    What's New in VirusScan for DOS v3.0.2 (3006)
         Copyright 1994-1997 by McAfee, Inc.
                All Rights Reserved.


Thank you for using McAfee's VirusScan for DOS.
This What's New file contains important information 
regarding the current version of this product. 
It is highly recommended that you read the 
entire document.

McAfee welcomes your comments and suggestions. 
Please use the information provided in this file 
to contact us.

___________________
WHAT'S IN THIS FILE

- New Features
- Known Issues
- Installation
- Documentation
- Frequently Asked Questions
- Contact McAfee

____________
NEW FEATURES


1.  New command-line option for cleaning macros. Use the
    new /CLEANDOCALL switch to clean all macros from
    infected MSWord and MSOffice documents including the
    the LAROUX Excel macro virus from .XLS files.
    
2.  New command-line option for scanning specific file
    sizes. Use the new /MAXFILESIZE xxx.x (where xxx.x is,
    specify file size in megabytes) switch to scan only
    files with sizes under the amount specified.  
    
3.  VirusScan for DOS continues to provide the exceptional
    virus detection rates and fast scanning performance of
    the 3.0 engine series.
       
    The VirusScan 3.0 series offers users maximum defense
    against the newest threats to data. The VirusScan 3.0
    series can detect all virus types including Word and 
    Excel macros, boot-sector infections, file, multi-
    partite, stealth, polymorphic and encrypted viruses.
    
 
* ENHANCEMENTS *

1.  Enhanced command-line option for cleaning diskette boot 
    sectors. Use the /FORCE switch to clean infected boot 
    sectors of diskettes. The /FORCE switch can be used 
    even when a remover is not yet available for the boot 
    sector virus. 


* NEW VIRUSES DETECTED *
  
This DAT file, 3006, detects the following 204 new 
viruses. Locations that have experienced particular 
problems with specific viruses are also identified.

_925
1205
ALIEN.D
ALIEN.E
ANAK.A			(Australia)
ANARCHY.6093
ANDR.2374
ANEMKOE.1965
ANEMKOE.1965 DROPPER
ATTACK.A
BANDUNG.AF
BANDUNG.AG
BANDUNG.AH
BANDUNG.AI
BANDUNG.AJ
BANDUNG.AK
BANDUNG.AL
BANDUNG.AM
BANDUNG.AN
BANDUNG.AO
BEEPER.A
BEEPER.B
BERTIK.A
BISMARK.A
BISMARK.B
BISMARK.C
BISMARK.D
CAP.L
CAP.M
CASTELLO.3730
CEBU.B
CEEFOUR.B
CHAKA.A
CHANDIGARH.A
COE.A
COLORS.AU
COLORS.AV
COLORS.AW
COLORS.AX
COLORS.AY
COLORS.AZ
COLORS.BA
COLORS.BB
CONCEPT.AO
CONCEPT.AP
CONCEPT.AQ
CONCEPT.AR
CONCEPT.AS
CULT.A(INTENDED)
CVCK1.B
CVCK1.C
CVCK1.D
CVCK1.E
CZECH.A
DAKOTA.A
DAKOTA.B
DARK_APOCALYPSE.Z
DATE.B
DEDICATO.A:IT
DEFENDER.A
DOGGIE.E
DONOS.A
ENVADER.A
ERASER.E:TW
ERASER.F:TW
GAMBLER.A
GAMBLER.B
GAMBLER.C
GAMBLER.D
GIPPO_JUMPINGJ.905
GOLDFISH.B
GOODNIGH.A
HAGGIS.A
HARK.A
HELPER.C
HELPER.D
HELPER.E
HOLIDAY.2900
HYPER.A
HYPER.A1
IRISH.M
IRISH.N
IRISH.O
IRISH.P
IVP.1131
IWASHERE.710		(Philippines)
JAJA.A
JOHNNY.K1
JOHNNY.M
JOHNNY.M1
JULY13TH.1201
JUNKFACE.C
LAVOT			      (Europe)
LEMENA.3681
LEMON.A
LUCIFER.1707
LUNCH.C
MAINMAN.200
MAINMAN.213
MAINMAN.315
MAINMAN.356
MAINMAN_OVER.232
MARK.A:TW
MARK.B:TW
MDMA.P
MDMA.Q
MDMA.R
MERCY.B
MINIMAL.N
MINIMAL.O
MINIMORPH.A
MJ13.80/86
MTF.A
MUTT.1394		      (Argentina)
NICEDAY.D
NICEDAY.E
NICEDAY.F
NICEDAY.G
NICEDAY.H
NICEDAY.I
NICEDAY.J
NOP.H:FR
NOP.I
NOP.J:DE
NPAD.BC
NPAD.BD
NPAD.BE
NPAD.BF
NPAD.BG
NPAD.BH
NPAD.BI
NPAD.BJ
NPAD.BK
NPAD.BM
NPAD.BN
NPAD.BO
NPAD.BP
NUCLEAR.K
OPIM.A
ORDO.A
PAYCHECK.B
PAYCHECK.C
PESAN.A
PIG.D:TW
PIG.E:TW
RANDOMIC.A
RAPI.AI2
ROETE5.753		      (Europe)
RUSHER3
SERBU.3493
SHOWOFF.AV
SHOWOFF.AW
SHOWOFF.AX
SHOWOFF.AY
SHOWOFF.AZ
SHOWOFF.BA
SHOWOFF.BB
SHOWOFF.BC
SIMPLE.B
SLOW
SMILEY.1983
SPANSKA.1500		(Internet)
STREZZ.A
SUNBEAM.A
SWITCHER.A
SWITCHER.B
TALON.A
TALON.H
TALON.I
TEAR.A
TEMPLE.A
TENERIFE.1550
TERRON.2538
TOTEN.A:DE
TWNO.G:TW
TWOLINES.A1
TWOLINES.B
TWOLINES.C1
TWOLINES.D
TWOLINES.D1
TWOLINES.E
TWOLINES.E1
TWOLINES.F
TWOLINES.F1
TWOLINES.G
TWOLINES.G1
TWOLINES.H
TWOLINES.H1
TWOLINES.I
TWOLINES.I1
UGLYKID.A
VENENO.A:SP
VIENNA.751
WAZZU.CB
WAZZU.CC
WAZZU.CD
WEREWOLF.1361.A
WHY.A
WIPEOUT
WMVH1.A:TW
XM/EMPEROR.A
XM/LMV.D
XM/TJORO.A
ZY-X.2545


* NEW VIRUSES REMOVED *

This DAT file, 3006, removes the following 187 new 
viruses. Locations that have experienced particular 
problems with specific viruses are also identified.

_925
1205 
ALIEN.D
ALIEN.E
ANAK.A			(Australia)
ANEMKOE.1965 DROPPER
ATTACK.A
BANDUNG.AF
BANDUNG.AG
BANDUNG.AH
BANDUNG.AI
BANDUNG.AJ
BANDUNG.AK
BANDUNG.AL
BANDUNG.AM
BANDUNG.AN
BANDUNG.AO
BEEPER.A
BEEPER.B
BERTIK.A
BISMARK.A
BISMARK.B
BISMARK.C
BISMARK.D
BLACK_ADDER.1015        (Florida)
CAP.L
CAP.M
CASTELLO.3730
CEBU.B
CEEFOUR.B
CHAKA.A
CHANDIGARH.A
COE.A
COLORS.AU
COLORS.AV
COLORS.AW
COLORS.AX
COLORS.AY
COLORS.AZ
COLORS.BA
COLORS.BB
CONCEPT.AO
CONCEPT.AP
CONCEPT.AQ
CONCEPT.AR
CONCEPT.AS
CVCK1.B
CVCK1.C
CVCK1.D
CVCK1.E
CZECH.A
DAKOTA.A
DAKOTA.B
DATE.B
DEDICATO.A:IT
DEFENDER.A
DOGGIE.E
DONOS.A
ENVADER.A
ERASER.E:TW
ERASER.F:TW
GAMBLER.A
GAMBLER.B
GAMBLER.C
GAMBLER.D
GIPPO_JUMPINGJ.905
GOLDFISH.B
HAGGIS.A
HARK.A
HELPER.C
HELPER.D
HELPER.E
HOLIDAY.2900
HYPER.A
HYPER.A1
IRISH.M
IRISH.N
IRISH.O
IRISH.P
IVP.1131
IWASHERE.710		(Philippines)
JAJA.A
JOHNNY.K1
JOHNNY.M
JOHNNY.M1
JULY13TH.1201
JUNKFACE.C
LAVOT			      (Europe)
LEMON.A
LUCIFER.1707
LUNCH.C
MAINMAN.200
MAINMAN.213
MARK.A:TW
MARK.B:TW
MDMA.P
MDMA.Q
MDMA.R
MINIMAL.N
MINIMAL.O
MINIMORPH.A
MTF.A
MUTT.1394		      (Argentina)
NICEDAY.D
NICEDAY.E
NICEDAY.F
NICEDAY.G
NICEDAY.H
NICEDAY.I
NICEDAY.J
NOP.H:FR
NOP.I
NOP.J:DE  
NPAD.BC
NPAD.BD
NPAD.BE
NPAD.BF
NPAD.BG
NPAD.BH
NPAD.BI
NPAD.BJ
NPAD.BK
NPAD.BM
NPAD.BN
NPAD.BO
NPAD.BP
OPIM.A
ORDO.A
PAYCHECK.B
PAYCHECK.C
PESAN.A
PIG.D:TW
PIG.E:TW
RANDOMIC.A
RAPI.AI2
RUSHER3
SHOWOFF.AV
SHOWOFF.AW
SHOWOFF.AX
SHOWOFF.AY
SHOWOFF.AZ
SHOWOFF.BA
SHOWOFF.BB
SHOWOFF.BC
SIMPLE.B
SLOW
SMILEY.1983
SPANSKA.1500		(Internet)
STREZZ.A
SUNBEAM.A
SWITCHER.A
SWITCHER.B
TALON.A
TALON.H
TALON.I
TEAR.A
TEMPLE.A
TENERIFE.1550
TERRON.2538
TOTEN.A:DE
TWNO.G:TW
TWOLINES.A1
TWOLINES.B
TWOLINES.C1
TWOLINES.D
TWOLINES.D1
TWOLINES.E
TWOLINES.E1
TWOLINES.F
TWOLINES.F1
TWOLINES.G
TWOLINES.G1
TWOLINES.H
TWOLINES.H1
TWOLINES.I
TWOLINES.I1
UGLYKID.A
VENENO.A:SP
VIENNA.751
WAZZU.CB
WAZZU.CC
WAZZU.CD
WHY.A
WMVH1.A:TW
XM/EMPEROR.A
XM/LMV.D
ZY-X.2545

____________
KNOWN ISSUES

1. Legitimate programs which write to the Master
   Boot Record of a disk, such as some disk security
   programs, may be identified by VirusScan as a
   "probable unknown boot sector virus." If this
   problem is encountered, use the /NODDA command-line
   switch. This prevents VirusScan from scanning the
   Master Boot Record of the disk. 
 
2. This DAT file, 3006, is compatible with VirusScan's
   v3.0 engines only. This DAT file is not intended for 
   use with the VirusScan v2.5x series.    
                             
____________
INSTALLATION

* INSTALLING THE PRODUCT *

Perform one of the following installation procedures
depending on which version of VirusScan for DOS you
want to install.

1.  For the installable version of VirusScan for DOS,
    take the following steps:

    a.  Execute the INSTALL.BAT program.
    b.  Follow the on-screen instructions.

    By default, McAfee's installation program makes 
    a directory on the hard disk drive named
    C:\MCAFEE\VIRUSCAN and copies the program files
    to that directory.

    The installation script adds the directory
    to the path statement in your AUTOEXEC.BAT file
    and adds two lines that reference the VShield
    program to provide on-access virus prevention.
    For the most complete virus protection, McAfee
    recommends using the /ANYACCESS switch.

    or  

2.  For the non-installable version of VirusScan for
    DOS, take the following steps:

    a.  Make a directory on your hard disk drive.
    b.  Copy the files to that directory.
    c.  Add that directory to the path statement in
        your AUTOEXEC.BAT file.
                              

* PRIMARY PROGRAM FILES FOR VIRUSSCAN FOR DOS *

Files located in the Install directory:
=======================================

        SCAN.EXE = VirusScan for DOS program
      README.1ST = McAfee information
     PACKING.LST = Packing list
    VALIDATE.EXE = Authenticity validation program
        SCAN.DAT = Virus scan definition data
       NAMES.DAT = Virus names definition data
       CLEAN.DAT = Virus clean definition data
    WHATSNEW.TXT = What's New document
    RESELLER.TXT = McAfee authorized resellers


* TESTING YOUR INSTALLATION *

The Eicar Standard AntiVirus Test File is a combined effort 
by anti-virus vendors throughout the world to come up 
with one standard by which customers can verify their 
anti-virus installations.

To test your installation, copy the following line into its
own file and name it EICAR.COM.

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

When done, you will have a 69- or 70-byte file.

When VirusScan is applied to this file, SCAN will report 
finding the EICAR-STANDARD-AV-TEST-FILE virus.

It is important to know that THIS IS NOT A VIRUS. However,
users often have the need to test that their installations 
function correctly. The anti-virus industry, through the 
European Institute for Computer Antivirus Research, has 
adopted this standard to facilitate this need.

Please delete the file when installation testing is 
completed so unsuspecting users are not unnecessarily 
alarmed.


* UNINSTALLING THE PRODUCT * 

Follow the instructions outlined below to uninstall the
installable version of VirusScan for DOS.
                                         
1.  Execute VSHIELD/REMOVE to remove VShield from
    memory, then remove the files from your hard
    drive and remove any lines in your AUTOEXEC.BAT
    file that call VShield. If an error message is
    displayed indicating that VShield could not be
    removed from memory, take the following step. 
        
2.  Edit your AUTOEXEC.BAT file and remove all lines
    that call VShield, then reboot your system. On
    restarting your system, VShield will not be loaded
    into memory and you can remove the files from your
    hard drive.

    Note: If the files are removed from your hard drive
    prior to removing VShield from memory, an error
    message will be displayed until you remove
    VShield from memory or restart your system.

_____________
DOCUMENTATION

For more information, refer to the VirusScan User's Guide,
included on the CD-ROM versions of this program or 
available from McAfee's BBS and FTP site. McAfee Document-
ation files are in Adobe Acrobat Portable Document Format
(.PDF) and can be viewed using Adobe Acrobat Reader. This
form of electronic documentation includes hypertext links
and easy navigation to assist you in finding answers to
questions about your McAfee product.

Adobe Acrobat Reader is available on CD-ROM in the ACROREAD
subdirectory. Adobe Acrobat Reader also can be downloaded 
from the World Wide Web at:

http://www.adobe.com/Acrobat/readstep.html

VirusScan documentation can be downloaded from McAfee's BBS
or the World Wide Web at:

http://www.McAfee.com or http://205.227.129.164

For more information on viruses and virus prevention,
see the McAfee Virus Information Library, included on the
CD-ROM version of this product or available from McAfee's
BBS and FTP site. A ViaGrafix Interactive Anti-virus
Training program also is available on the CD-ROM version,
or can be purchased from the McAfee Web Site. 

__________________________
FREQUENTLY ASKED QUESTIONS 

Regularly updated lists of frequently asked questions 
about McAfee products also are available on McAfee's 
BBS, website, and CompuServe and AOL forums.
   
Q:  How do I enable McAfee's Centralized Alerting and
    Reporting option?

A:  VirusScan now supports Centralized Alerting and
    Reporting to a remote NetWare or Windows NT servers
    running NetShield for Windows NT v2.5.3 and later
    or NetShield for NetWare v2.3.3 and later. To 
    configure this option on your VirusScan client,
    use the /ALERTPATH <directory> option, where the 
    <directory> is the path to the remote NetWare 
    volume or NT directory. From this directory, 
    NetShield can broadcast or compile the alerts 
    and reports
    according to its established configuration.

    NOTE: The client must have write access to this
    <directory> location and the directory must contain
    the NetShield-supplied CENTALRT.TXT file.

    To send a complete alerting file identifying the
    system and user, establish the following environment
    variables or add them to the AUTOEXEC.BAT file.

      Set COMPUTERNAME=<name of computer>
      Set USERNAME=<user name>

    The alert file sent to the server is an .alr text
    file. Upon receipt of the alert file, NetShield NT
    or NetShield for NetWare sends an alert message to
    an administrator and/or appropriate personnel.


Q:  What can I do to scan my zip drive when VirusScan is
    unable to access it?

A:  If you are experiencing problems accessing your zip
    drive, go to the VirusScan directory, and type
    SCAN X: /NODDA (where X is the letter of your zip
    drive). Using this switch will allow you to access
    and scan your zip drive.


Q:  I have created my own Emergency diskette, how
    can I optimize it's performance?

A:  For optimal performance, create a CONFIG.SYS file on
    the boot diskette and add the following lines:

       [CONFIG.SYS]

       DEVICE=HIMEM.SYS
       DOS=HIGH
    
    Also, add the HIMEM.SYS file from the DOS directory
    to the boot diskette. 

    Note: For detailed instructions on creating an Emergency
    diskette, refer to the instructions outlined in your
    online documentation or see FaxBack Document #214.

 
Q:  What does McAfee recommend for systems that have
    low conventional memory?

A:  McAfee recommends using ScanPM for low memory environ-
    ments. ScanPM is a command-line scanner with a reduced
    conventional memory footprint, that operates in
    protected mode command-line environments.

    ScanPM is available for a free evaluation and can be
    downloaded from the online services listed below.


Q:  What is the difference between the VShield DOS TSR
    and VirusScan for DOS?

A: #1  VShield installs itself in memory and stays
       resident in memory to monitor your system for
       viral activity. If an infected program is
       executed or an infected boot sector is accessed,
       VShield will display a warning that a virus
       is present.

A: #2  VirusScan for DOS is an on-demand scanner that
       allows you to perform a complete or partial
       scan of your computer, floppies, and CD's at
       any time. VirusScan for DOS can run customized
       scans through a large set of command line 
       switches.

 
Q:  How can I run VirusScan for DOS from a Netware login
    script without running out of memory?

A:  If you are having memory problems when trying to
    run VirusScan for DOS from a NetWare login script,
    take these steps to resolve the issue:

    1.  Rename LOGIN.EXE to LOGIN1.EXE and remove
        any references to VirusScan.
    2.  Create a batch file named LOGIN.BAT.
    3.  On the first line of the batch file, run your
        scan with whatever switches you want to include.
    4.  On the second line of the batch file, run
        LOGIN1.EXE.
 
    By taking these steps, you eliminate the problem
    of having LOGIN.EXE and SCAN.EXE in memory at the
    same time. This allows VirusScan for DOS to run
    prior to accessing the network and allows your login
    script to be processed without complications.


Q:  Can I clean the Master Boot Record (MBR) of a
    Windows NT file system (NTFS) formatted hard drive?

A:  Yes. Take these steps to clean the MBR. Boot the
    Windows NT computer from a virus-free DOS bootable
    (system) diskette. Then run VirusScan for DOS;
    SCAN C: /BOOT /CLEAN from a known virus-free floppy.
    This will clean the NTFS Master Boot Sector and allow 
    Windows NT to successfully reboot from the hard disk
    drive. However, VirusScan for DOS will not be able to
    read the rest of the NTFS partition.

    After starting Windows NT, execute VirusScan for
    Windows NT to detect and clean Windows NT file
    infections.


Q:  Can I update VirusScan's data files to detect
    new viruses?

A:  Yes. If you have Internet access, you can download
    updated VirusScan data files from the McAfee Web 
    Site, BBS, or other online resources. To download 
    from the McAfee Web Site, follow these steps:
 
    1.  Go to the McAfee Web Site (http://www.mcafee.com
        or 205.227.129.164).

    2.  Select Update DAT File in the left hand column
        or frame.

    3.  Scroll down, and click Update Your DAT Files to
        update your virus definition files.

    4.  Data file updates are stored in a compressed form 
        to reduce transmission time. Unzip the files into
        a temporary directory, then copy the files to the
        appropriate directory, replacing your old files.    

    5.  Before performing any scans, shut down your
        computer, wait a few seconds, and turn it on again.

    If you need additional assistance with downloading, 
    contact McAfee Download Support at (408) 988-3832.

______________
CONTACT McAFEE

Contact McAfee's Customer Care department: 

1.  Corporate-licensed customers, call (408) 988-3832
    Monday-Friday, 6:00 A.M. - 6:00 P.M. Pacific time

    Retail-licensed customers, call (972) 278-6100
    Monday-Friday, 6:00 A.M. - 6:00 P.M. Pacific time

2.  Fax (408) 970-9727
    24-hour, Group III fax 
		
3.  Fax-back automated response system (408) 988-3034
    24-hour fax

Send correspondence to any of the following McAfee
locations.

    McAfee Corporate Headquarters
    2805 Bowers Avenue 		
    Santa Clara, CA 95051-0963		
	
    McAfee East Coast Office					
    Jerral Center West
    766 Shrewsbury Avenue
    Tinton Falls, NJ 07724-3298

    McAfee Central Office			
    4099 McEwen
    Suites 500 and 700
    Dallas, TX 75244		
						
    McAfee Canada
    139 Main Street
    Suite 201
    Unionville, Ontario
    Canada L3R2G6

    McAfee Europe B.V.			
    Gatwickstraat 25	
    1043 GL Amsterdam				
    The Netherlands	 		

    McAfee (UK) Ltd.
    Hayley House, London Road
    Bracknell, Berkshire  RG12 2TH
    United Kingdom 

    McAfee France S.A.			
    50 rue de Londres				
    75008 Paris					
    France					
				
    McAfee Deutschland GmbH
    Industriestrasse 1
    D-82110 Germering
    Germany

    McAfee Japan KK
    4F Toranomon Mori bldg. 33
    3-8-21 Toranomon
    Minato-Ku
    Tokyo, 105
    Japan
    	
Or, you can receive online assistance through any of the 
following resources:

1.  Bulletin Board System: (408) 988-4004
    24-hour US Robotics HST DS

2.  Internet e-mail: support@mcafee.com

3.  Internet FTP: ftp.mcafee.com or 205.227.129.168

4.  World Wide Web: http://www.mcafee.com
    or http://205.227.129.164

5.  America Online: keyword MCAFEE

6.  CompuServe: GO MCAFEE

7.  The Microsoft Network: GO MCAFEE

Before contacting McAfee, please make note of the
following information. When sending correspondence,
please include the same details.

- Program name and version number
- Operating system type and version
- Contents of your AUTOEXEC.BAT, CONFIG.SYS, and 
  system LOGIN script
- Network name, operating system, and version
- Type and brand of your computer, hard drive, and any 
  peripherals
- Microsoft service pack, where applicable
- Network card installed, where applicable
- Modem manufacturer, model, and baud, where 
  applicable
- Relevant browsers/applications and version number,
  where applicable

- Issue encountered
- Specific scenario where problem occurs
- Conditions required to reproduce problem
- Statement of whether problem is reproducible on demand

- Your contact information: voice, fax, and e-mail

Other general feedback is also appreciated.

Documentation feedback is welcome. Send e-mail to
documentation@cc.mcafee.com.


* FOR ON-SITE TRAINING INFORMATION *
 
Contact McAfee Customer Service at (800) 338-8754.


* FOR PRODUCT UPGRADES *

To make it easier for you to receive and use McAfee's
products, we have established a Resellers program to 
provide service, sales, and support for our products 
worldwide. For a listing of resellers, see the file 
RESELLER.TXT, where applicable, or contact McAfee
Customer Service for resellers near you.


* MCAFEE BETA SITE *

Get pre-release software, including DAT files, through
http://beta.mcafee.com/public/datafiles. You will have
access to Public Beta and External Test Areas. Your
feedback will make a difference.

 
