Page 1
Errors and technical subject to change. Issued Q1-2009 AntiVir® is a registered trademark of the Avira GmbH. All other brand and product names are trademarks or registered trademarks of their respective owners. Protected trademarks are not marked as such in this manual.
8.1 Support ............................40 8.2 Online Shop............................ 41 8.3 Contact............................41 Chapter 9. Appendix .................42 9.1 Glossary ............................42 9.2 Further Information ........................43 9.3 Golden Rules for Protection Against Viruses ................44 Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Signs and Symbols – Page 4 Introduction We have included in this manual all the information you need about Avira AntiVir Server/ Professional and it will guide you step by step through installation, configuration and operation of the software. The appendix contains a Glossary which explains the basic terms.
Signs and Symbols – Page 4 Cross-reference within the document Abbreviations The manual uses the following abbreviations: Abbreviation Meaning Command Line Scanner Frequently Asked Question Graphical User Interface SMTP Simple Mail Transfer Protocol Virus Definition File Avira GmbH Avira AntiVir Server/ Professional (UNIX)
So, viruses can access a server through a Windows Client and freely cause damage. Avira AntiVir Server/ Professional is a comprehensive and flexible tool for confronting viruses and unwanted programs and for reliable protection of your systems. Right from the beginning, two really important hints: Losing valuable files usually has dramatic consequences.
The license is given in a license file named hbedv.key . You will receive it by email from Avira GmbH. It contains certain data, such as the programs you will use and the period of your license. The same license file may refer to more AntiVir products.
It can be integrated and used within scripts. Avira Updater Avira Updater downloads current updates from the AntiVir web servers and installs them at regular intervals, manually or automatically. It can also send update notifications by email. You can update Avira AntiVir Server entirely or only certain components: signatures, engine, scanner.
- Sun Solaris 10 (SPARC) - Novell Open Enterprise Server Avira AntiVir Professional asks for the following minimum system requirements on your server: • i386 (Linux) or Sparc (SunOS) processor; • 100 MB free hard disk space; • 20 MB temporary disk space;...
Installation You can find the current version of Avira AntiVir Server/ Professional on the Internet www.avira.com. AntiVir is supplied as a packed archive. It contains AntiVir Engine, Guard, Command Line Scanner and the Avira Updater. You will be guided step by step throughout the installation procedure. This Chapter is divided into the following sections: •...
You can easily acquire Avira AntiVir Server/ Professional using our Online Shop (for details, visit http://www.avira.com). Copying the License File Copy the license file hbedv.key to the installation directory on your system ./tmp/antivir-server-prof-<version> or in ./tmp/antivir-workstation-prof-<version> You can also perform the installation without having a license key from the beginning.
Page 11
/usr/lib/AntiVir/ ... done ..Enter the path to your key file: [HBEDV.KEY] copying HBEDV.KEY to /usr/lib/AntiVir/avira.key ... done installation of AntiVir Core Components (Engine, Savapi and Avupdate) complete After you type the path to the key file, the installer continues with updates’...
Page 12
Type one directory, which you want to be protected on-access (for example, /home) and press Enter. If you want to modify the list of protected directories, you can add or remove entries later, by editing /etc/fstab file and remounting dazukofs. Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 13
The automatic system start is configured: setting up boot script ... done installation of AVIRA Guard complete Then the script can install the optional plug-in for Avira Security Management Center: 4) activate SMC support The AntiVir Security Management Center (SMC) requires this feature.
• Later installation of some components, e.g. AntiVir Guard or Avira Updater. • Activating or deactivating the automatic start of Avira Updater or AntiVir Guard. Reinstalling AntiVir The procedure applies to all above mentioned cases: First of all, you have to make sure that AntiVir Guard is stopped:...
Unfortunately, this method is not as efficient as a dedicated email scanner. For an environment with higher throughput requirements, you should consider integrating Avira AntiVir MailGate or SAVAPI-based products. You need a license to integrate the Command Line Scanner with AMaViS.
-Configuration of the Command Line Scanner in avscan.conf – Page 22 Scanner specific configuration in avguard-scanner.conf – Page 26 Configuration of Avira Updater in avupdate.conf – Page 27 • Testing AntiVir Server/ Professional – Page 28, after completing the configuration.
Page 17
For setting more access types at the same time, you have to add the above values. For example, to scan files when opened and when closed, the value has to be 3 (default). Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 18
• all: always scan files, of all types and names. • The default is: ScanMode all ArchiveScan Scanning archives on-access: AntiVir Guard scans archives when opened, depending on the setting for Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 19
You can use macros (preceded by %) to pass the results as arguments to the external program. Thus the data can be treated differently and adjusted to the local conditions. The following table shows the supported macros and their significance: Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 20
The recipients will only receive notifications with the selected priority or higher. Syntax: SuppressNotificationBelow scanner <level> The possible priority levels (in ascending order) are notice, information, warning, error and alert. Example: SuppressNotificationBelow scanner warning Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 21
Win32-Heuristics: Sets the level of heuristic detection in all types of files. Available values are 0 (off), 1 Level (low), 2 (medium) and 3 (high - could result in false alerts!). HeuristicsLevel 1 Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 22
GUISupport Support via graphical user interface (GUI): This option must be activated in order for AntiVir Server/ Professional to communicate with the GUI of Avira SMC. You must enter the following parameters: GuiSupport GuiCAFile /usr/lib/AntiVir/gui/cert/cacert.pem GuiCertFile /usr/lib/AntiVir/gui/cert/server.pem GuiCertPass antivir_default In the case of missing or invalid parameters, the GUI support is not available. The log file records possible errors.
Page 23
Maximum compression rate for archives: MaxRatio This option limits the scanning to files which do not exceed a certain compression level. It ensures protection against so-called "mail bombs", which occupy an unexpectedly large Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 24
File system or partition (device) on which the file is located (hexadecimal) PID of the process UID of the process Flag of file operation (hexadecimal) Access mode of file operation (hexadecimal) Name of the detected virus / unwanted program Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 25
- option to detect all supported malware types. • Syntax: list of types, separated by whitespace or colon. DetectPrefixes <type>[=<bool>] <type>[=<bool>] ... Example: DetectPrefixes adspy=yes appl=no bdc=yes dial=yes game=no hiddenext=no joke=no pck=no phish=yes spr=no Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 26
(low), 2 (medium) and 3 (high - could result in false alerts!). HeuristicsLevel 1 GUISupport Support for Avira Security Management Center: This option must be activated in order for AntiVir Server/ Professional to communicate with the GUI of Avira SMC. You must enter the following parameters: GuiSupport GuiCAFile /usr/lib/AntiVir/gui/cert/cacert.pem GuiCertFile /usr/lib/AntiVir/gui/cert/server.pem...
Page 27
Engine), which provide security against viruses or unwanted programs, are always kept up to date. With Avira Updater you can update Avira software on your computers, using Avira update servers. To configure the update process, use the options in /etc/avira/avupdate.conf described below.
"Avira Updater" will be available for installation on machines administered by the SMC. The "Avira Updater" product allows updates to be configured for all products installed on computers administered by the SMC. For more details, please refer to the SMC documentation.
Page 29
Configuration of AntiVir Guard in avguard.conf – Page 16) Check the value of AccessMask in /etc/avira/avguard.conf. If the value is 0, then AntiVir Guard is deactivated. Check the messages in the logfile of AntiVir Guard or in syslog in order to isolate errors.
See the actions’ list at AlertAction – Page 17 --alert-action=quarantine --archive-max-count=<spec> Limits the number of files packed in archive or mailbox. The Guard does not scan beyond the configured limits. Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 31
Enables or disables recursion into archive containers. By default on. --scan-in-mbox[=<bool>] Enables or disables recursion into archive mailbox. By default on. --scan-mode=<spec> Instructs the scanner how a sample should be scanned. ScanMode {all|smart|ext} Avira GmbH Avira AntiVir Server/ Professional (UNIX)
--config Prints a sample configuration. -C <configuration-file> Use a specific configuration file instead of the default one. Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 33
Defines the absolute path of the directory for temporary files. Set verbose mode on. This option should be used in exceptional cases only, as for --verbose example after a virus detection/removal. --version Prints version information. Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Page 34
You can use the following parameters: --scan-mode=all Scans all files. Scans all subfolders. --scan-in-archive Scans packed files, too. If your DOS partitions are in /mnt and the incoming and outgoing files are in /var: Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Type the command: avscan --scan-mode=all -e -del /home/myhome Reaction to Detecting Viruses/ Unwanted Programs If correctly configured, Avira AntiVir Server/ Professional is set to deal automatically with all the tasks on your computer: • The infected file is repaired or at least deleted.
Updates With Avira Updater you can update Avira software on your computers, using Avira update servers. The program can be configured either by editing the configuration file (see 4.1.4 Configuration of Avira Updater in avupdate.conf), or by using parameters in the command line.
Page 37
Start the update process to test the settings: /usr/lib/AntiVir/avupdate --product=[product] where [product] takes the same values as above. If successful, a report will appear in the logfile /var/log/avupdate.log Avira GmbH Avira AntiVir Server/ Professional (UNIX)
UNIX kernel and the AntiVir Guard will not start. A message will be displayed and you can solve the situation afterwards. Go to the temporary directory where you unpacked Dazuko, for example: Avira GmbH Avira AntiVir Server/ Professional (UNIX)
(file.a) within that folder is a symbolic link to another file (which is not in a folder mounted as dazukofs, for example file.b), access to file.a is always granted, while file.b is not scanned, since it is not accessed through dazukofs. Avira GmbH Avira AntiVir Server/ Professional (UNIX)
The expertise and experience of our developers is available to you. The experts of Avira answer your questions and help you with difficult technical problems. During the first 30 days after you have purchased a license, you can use our AntiVir Installation Support by phone, email or by online form.
Online Shop Would you like to buy our products with a mouse-click? You can visit Avira Online Shop at http://www.avira.com and buy, upgrade or extend AntiVir licenses quickly and safely. The Online Shop guides you step by step through the order menu.
A text file containing commands to be executed by the system (similar to batch files in DOS) Signature A Byte combination used to recognize a virus or unwanted program. SMP (Symmetric Multi UNIX SMP: UNIX version for computers with parallel processors. Processing) Avira GmbH Avira AntiVir Server/ Professional (UNIX)
You can find further information on viruses, worms, macro viruses and other unwanted programs at http://www.avira.com/en/threats/index.html . AntiVir Guard is based on DazukoFS (http://www.dazuko.org), an open source software project. DazukoFS is a kernel module which allows the AntiVir Guard daemon to access the files. Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Set up a plan for data protection and recovery. Your network must be correctly configured and the access rights must be wisely assigned. This is good protection against viruses. Avira GmbH Avira AntiVir Server/ Professional (UNIX)
Need help?
Do you have a question about the ANTIVIR SERVER UNIX and is the answer not in the manual?
Questions and answers