scans. Naturally, you can
change the options before you start the process. Moreover, the options you
set in this menu are used as default for the processes included in the
schedule later.


"On access" scan process

This scan process controls files that a workstation writes to or opens on
the server. The process initiates the antivirus check when the server
executes a workstation's request for a file transaction.

When a workstation writes a new file to the server, or modifies an existing
file, this file is locked and cannot be accessed from other workstations
until it is checked.

Additionally, you can specify file transactions to be intercepted for virus
check ([On Access | Modes]):

- Open files - workstation opens a file on the servers;
- Write files - workstation modifies an existing file on the server;
- Create files - workstation creates a new file on the server.

Each of these options can be enables or disabled. Disabling all three
options disables the "On access" scan.


Schedule

Use this menu item to display a list of scheduled processes. To add a
process to the list, press Ins. To delete a process, press Del.

In addition to the general options mentioned above, for each scheduled scan
you must specify the following attributes:

- Time or Interval - is the launch time or interval specified as HH:MM; this
  attribute is interpreted by DrWeb depending on the "launch mode";
- Modes - is the launch mode:
  (By time) starts a process at the moment specified by the "launch time";
  (By interval) starts the process after the interval specified by the
     "launch time" expires.
- Hold - temporarily puts a scheduled process on hold. The process remains
  in the list, but does not run.
- Days of week - specifies the days of week when the process is to be
  started;
- Days of month - specifies the days of month when the process is to be
  started;
- Month - specifies the months when the process is to be started;
- Scan paths - specifies the directories that the process is to check on the
  server;

"Days of week", "Days of month" and "Months" are ignored by the processes
run "by interval".

A process run "by time" starts only if both the "Days of week" and "Days of
month" conditions are satisfied.

Scan options are displayed in the list of processes. At the end of each line
you can see the activity indicator:

  "-" - the process is included in the schedule but is inactive now;
  "!" - the process is active, i.e. is now running;
  "H" - the process is put on hold;
  "i" - the process runs "by intervals";
  "t" - the process runs "by time";


Monitor of scan processes

In the Main Control Panel, use the "Monitor" item to display a list of
active scans. In this list, press Ins to start an immediate scan of any
server volume or directory. Such scan runs with the default options as
specified in the [Setup | Scan settings] item. Before starting the process,
DrWeb will prompt you to enter the name of the directory/volume to be
scanned. Any active process in the list can be terminated by pressing Del.

The "Enter" key displays statistics for the selected process, including the
time, files checked, viruses detected, etc.

In the Main Control Panel you can set the following options:

[Setup | If virus found] - specifies DrWeb's reaction if a virus is found:

- (Send message) - sends a message to the workstation attacked by the virus.
  This version supports this option under NetWare 4.x only if Bindary
  Services are enabled for the given connection;
- (Disconnect station) - disconnects the workstation attacked by the virus;
- (Ring the bell) - plays sound on the server console;
- (Create flag file) - creates a zero-length file that flags a certain event
  (in this case, a virus attack). It makes sense if your system is running
  some application that can monitor and respond to this flag. The filename
  of a flag file is specified in the [Setup | Miscellaneous | Flag file
  name] item.

In the [Setup | Miscellaneous] item you can set the following options:

- (Send messages, whom) - lists the users that are always notified of virus
  detection on the server;
- (Flag file name) - specifies the filename of a flag file;
- (Disconnected users) - displays a list of Disconnected users. Press Del to
  delete a disconnected user from the list. This will enable the user to
  reconnect to the server;
- you can specify the text for the "Virus found" message, "Suspected file"
  message, "Disconnect Workstation" message.


Log

In the Main Control Panel, use this item to setup and view the event log
that contains scan report data. You can set the following log options:

- (Log to file) - enables/disables logging;
- (Overwrite log) - overwrites/appends new data to the log;
- (Log scanned files) - enables/disables logging for files that are not
  infected or suspected;
- (Log packed files) - write/omits the name of packers of executable files.


LIMITATIONS IN THIS VERSION OF PROGRAM

- Virus check in archives supported only for ZIP, ARJ and RAR.
- Virus check of UUENCODE and MIME encoded files not supported.


======================
Below is a PGP public key of Igor Daniloff. This key should be used to
encode the virus specimens when a user wishes to e-mail them to us.

Type Bits/KeyID    Date       User ID
pub  1024/1B87196D 1994/05/12 Igor A. Daniloff <ID@DrWeb.Ru>
                              Igor A. Daniloff <id@sald.spb.su>

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.3i

mQCNAi3R1+AAAAEEAMeH97dViOlTOwWjd6iLsRnEvDuNMnfQor+7NtuxV0v7Dgig
Kd4cE8dcSdfINr89mmIcPVCgI+uSDoDdgGK0WAl2pkJUigmJtidMpjFgyPoUTU6T
cqmss4CyDFH9UoM74RUEqSG0cwsnt+rz46yELf+v6kS9QZC3r53C6gEbhxltAAUR
tB5JZ29yIEEuIERhbmlsb2ZmIDxJREBEcldlYi5SdT6JAJUDBRA3P7dHncLqARuH
GW0BAQDTBACeJaSAdFMINa6G4xChVPHKUWy/jqdze94UtBRymBZFdmrtup+3bL6D
IB148AkFjH6zZyQLPCgXr4RqxURtA5H1SsFJR1Iqj2eTjQZOqfgL2IAR3M79qBqD
nhGzeQMOr7gP3hXnb2hQZtZJFgw6IneSHM5gXRVGm7y29yR0y6+RT7QhSWdvciBB
LiBEYW5pbG9mZiA8aWRAc2FsZC5zcGIuc3U+iQCVAwUQL7d6qTCAIMQGDNzxAQFN
jQP7BS+D1P68oNZjqHSGbxqqzrvasK5WjFJBefJ14ALeJbn4X3BcTFqfckYNYG6w
ZqTMWt9aZZKAWOA5rKfPp9LflJzJvZSSwYZz1Su5hJ3G0RM6z7JDVCQyV90yelDq
X1ehBEHAqMV2gvkhE5YKxvoH+uOG+TPq1FzUz4hQB/W4srCJAJUDBRAugG2cOpoV
rn3diFEBAeD3A/9jGJRp5TqD2FBrwkIaJd6SqJVvSbYQnE39th/u4csghFYEYcdS
GqPnVjxl0Sri1N5OqYB2uTRn0d0kqsrD24fuWFbZwvKlcZQO2C6W1zZSmwqAfw2p
jAD+tTvRZDSx2z0+zgRZ/EhDIaH/louf8zcL3UlrW2YPNRODzJW6VUiouIkAlQMF
EC8n2IANOmycNvS2swEBvqYEAJgRxQjfQhJI+iTMMUhWS8whvgitjzDeD+5u2tKz
KwqSa4TaOfgf2000rN2SbqyTg5gDirLsVF8x80PusKFRxedwBzBNLl9ar78HB/x4
lOEO+/obRUH4wT+bH6KfUkDuqVvYsTRZ3mDoLfyJw9pCtkDiFQdCrWcGh+UNr8nJ
oNBx
=VFhp
-----END PGP PUBLIC KEY BLOCK-----


======================
Please send your comments to:

DialogueScience, Inc.
40 Vavilova St., office 102
Moscow, 117786, RUSSIA

Tel.:     +7 (095) 135-6253, 137-0150
Tel./fax: +7 (095) 938-2970, 938-2855

FidoNet: 2:5020/69

E-mail:   Antivir@Dials.ru
WWW:      http://www.Dials.ru
FTP:      ftp.Dials.ru, ftp2.Dials.ru, ftp3.Dials.ru


The author of Dr. Web is available by

E-mail: Igor.Daniloff@Dials.ru , id@drweb.ru
FidoNet: 2:5020/69.14 , 2:5030/87.57
