      What's New in VirusScan for DOS v2.5.4 (9702)
         Copyright 1994-1997 by McAfee, Inc.
                All Rights Reserved.


Thank you for using McAfee's VirusScan for DOS.
This What's New file contains important information 
regarding the current version of this product. 
It is highly recommended that you read the 
entire document.

McAfee welcomes your comments and suggestions. 
Please use the information provided in this file 
to contact us.

___________________
WHAT'S IN THIS FILE

- New Features
- Installation
- Documentation
- Frequently Asked Questions
- Contact McAfee

____________
NEW FEATURES

* ENHANCEMENTS *

1.  VirusScan for DOS now detects the LAROUX Excel Macro
    virus. A remover for the LAROUX Macro virus is available
    as a separate component from McAfee via the Internet.

2.  VirusScan for DOS now supports the option of moving
    files with unknown viruses onto diskette. The virus
    sample can then be sent to McAfee Virus Research for
    review.


* ISSUES ADDRESSED IN THIS RELEASE *

1.  DAT file 9702 addresses and fixes a false ID situation
    in 9701. Anyone using DAT file 9701 should immediately
    replace it with 9702. Otherwise the two DAT sets behave
    the same.
                             
2.  While the /LOCK option was enabled, some systems
    locked after a scan when no viruses were found and
    non-critical errors were encountered. This issue has
    been resolved.


* NEW VIRUSES DETECTED *
  
This DAT file (9702) detects the following 127 new viruses.
Locations that have experienced particular problems with
specific viruses are also identified.

_723                      Italy
_1819                     Europe
ALIEN.B
ANTIMIT.770
APPARITION.5969
BADBOY
BEST_WISHES.981           Australia
CAGLI
CANNIBAL.237
CANNIBAL.238
CANNIBAL.275
CARNIVAL                  Czech Republic
CHANGE.663
CHAPA.566.A
CHAPA.566.B
CHAPA.572
CLAIRE.821                France
COMBI.1106
COMPAN.17700              Brazil
CORU$A.1489               Spain
DEIMOS.277
DIAMONDSUTRA              US
DONG.1741                 Taiwan
DREPO
EASTERN_DIGITAL.1700
EDDY.1422
EDDY.1457
EDDY.1463
EDDY.1478
EDDY.1482
EDDY.1542
EDDY.1551
EDDY.1567
ESOTERIC.421
ESOTERIC.500
FUNYOUR
GALICIA.840
GOJOHNNY                  US (NJ)
GOODBYE.860
GREMLIN.3263              Internet (Simtel)
HAJO.765                  Switzerland
HARRIER.4602
HLLP.4999
IBVV.742
IMMORTAL.377
INDONESIA.2456
INT40                     Eastern Europe
INTCE                     Canada
INTENDED STONED DROPPER   Internet
IVP.345
IVP.737
IVP.827
IVP.2358
JAREK.1062
JERUSALEM.1478
JERUSALEM.1548
JERUSALEM.SUNDAY.1636
JOUC.1608
JTTP.3423
KEEPER.LEMMING.2160
KILLPROT
KW2.1756
KW2.1768
KW2.1783
KW2.1809
KW2.1811
KW2.1844
KW2.1845
KWAN.1589
KWAN.1598
LADY_DEATH
LAROUX (*)
LEONARDO.1215
LEPROSY.SENECA.381
LEPROSY.SENECA.493
LURE
MAD.1288
MALAGA.2385               Spain
MALAGA.2610               Spain
MALAGA.2658               Spain
MALATINEC.2367            Eastern Europe
MANIAK.LBS/MBR
MDMA.D
MDMA.E                    Australia
MOLOCH (*)                Europe
MWSC                      Australia
MX/DELTA                  Indonesia
MX/SOFA
NADO.APRIL.797
NADO.LOVE.531
NOSTARDAMOS.5995
NUKER.EXCESS.3529
NUKER.EXCESS.3536
ODIOUS.569
OFFSPRING.1327            Australia
ORNATE                    Philippines
PAZ.2560
PI.2048
PS-MPC.298
PS-MPC.361
PS-MPC.401
PS-MPC.594
QUARK.2000                Philippines
SPINNER.1068 
SRP.2280
SRP.2388
TCHECHEN.3420
TCHECHEN.3560
TCHECHEN.3604
TOPPER.1024.A
TREB.1480
TRIVIA.319
TRIVIAL.22
TRIVIAL.29.E.2
TRIVIAL.30.H.2
TRIVIAL.42.C
TRIVIAL.45.J
TRIVIAL.90
TRIVIAL.91
TWOLINES.A                Philippines
UPSIDE DOWN.1051
VCL.353
VCL.583
VCL.COMP.358
VCL.O.406
VIOLA
WHITE_LION.942
WPC_ALAEH.3072            Philippines
XUXA.599

(*) Requires 2.5.4 scan engine for detection.


* NEW VIRUSES REMOVED *

This DAT file (9702) removes the following 59 new viruses.
Locations that have experienced particular problems with
specific viruses are also identified.

_723                      Italy
_1819                     Europe
4SEASONS
ALIEN.B
BADBOY
BEST_WISHES.981
CAGLI
CARNIVAL
CHAPA.450.C
CHAPA.566.A
CHAPA.566.B
CHAPA.572
CHAPA.586
COMPAN.17700              Brazil
CORU$A.1489
CROVIR.625
DIAMONDSUTRA              US
DONG.1741                 Taiwan
FUNYOUR
GOJOHNNY                  US (NJ)
GOODBYE.860
HARRIER.4602
INDONESIA.2456
INT40                     Eastern Europe
INTCE                     Canada
INTENDED STONED DROPPER   Internet
IVP.345
JERUSALEM.1478
JERUSALEM.1548
KEEPER.LEMMING.2160
KILLPROT
LEONARDO.1215
MALAGA.2385               Spain
MALAGA.2610               Spain
MALAGA.2658               Spain
MANIAK.LBS/MBR
MDMA.D
MDMA.E                    Australia
MILIKK.1020
MWSC                      Australia
NO_FRILL.843              Australia/Fiji
ORNATE                    Philippines
PAZ.2560
POJER.4028                Czech Republic
PS-MPC.298
PS-MPC.361
PS-MPC.432
QUARK.2000                Philippines
RUSSEL.1200
SENORITA.885              Spain
SKYNET.1809               Spain
SPINNER.1068
TRIVIA.319
TWOLINES.A                Philippines
UPSIDE DOWN.1051
VIOLA
WPC_ALAEH.3072            Philippines
YEKE.1204
YESSMILE.5504
ZIPPER (EXE)

____________
INSTALLATION

* INSTALLING THE PRODUCT *

Perform one of the following installation procedures
depending on which version of VirusScan for DOS you
want to install.

1.  For the installable version of VirusScan for DOS,
    take the following steps:

    a.  Execute the INSTALL.BAT program.
    b.  Follow the on-screen instructions.

    By default, McAfee's installation program makes 
    a directory on the hard disk drive named
    C:\MCAFEE\VIRUSCAN and copies the program files
    to that directory.

    The installation script adds the directory
    to the path statement in your AUTOEXEC.BAT file
    and adds two lines that reference the VShield
    program to provide on-access virus prevention.
    For the most complete virus protection, McAfee
    recommends using the /ANYACCESS switch.

    or  

2.  For the non-installable version of VirusScan for
    DOS, take the following steps:

    a.  Make a directory on your hard disk drive.
    b.  Copy the files to that directory.
    c.  Add that directory to the path statement in
        your AUTOEXEC.BAT file.
                              

* PRIMARY PROGRAM FILES FOR VIRUSSCAN FOR DOS *

Files located in the Install directory:
=======================================

        SCAN.EXE = VirusScan for DOS program
      README.1ST = McAfee information
     PACKING.LST = Packing list
    VALIDATE.EXE = Authenticity validation program
        SCAN.DAT = Virus scan definition data
       NAMES.DAT = Virus names definition data
       CLEAN.DAT = Virus clean definition data
    WHATSNEW.TXT = What's New document
      AGENTS.TXT = McAfee authorized agents


* TESTING YOUR INSTALLATION *

The Eicar Standard AntiVirus Test File is a combined effort 
by anti-virus vendors throughout the world to come up 
with one standard by which customers can verify their 
anti-virus installations.

To test your installation, copy the following line into its
own file and name it EICAR.COM.

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

When done, you will have a 69- or 70-byte file.

When VirusScan is applied to this file, SCAN will report 
finding the EICAR-STANDARD-AV-TEST-FILE virus.

It is important to know that THIS IS NOT A VIRUS. However,
users often have the need to test that their installations 
function correctly. The anti-virus industry, through the 
European Institute for Computer Antivirus Research, has 
adopted this standard to facilitate this need.

Please delete the file when installation testing is 
completed so unsuspecting users are not unnecessarily 
alarmed.


* UNINSTALLING THE PRODUCT * 

Follow the instructions outlined below to uninstall the
installable version of VirusScan for DOS.
                                         
1.  Execute VSHIELD/REMOVE to remove VShield from
    memory, then remove the files from your hard
    drive and remove any lines in your AUTOEXEC.BAT
    file that call VShield. If an error message is
    displayed indicating that VShield could not be
    removed from memory, take the following step. 
        
2.  Edit your AUTOEXEC.BAT file and remove all lines
    that call VShield, then reboot your system. On
    restarting your system, VShield will not be loaded
    into memory and you can remove the files from your
    hard drive.

    Note: If the files are removed from your hard drive
    prior to removing VShield from memory, an error
    message will be displayed until you remove
    VShield from memory or restart your system.

_____________
DOCUMENTATION

For more information, refer to the VirusScan User's Guide,
included on the CD-ROM versions of this program or
available from McAfee's BBS and FTP site. This file is
in Adobe Acrobat Portable Document Format (.PDF) and can
be viewed using Adobe Acrobat Reader. This form of
electronic documentation includes hypertext links and
easy navigation to assist you in finding answers to
questions about your McAfee product.

Adobe Acrobat Reader is available on CD-ROM in the ACROREAD
subdirectory. Adobe Acrobat Reader also can be downloaded 
from the World Wide Web at:

http://www.adobe.com/Acrobat/readstep.html

VirusScan documentation can be downloaded from McAfee's BBS
or the World Wide Web at:

http://www.McAfee.com or http://205.227.129.97

For more information on viruses and virus prevention,
see the McAfee Virus Information Library, included on the
CD-ROM version of this product or available from McAfee's
BBS and FTP site. A ViaGrafix Interactive Anti-virus
Training program also is available on the CD-ROM version,
or can be purchased from the McAfee Web Site. 

__________________________
FREQUENTLY ASKED QUESTIONS 

Regularly updated lists of frequently asked questions 
about McAfee products also are available on McAfee's 
BBS, website, and CompuServe and AOL forums.
   
Q:  How do I enable McAfee's Centralized Alerting and
    Reporting option?

A:  VirusScan now supports Centralized Alerting and
    Reporting to a remote NetWare or Windows NT server
    running NetShield for Windows NT v2.5.3 and higher
    or NetShield for NetWare v2.3.3 and higher. To set
    up this option on your VirusScan client, use the
    /ALERTPATH <directory> option, where the <directory>
    is the path to the remote NetWare volume or NT
    directory. From this directory, NetShield can
    broadcast or compile the alerts and reports
    according to its established configuration.

    NOTE: The client must have write access to this
    <directory> location and the directory must contain
    the NetShield-supplied CENTALRT.TXT file.

    To send a complete alerting file identifying the
    system and user, establish the following environment
    variables or add them to the AUTOEXEC.BAT file.

      Set COMPUTERNAME=<name of computer>
      Set USERNAME=<user name>

    The alert file sent to the server is an .alr text
    file. Upon receipt of the alert file, NetShield NT
    or NetShield for NetWare sends an alert message to
    an administrator and/or appropriate personnel.


Q:  What can I do to scan my zip drive when VirusScan is
    unable to access it?

A:  If you are experiencing problems accessing your zip
    drive, go to the VirusScan directory, and type
    SCAN X: /NODDA (where X is the letter of your zip
    drive). Enabling this switch will allow you to access
    and scan your zip drive.


Q:  I have created my own Emergency diskette, how
    can I optimize it's performance?

A:  For optimal performance, create a CONFIG.SYS file on
    the boot diskette and add the following lines:

       [CONFIG.SYS]

       DEVICE=HIMEM.SYS
       DOS=HIGH
    
    Also, add the HIMEM.SYS file from the DOS directory
    to the boot diskette. 

    Note: For detailed instructions on creating an Emergency
    diskette, refer to the instructions outlined in your
    online documentation.


Q:  How much conventional memory is required to run
    VirusScan for DOS?

A:  A minimum of 490K of free conventional memory is
    recommended to run VirusScan for DOS.

 
Q:  What does McAfee recommend for systems that do not
    have the 490K of free conventional memory to run
    VirusScan?

A:  McAfee recommends using ScanPM for low memory environ-
    ments. ScanPM is a command-line scanner with a reduced
    conventional memory footprint, that operates in
    protected mode command-line environments.

    ScanPM is available for a free evaluation and can be
    downloaded from the online services listed below.


Q:  What is the difference between the VShield DOS TSR
    and VirusScan for DOS?

A: #1  VShield installs itself in memory and stays
       resident in order to monitor your system for
       viral activity. If an infected program is
       executed or an infected boot sector is accessed,
       VShield will display a warning that a virus
       is present.

A: #2  VirusScan for DOS is an on-demand scanner that
       allows you to perform a complete or partial
       scan of your computer at any time. VirusScan
       for DOS can run customized scans through a
       large set of command line switches.

 
Q:  How can I run VirusScan for DOS from a Netware login
    script without running out of memory?

A:  If you are having memory problems when trying to
    run VirusScan for DOS from a NetWare login script,
    take these steps to resolve the issue:

    1.  Rename LOGIN.EXE to LOGIN1.EXE and remove
        any references to VirusScan.
    2.  Create a batch file named LOGIN.BAT.
    3.  On the first line of the batch file, run your
        scan with whatever switches you want to include.
    4.  On the second line of the batch file, run
        LOGIN1.EXE.
 
    By taking these steps, you eliminate the problem
    of having LOGIN.EXE and SCAN.EXE in memory at the
    same time. This allows VirusScan for DOS to run and
    your login script to be processed without problems.


Q:  Can I clean the Master Boot Record (MBR) of a
    Windows NT file system (NTFS) formatted hard drive?

A:  Yes. Take these steps to clean the MBR. Boot the
    Windows NT computer from a virus-free DOS bootable
    (system) diskette. Then run VirusScan for DOS;
    SCAN C: /BOOT /CLEAN. This will clean the NTFS
    Master Boot Sector and allow Windows NT to
    successfully reboot from the hard disk drive.
    However, VirusScan for DOS will not be able to read
    the rest of the NTFS partition.

    After starting Windows NT, execute VirusScan for
    Windows NT to detect and clean Windows NT file
    infections.



Q:  Can I update VirusScan's data files to detect
    new viruses?

A:  Yes. If your data files are dangerously out-of-date,
    VirusScan for DOS will prompt you to update them.
    If you have Internet access, you can download
    updated VirusScan data files from the McAfee Web 
    Site, BBS, or other online resources. To download 
    from the McAfee Web Site, follow these steps:

    1.  Go to the McAfee Web Site (http://www.mcafee.com
        or http://205.227.129.97).

    2.  Click on the Download McAfee button in the upper
        left hand column or frame.

    3.  Click on Update Your DAT Files to update DAT files.

    4.  View the information provided on new DAT files
        and downloading.

    5.  Click on Download this Month's DAT.
   
    6.  Data file updates are stored in a compressed form 
        to reduce transmission time. Unzip the files into
        a temporary directory, then copy the files to the
        appropriate directory, replacing your old files.    

    7.  Before performing any scans, shut down your
        computer, wait a few seconds, and turn it on again.

    If you need additional assistance with downloading, 
    contact McAfee Download Support at (408) 988-3832.

______________
CONTACT McAFEE

* FOR QUESTIONS, ORDERS, PROBLEMS, or COMMENTS *

Contact McAfee's Customer Care department: 

1.  Call (408) 988-3832
    Monday-Friday, 6:00 A.M. - 6:00 P.M. Pacific time              
						    
2.  Fax (408) 970-9727
    24-hour, Group III Fax 
		
3.  Fax-back automated response system (408) 988-3034
    24-hour fax

Send correspondence to any of the following McAfee
locations:
	
    McAfee Corporate Headquarters		
    2710 Walsh Avenue			
    Santa Clara, CA 95051-0963		
	
    McAfee East Coast Office					
    Jerral West Center
    766 Shrewsbury Avenue
    Tinton Falls, NJ 07724-3298

    McAfee Central Office			
    5944 Luther Lane, Suite 117		
    Dallas, TX 75225				
						
    McAfee Canada
    178 Main Street
    Unionville, Ontario
    Canada L2R 2G9

    McAfee Europe B.V.			
    Orlyplein 81 - Busitel 1		
    1043 DS Amsterdam				
    The Netherlands

    McAfee (UK) Ltd.
    Hayley House, London Road
    Bracknell, Berkshire  RG12 2th       
    United Kingdom

    McAfee France S.A.			
    50 rue de Londres				
    75008 Paris					
    France					
				
    McAfee Deutschland GmbH
    Industriestrasse 1
    D-82110 Germering
    Germany

Or, you can receive online assistance through any 
of the following resources:

1.  Bulletin Board System: (408) 988-4004  
    24-hour US Robotics HST DS

2.  Internet e-mail: support@mcafee.com

3.  Internet FTP: ftp.mcafee.com or 205.227.129.134

4.  World Wide Web: http://www.mcafee.com
    or http://205.227.129.97

5.  America Online: keyword MCAFEE

6.  CompuServe: GO MCAFEE

7.  The Microsoft Network: GO MCAFEE

Before contacting McAfee, please make note of the following 
information. When sending correspondence, please include 
the same details.

- Program name and version number
- Type and brand of your computer, hard drive, and any 
  peripherals
- Operating system type and version
- Network name, operating system, and version
- Contents of your AUTOEXEC.BAT, CONFIG.SYS, and 
  system LOGIN script
- Microsoft service pack, where applicable
- Network card installed, where applicable
- Modem manufacturer, model, and baud, where 
  applicable
- Relevant browsers/applications and version number,
  where applicable

- Problem
- Specific scenario where problem occurs
- Conditions required to reproduce problem
- Statement of whether problem is reproducible on demand

- Your contact information: voice, fax, and e-mail

Other general feedback is also appreciated.


* FOR ON-SITE TRAINING INFORMATION *

Contact McAfee Customer Service (800) 338-8754.


* FOR PRODUCT UPGRADES *

To make it easier for you to receive and use McAfee's
products, we have established an Agents program to 
provide service, sales, and support for our products 
worldwide. For a listing of agents, see the file 
AGENTS.TXT, where applicable, or contact McAfee
Customer Service for agents near you.
