Protea AntiVirus Tools for Lotus Domino

Protea AntiVirus Tools for Lotus Domino description and components
Scanning	
Limitations
System requirements
Main features	
Installation	
 ClamAV - Installation Instructions
 Installation of Protea AntiVirus Tools for Lotus Domino
Setting up Protea AntiVirus Tools for Lotus Domin
Description of ini file parameters
Values used in the notification templates
Uninstall of Protea AntiVirus Tools for Lotus Domino
UPDATER of Protea AntiVirus Tools for Lotus Domino
Contact Us

Protea AntiVirus Tools for Lotus Domino description and components
-------------------------------------------------------------------

Antiviral  package Protea AntiVirus Tools for Lotus Domino is designed 
to provide a virus protection within Lotus Domino. Clam AntiVirus and other 
scanner is used for a virus detection.

Protea AntiVirus Tools for Lotus Domino acts as follows: 
* Scans all mail passing through Lotus Domino for viruses.
* Scans for viruses documents in the users bases as set by Administraror.
* Deletes or removes into quarantine infected and suspected mail messages 
  and documents. 
* Notifies users and administrators about infected and suspected objects.
* Saves results in the Log file.

Protea AntiVirus Tools for Lotus Domino consists of the following components:
* Monitor - to check up incoming and outgoing messages.
* Scanner - to check up documents in nsf bases as set by Administrator.
* Updater - for automatic update of anti virus bases.
* Configuration base - to manage anti virus package.
* Quarantine - to keep infected and suspected objects.

Any authorized Administrator of Protea AntiVirus Tools for Lotus Domino can 
set up the package and view infected documents.

Scanning
--------

Real time scanning and cleaning e-mail traffic of Lotus Domino without slowing 
down mail delivery. Infected objects are blocked regardless of format, archive 
or compression type.

Mail messages monitor checks:
* Body of the mail message.
* Attached files.
* Any attached OLE objects.

On-demand scanning ensures that databases are virus-free on setup. Fully 
configurable scheduled database scanning offers an additional layer of 
protection. Scanner checks NSF bases in the catalogs specified by Administrator. 

The following objects in the documents are scanned:
* Rich Text fields.
* Attached files.
* OLE objects.

Limitations
-----------

* Encrypted files can not be checked.
* Electronic signature may be damaged during check up process.
* Files created in OS2 and Macintosh can not be checked.

System requirements
-----------

* OS Windows NT/2000/XP.
* Lotus Domino R5.0.3 for Windows or higher.
* CPU Pentium 133 or higher.
* Enough disk space to accommodate mail messages and documents. 
* Minimum 64 MB RAM (128 MB recommended).

Main features
-----------

There are the following features in use of Protea AntiVirus Tools for Lotus 
Domino:

* Clam AntiVirus scanner is used.
* Different antivirus scanners can be enabled.
* E-mail messages with multiple recipients are filtered only once, before 
  delivery, not once for every recipient.
* Mail messages monitor can process multiple mail boxes.
* Infected or suspicious files are isolated in the quarantine zone, preventing 
  network infection.
* Optimized speed.

Protea AntiVirus Tools for Lotus Domino provides all means to enable different 
antivirus scanners, flexible settings of antivirus according to scan results, 
notification to addressor, addressee and system Administrator about found 
viruses, saving of the original copy of the received mail message.

Enables automatic update of virus definitions, without user intervention, 
directly from the ClamAV servers. Thus, the product is kept up to date, 
ensuring a swift and effective reaction.

Installation
------------

Created and used Protea Antivirus Tools nfs base found in folder Domino\Data\PAVT.

Protea AntiVirus Tools for Lotus Domino package uses Clam AntiVirus scanner. 
Before installation of Protea AntiVirus Tools for Lotus Domino, Clam AntiVirus 
scanner should be installed.

ClamAV - Installation Instructions
==================================

 * Click http://www.sosdg.org/clamav-win32/index.php to open a download page.
 * Use the following link to download a program 'ClamAV for Windows'.
 * How to install 'ClamAV for Windows' you can find at http://www.mxguard.com/postmaster/how_to_clamav.asp.
 * In case of 'ERROR: Unable to create temporary directory', 
   use How To Fix TMP Directory (TMPPDIR) Errors In ClamAV For Windows 
   http://forums.sosdg.org/viewtopic.php?p=34.
 * To enable the ClamAV Daemon the TCP socket should be used. Set the value of 
   LocalSocket in the configuration "file \clamav-devel\etc\clam.conf" to #LocalSocket and 
   the value of TCPSocket to TCPSocket 3310.
 * Start Clamd \clamav-devel\start-clamd.bat or \clamav-devel\bin\clamd.exe.

As long as there were no errors, the installation was a success!

Installation of Protea AntiVirus Tools for Lotus Domino
=======================================================

 * Using Domino Administrator create a group PAVAdmins. By default this group 
   has an administrative access to the NSF bases of the Protea AntiVirus Tools 
   for Lotus Domino package. Include all the administrators of the Protea 
   AntiVirus Tools for Lotus Domino into this group PAVAdmins.
 * Install Protea AntiVirus Tools for Lotus Domino. 
 * Restart Lotus Domino.

If other anti virus programs installed it would be necessary to exclude from 
their scanning a catalog containing temporary files used by Protea AntiVirus 
Tools for Lotus Domino. The path to this catalog can be found in pavt.ini file 
under TempFolder.

Setting up Protea AntiVirus Tools for Lotus Domino
--------------------------------------------------

When changing the settings, the Scanner and Updater modules will use the
newly set parameters as early as one minute after they are saved in the
configuration database. The Hook module requires the server to be restarted to
use the new settings.

Description of ini file parameters
==================================

pavt.ini, section [Notes] 

Common values
=============

* Binary switches "Yes/No"
* All time values are in seconds.
* All file sizes are in kilobytes.
* All file names are given in absolute paths in relation to the folder.
* Meaning of "Action" field is work with objects:
  "Delete" - to delete a message.
  "Move" - to remove a message into the folder for moved objects.
  "Skip" - to skip a message.

LogfilePath
===========
LogfilePath shows a path to the catalogue where log files are created.

TemplatePath
============
TemplatePath shows a path to the catalogue containing templates for 
notification.

TempFolder
==========
TempFolder shows a path to the catalogue where temporary files of Protea 
AntiVirus Tools for Lotus Domino are created.

NSFPath
=======
NSFPath shows a path to the catalogue of the configuration and quarantine bases.

Administrators
=======================
Administrators contains a list of system administrators. If there are 
a few administrators, the first one of the list will be notified regarding 
infected message.

Maximum Logfile Size
==============
Maximum Logfile Size is a maximum size of a log file. 

Enable console
=============
Enable console specifies whether or not to allow report on Console of Lotus 
Domino.
* Yes - to allow.
* No - not to allow.

Infected object
==============
Infected object specifies system actions with infected object.
* CURED - infected object to be cured.
* DELETED - infected object to be deleted.

Infected copy quarantine
======================
Infected copy quarantine specifies whether or not to save in quarantine a 
document with infected object.
* Yes - to save.
* No - not to save.

Infected notification
====================
Infected notification contains a list of system users to be notified regarding 
infected object.
* RECIPIENT - all recipients.
* SENDER - sender. 
* MANAGER - managers listed in the NotificationManagerList.

Infected add body
=======================
Infected add body specifies whether or not to add an information regarding 
infected object into the mail message containing infected object.
* Yes - to add.
* No - not to add.

Infected add log
==============
Infected add log specifies whether or not to add an information regarding 
infected object into the log file.
* Yes - to add.
* No - not to add.

Delete archive action
=========================
Delete archive action specifies whether or not to delete an entire archive 
containing even one infected file.
* Yes - to delete.
* No - not to delete.

Not checked object
================
Not checked object specifies system actions with suspicious object.
* DELETED - suspicious object to be deleted.
* SKIPPED - no action to take place with suspicious object.

Not checked copy quarantine
========================
Not checked copy quarantine specifies whether or not to save in quarantine a 
document containing unchecked object.
* Yes - to save.
* No - not to save.

Not checked notification
======================
NotCheckedNotification contains a list of system users to be notified regarding 
unchecked object.
* RECIPIENT - all recipients.
* SENDER - sender.
* MANAGER - managers listed in the NotificationManagerList.

Not checked add body
=========================
Not checked add body specifies whether or not to add information regarding 
unchecked object into the mail message containing suspicious object.
* Yes - to add.
* No - not to add.

Not checked add log
================
Not checked add log specifies whether or not to add an information regarding 
unchecked into the log file.
* Yes - to add.
* No - not to add. 

Notification body or attachments
===========================
Notification body or attachments specifies whether to substitute a body of 
the mail message with the information regarding infected object or to attach 
it as an attachment.
* BODY - to add into message body.
* ATTACHMENTS - to attach as an attachment. 

Start day
========
Start day specifies weekdays to start a scanner. 
Possible values are Mon;Tue;Wed;Thu;Fri;Sat;Sun.

Start every
==========
Start every specifies a time to start a scanner in format hh:mm. 

List of database paths
=================
List of database paths contains a list of catalogs with the bases to be scanned.

Include subdirectories
=====================
Include subdirectories specifies whether or not to check subdirectories from 
the catalogue list in the ScanDatabasesPath.
* Yes - to check.
* No - not to check.

List of excluded databases
================
List of excluded databases contains a list of data bases masks excluded from 
the scanning process.

Databases objects scaning
========================
Databases objects scaning contains a type of objects to be scanned.
* ATTACHMENTS - all files in the document.
* OLE - all OLE objects in the document.
* BODY - text of the document. 

Databases attachment scanning
===========================
Databases attachment scanning specifies what file extensions to scan.
* ALL - to scan all objects with file extensions not contained in the 
  DatabasesExcludeAttachmentScanningMask.
* MASK - to scan only objects with file extensions contained in the 
  Databases exclude attachment scanning mask.

Databases exclude attachment scanning mask
======================================
Databases exclude attachment scanning mask contains a list of file extensions 
excluded from scanning process unlike the case of DatabasesAttachmentScanning=ALL. 
File extensions are defined as a list where the divider specified in Delimiter 
is used.

Mail objects scaning
===================
Mail objects scaning contains a type of objects to be monitored.
* ATTACHMENTS - all files in the document.
* OLE - all OLE objects in the document.
* BODY - text of the document.

Mail attachment scanning
======================
Mail attachment scanning specifies what file extensions to monitor.
* ALL - to monitor all objects with file extensions not contained in the 
  mail attachment scanning.
* MASK - to scan only objects with file extensions contained in the 
  mail attachment scanning.

Mail exclude attachment scanning mask
=================================
Mail exclude attachment scanning mask contains a list of file extensions 
excluded from monitoring unlike the case of MailAttachmentScanning=ALL.
File extensions are defined as a list where the divider specified in Delimiter 
is used.

Mail attachment scanning mask
==========================
Mail attachment scanning mask contains a list of file extensions to be 
monitored as per *.EXE.

Hourly
============
Hourly  specifies how to update anti virus bases.
* Yes - every hour.
* No - at the times specified in StartUpdaterEvery.

Start updater day
===============
Start updater day specifies weekdays to start an update. Possible values are 
Mon;Tue;Wed;Thu;Fri;Sat;Sun.

Start updater every
=================
Start updater every specifies a time to start an update of anti virus bases in 
format hh:mm. Time value for an update is taken from Start updater every if 
Hourly=No.

Updater path
===========
Updater path is a path to an updater of Clam AntiVirus.

Update URL
=========
Update URL is a url to update virus base of Clam AntiVirus.

Values used in the notification templates
-----------------------------------------

Notification system is used to notify sender, recipients and system 
administrators about infected or suspicious objects. Notification templates 
are kept in the template catalogue. Path to it is specified in ini file of 
TemplatePath.
* virwarn.adm is a template to notify administrator.
* virwarn.lot is a notification  template of attachment to a mail message or 
  included in the body of infected message.
* virwarn.rec is a template to notify recipients.
* virwarn.snd is a template to notify a sender.
* virwarn.quar is a notification template about plasig a message into 
  quarantine base.
* virwarn.note is a template to notify an administrator about infected object.

System Administrator can edit notification text. The following values can be 
used in notification:
* $SENDER$ - sender's mail.
* $RCPTS$ - recipients' mail.
* $SUBJECT$ - subject of the mail message.
* $NOTEID$ - ID of infected mail message.
* $ORIG$ - global ID ($Orig) of infected mail message.
* $QUARANTINE$ - informative notice about placing a message into quarantine 
  base. Text of the message is in virwarn.quar.

Uninstall of Protea AntiVirus Tools for Lotus Domino
----------------------------------------------------

To remove Protea AntiVirus Tools for Lotus Domino the following should be done:
* Stop running Lotus Domino.
* To open  Windows Control Panel/Add/Remove Programs and select Protea AntiVirus. 
* Tools for Lotus Domino, choose an option Remove.
* To restart Lotus Notes/Domino.

UPDATER of Protea AntiVirus Tools for Lotus Domino 
--------------------------------------------------
Update program npavupdate is included in the package of Protea AntiVirus Tools 
Lotus Domino and used to update anti virus bases via Internet from the URL 
specified by Administrator which is located in Update URL. If Hourly=Yes 
update will run every hour. Time for next hourly update will be chosen at random.
If Hourly=No update of anti virus bases will run in days and times specified in 
Start updater day and Start updater every.

Contact Us
----------
WWW: www.proteatools.com
Sales: sales@proteatools.com
Support: support@proteatools.com
