Protea AntiVirus Tools for Lotus Domino

Protea AntiVirus Tools for Lotus Domino overview and components
Scanning	
Limitations
System requirements
Main features	
Installation
 Installing Protea AntiVirus Tools for Lotus Domino
 Post-install configuration
Uninstalling Protea AntiVirus Tools for Lotus Domino
Configuring Protea AntiVirus Tools for Lotus Domino
Description of the ini file parameters
Description of the configuration database parameters
Variables used in the notification templates
UPDATER of Protea AntiVirus Tools for Lotus Domino
Contact Us

Protea AntiVirus Tools for Lotus Domino overview and components
---------------------------------------------------------------

The Protea AntiVirus Tools for Lotus Domino antiviral package is designed to 
provide virus protection for Lotus Domino. The Avast, Clam AntiVirus and 
Quick Heal scanners are used to detect viruses.

The Protea AntiVirus Tools for Lotus Domino software does the following to 
ensure your protection: 
- Mail is scanned as it passes through the Lotus Domino environment.
- Documents in the user databases are scanned as set by Administrator.
- Infected and suspicious mail messages and documents are either deleted or quarantined. 
- Users and administrators are notified about infected and suspicious items.
- Results are saved in a log.

Protea AntiVirus Tools for Lotus Domino includes the following components:
- Monitor - that scans all incoming and outgoing mail.
- Scanner - that scans all documents in the nsf databases as set by Administrator.
- Updater - that updates antivirus databases automatically.
- Configuration database - that is used to manage the antivirus package.
- Quarantine store - that is used to keep infected and suspected objects.

Any authorized Administrator of Protea AntiVirus Tools for Lotus Domino can 
configure the package and view the infected documents.

Scanning
--------

Real time scanning and cleaning of the Lotus Domino e-mail traffic doesn't 
slow down mail delivery. Infected objects are blocked regardless of their 
format and archive or compression type used.

The mail messages monitor checks:
- Body of the mail message.
- Attached files.
- Any attached OLE objects.

On-demand scanning ensures that databases are virus-free on setup. Fully 
configurable scheduled database scanning offers an additional layer of protection. 
Scanner checks NSF bases in the directories specified by Administrator. 

The following components of the documents are scanned:
- Rich Text fields.
- Attached files.
- OLE objects.

Limitations
-----------

- Encrypted files cannot be checked.
- Electronic signature may be damaged during the scanning process.
- Files created in OS2 and Macintosh cannot be checked.

System requirements
-------------------

Windows NT/2000/XP/2003/2008 operating system.
Lotus Domino R6.0.1 for Windows or higher.
CPU Pentium 133 or higher.
Enough disk space to store mail messages and documents. 
64 MB RAM (128 MB recommended).

Main features
-------------

Features of Protea AntiVirus Tools for Lotus Domino:

- The Avast, Clam AntiVirus and Quick Heal scanners are used.
- Different antivirus scanners can be plugged in.
- Lotus Domino R6.0.1 and higher is supported (Notes/Domino server R6, R6.5, R7 or R8).
- Lotus Domino partitioned server is supported.
- High performance allows it to check up to 18 000 messages per hour.
- Infected messages can be cured instead of being deleted.
- E-mail messages with multiple recipients are scanned once before  delivery. No additional per-recipient scans are performed.
- The mail messages monitor can process multiple mail boxes.
- Infected or suspicious files are isolated in the quarantine zone, preventing network infection.
- Optimized speed.

Protea AntiVirus Tools for Lotus Domino supports plugging in different antivirus 
scanners and flexible antivirus configuration according to scan results. 
The addressor, addressee and system Administrator are notified about found 
viruses and the original copy of the received message is saved.

Automatic update of virus definitions directly from the Avast, ClamAV and 
Quick Heal servers is supported. Thus, the product is kept up to date, ensuring 
an effective service.

Installation
------------

During installation the Protea Antivirus Tools nfs database is created in the 
Domino\Data\PAVT folder.

The Protea AntiVirus Tools, ClamAV version uses the ClamWin AntiVirus scanner. 
Before installing Protea AntiVirus Tools for Lotus Domino, make sure that the 
ClamWin AntiVirus scanner is installed.

ClamWin - Installation Instructions
===================================

To install ClamWin engine:
- Proceed to the http://www.clamwin.com page.
- Use the following link to download the ClamWin software package.
- Install ClamWin to your server.
- When installing ClamWin for Windows, select Full type of install.

Installing Protea AntiVirus Tools for Lotus Domino
==================================================

- Before beginning the installation of Protea AntiVirus Tools for Lotus Domino 
  it is necessary to have installed Lotus Domino server R6.0.1 or higher. 
- Install Protea AntiVirus Tools for Lotus Domino. 
- Restart Lotus Domino.

If you have other antivirus programs installed, it is necessary to remove 
the Protea AntiVirus Tools for Lotus Domino temporary directory from their 
scanning targets. This directory is specified as the TempFolder value in 
the pavt.ini file.

Post-install configuration
==========================

In order for the application to function correctly, you must perform Domino 
database signing process after installing Protea AntiVirus on the server:

- Launch Lotus Domino Administrator. In the left frame of the opened window, 
  select the Protea AntiVirus configuration base (Domino\Data\PAVT\pavconf.nsf).
- In the context menu, select Sign for this base.
- Press OK in the window that will appear.
- Close Lotus Administrator.

After installation Protea AntiVirus uses the minimal set of parameters most 
of which are set to default values. You can tune the configuration according 
to the peculiar properties of your network and computer. To do this:
- Launch Lotus Client. 
- Open Domino\Data\PAVT\pavconf.nsf. 
- Make the required changes in the application's settings.

CHECKING WHETHER APPLICATION WORKS PROPERLY
===========================================

After installing and configuring Protea AntiVirus Tools we recommend to you 
check whether the program configuration is correct and application is working 
properly using the test "virus" and its modifications.
This test "virus" was specially designed by (The European Institute for 
Computer Antivirus Research) for testing anti-virus products.
The test "virus" is NOT A COMPUTER VIRUS. It does not contain any executable 
code that can damage your computer, however most anti-virus products will 
identify it as a virus.

WARNING: Never use real viruses to test your anti-virus products!

You can download the test "virus" from the official website of EICAR 
http://www.eicar.org/anti_virus_test_file.htm
If you don't have an internet connection, you can create it yourself: 
type the following text in any text editor and then save it as the "eicar.com" 
file:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TESTFILE!$
H+H*

The file that you have download from the EICAR website or created yourself 
contains the body of the standard test "virus". The anti-virus detects this 
virus, marks it as "Infected, cannot be cured" and performs actions configured 
by the administrator for such types of viruses. 

WARNING: it is recommended that you check the anti-virus for both incoming and 
outgoing mail for both message body and attachments. To test how the anti-virus 
checks message body, insert the text of the standard test "virus" to the message body.

Uninstalling Protea AntiVirus Tools for Lotus Domino
----------------------------------------------------

To remove Protea AntiVirus Tools for Lotus Domino from your system, do the 
following:
- Quit Lotus Domino.
- Go to the Windows Control Panel/Add/Remove Programs, select Protea AntiVirus 
  Tools for Lotus Domino and choose the Remove option.
- Restart Lotus Notes/Domino.

Configuring Protea AntiVirus Tools for Lotus Domino
---------------------------------------------------

If you changed the settings, the Mail Monotor, Scanner and Updater modules will 
reread the updated parameters in a minute after they are saved in the configuration 
database.

*** Description of the ini file parameters ***

LogfilePath
===========

LogfilePath specifies the path to the log files directory.

TempFolder
==========

TempFolder specifies the path to the temporary files directory. In case there 
are other anti-virus applications installed on the server, you should exclude 
the directory specified by TempFolder from their scan list.

LogLevel
========

The LogLevel variable specifies logging level.

0 - warning messages, message scanning report, virus infection report, 
    user base scanning report.
1 - detailed scanning report
2 - note and database open/close report
3 - debugging level

*** Description of the configuration database parameters  ***

*** Configuring Global settings ***

User name
=========

User name specifies the  registered username.

Serial number
=============

Serial number specifies the registered serial number.

*** Configuring Scan engine ***

Configuring actions performed on infected files
===============================================

The Actions section contains the settings of actions to perform on infected 
objects including those which are performed when files can't be cured.
The On infected attachments field determines actions to perform on infected 
objects.
- Log only action sets mode of virus search within scanning objects.
- Clean the infected attachment sets mode of virus cure in detected infected objects.
- Quarantine the document sets mode of moving infected objects to the Protea AntiVirus Quarantine database.
- Delete infected attachment enables removal of infected objects from Notes documents.

The On uncleanable attachments field specifies actions to perform on infected 
objects if their cure fails:
- Log only - skip infected objects.
- Delete - delete infected objects.
- Quarantine - move to the Protea AntiVirus Quarantine database.

The On archives containing viruses field specifies actions to perform on 
infected archives:
- Log only - skip infected objects.
- Delete - delete infected objects.
- Quarantine - move to the Protea AntiVirus Quarantine database.

Configuring actions performed not checked files
===============================================

Sometimes Protea AntiVirus can't scan a file. Protea AntiVirus allows 
configuring actions to perform on such not checked files.
It specifies actions to perform on not checked objects:
- Log only - skip suspicious objects.
- Delete - delete suspicious objects.
- Quarantine - move to the Protea AntiVirus Quarantine database.

*** Configuring Email Monitor ***

Attachments to scan
===================

This specifies how "File extensions to scan" and "Exclude files by extension" 
affect scanning process.
- YES - files with any extension except those in "Exclude files by extension" are scanned.
- NO - only files with extensions specified in "File extensions to scan" are scanned.

File extensions to scan
=======================

This specifies the list of file extensions that are scanned 
if "Attachments to scan " is NO.

Exclude files by extension
==========================

This specifies the list of file extensions that are not scanned 
if "Attachments to scan" is YES. The Delimiter value specifies the character 
used to separate the extensions.

Objects to scan
===============

This specifies which items are scanned.
- Scan Attachments - enables scanning of all files in the document.
- Scan OLE objects - enables scanning of embedded OLE-objects, for example MS Office objectst.
- Scan HTML bodies - enables scanning of mail message body.

Configuring virus notifications
===============================

- Warning to administrator(s) enables sending mail notifications of detected 
  viruses to administrators and/or to administrator groups specified in the 
  Administrator(s) field.
- Warning to sender enables sending mail notification to an infected message sender. 
- Warning to recipient(s) sending mail notification to infected message recipients.

Add virus information to original mail body
===========================================

- Add virus information to original mail body allows including information about 
infected objects scan results in the body of a message.

*** Configuring Schedule Scanner ***

Day(s) of week to run on
========================

This specifies days of the week when the scanner is launched. Possible values 
are Mon;Tue;Wed;Thu;Fri;Sat;Sun.

Time(s) to run
==============

This specifies the time interval between subsequent scans in the hh:mm format. 
The ';' character is used as list delimiter.

Databases or directories to scan on server
==========================================

This specifies the list of directories that contain databases for scanning.

Include subdirectories
======================

This specifies whether the "Databases or directories to scan on server" 
directory list is included along with subdirectories.
- YES - subdirectories are included.
- NO - subdirectories are not included.

Databases and directories to exclude from scan
==============================================

This specifies the list of databases (you can use filename or full path) that 
will not be scanned.

Attachments to scan
===================

This specifies how "File extensions to scan" and "Exclude files by extension" 
affect scanning process.
- YES - files with any extension except those in "Exclude files by extension" are scanned.
- NO - only files with extensions specified in "File extensions to scan" are scanned.

File extensions to scan
=======================

This specifies the list of file extensions that are scanned if 
"Attachments to scan " is NO.

Exclude files by extension
==========================

This specifies the list of file extensions that are not scanned if 
"Attachments to scan" is YES. The Delimiter value specifies the character used 
to separate the extensions.

Objects to scan
===============

This specifies which items are scanned.
- Scan Attachments - enables scanning of all files in the document.
- Scan OLE objects - enables scanning of embedded OLE-objects, for example, MS Office objectst.
- Scan HTML bodies - enables scanning of mail message body.

Configuring virus notifications
===============================

Warning to administrator(s) enables sending mail notifications of detected 
viruses to administrators and/or to administrator groups specified in 
the Administrator(s) field.

*** Configuring Updater ***

Hourly
======

Hourly specifies how to update anti-virus bases.
- YES - every hour.
- NO - specified by "Time(s) to update".

Day(s) of week to update on
===========================

This specifies days of the week when updating is performed. Possible values 
are Mon;Tue;Wed;Thu;Fri;Sat;Sun.

Time(s) to update
=================

This specifies the time interval between subsequent anti-virus updates in 
the hh:mm format. The ';' character is used as list delimiter. This is used 
if Hourly=NO.

The Use a proxy server field defines the usage of a proxy-server when downloading 
virus databases from the Internet. Provided the option is enabled, the following 
settings of the proxy-server are available:
- Address defines a proxy-server IP-address.
- Port number defines a port number.
- User name defines user name to authenticate at a proxy-server.
- Password defines a password.

Update path
===========

This specifies the path to the AntiVirus engine updater.

Update URL
==========

This specifies the url to the AntiVirus engine virus databases update.


Values used in the notification templates
-----------------------------------------

System Administrator can edit the notification text. The following variables 
can be used:
$SENDER$ - sender's mail address.
$RCPTS$ - recipients' mail address.
$SUBJECT$ - subject of the message.
$NOTEID$ - ID of the infected message.
$ORIG$ - global ID ($Orig) of the infected message.
$QUARANTINE$ -notification about a message being quarantined. The text of the message is contained in virwarn.quar.

UPDATER of Protea AntiVirus Tools for Lotus Domino 
--------------------------------------------------

The npavupdate program is included into the Protea AntiVirus Tools for 
Lotus Domino package. It can be used to update antivirus bases via the Internet 
using the URL specified by Administrator .using the Update URL configuration option. 
If the Hourly value is set to Yes then updating will be performed every hour 
(with time of the update chosen at random) If Hourly=No then updating will be 
performed as specified by the Day(s) of week to update on and Time(s) to update 
configuration parameters.

Contact Us
----------

www: www.proteatools.com
Sales: sales@proteatools.com
Support: support@proteatools.com

Postal Address:

P.O.Box 25450 
Monument Park 
0105 
South Africa
