AVIRA ANTIVIR UNIX SERVER User Manual

Hide thumbs Also See for ANTIVIR UNIX SERVER:

Advertisement

Quick Links

www.avira.com
User Manual
UNIX Server

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the ANTIVIR UNIX SERVER and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

Summary of Contents for AVIRA ANTIVIR UNIX SERVER

  • Page 1 User Manual UNIX Server...
  • Page 2: Table Of Contents

    Testing AntiVir UNIX Server ........
  • Page 3 Avira AntiVir UNIX Server Avira GmbH...
  • Page 4: About This Manual

    General information about AntiVir software, its modules, features, system requirements and licensing. 3 Installation Instructions to install AntiVir UNIX Server on your system – using both the installation script and the graphical installation routine. 4 Configuration Directions for optimum settings of AntiVir on your system.
  • Page 5: Signs And Symbols

    Choose component Elements of the software interface such as Select all menu items, window titles and buttons in dialog windows http://www.avira.com URLs Signs and Symbols – Page 4 Cross-reference within the document Avira AntiVir UNIX Server Avira GmbH...
  • Page 6: Abbreviations

    Frequently Asked Question FQDN Fully Qualified Domain Name General Public License Graphical User Interface MIME Multipurpose Internet Mail Extensions Mail Transport Agent Possibly Malicious Software Request For Comment SMTP Simple Mail Transfer Protocol Virus Definition File Avira GmbH Avira AntiVir UNIX Server...
  • Page 7 About this Manual Avira AntiVir UNIX Server Avira GmbH...
  • Page 8: Product Information

    So, viruses can access a server through a Windows Client and freely cause damage. Avira AntiVir UNIX Server is a comprehensive and flexible tool for confronting viruses and unwanted programs on your server and for reliable protection of your system.
  • Page 9: Features

    Optional user-friendly graphical user interface (GUI) for operating and configuring Avira AntiVir UNIX Server. Licensing Concept You must have a license to use Avira AntiVir UNIX Server and accept the license terms (see http://www.avira.com/documents/general/pdf/en/avira_eula_en.pdf). There are different license types for using the various functions of Avira AntiVir UNIX Server: •...
  • Page 10: Modules And Operating Mode Of Avira Antivir Unix Server

    License file on a floppy disk with the first delivery • Newsletter service (printed, regular mail delivery) Modules and Operating Mode of Avira AntiVir UNIX Server The Avira AntiVir UNIX Server security software consists of the following program components: • AntiVir Command line scanner •...
  • Page 11: System Requirements

    System Requirements Avira AntiVir UNIX Server asks for the following minimum system requirements on your server: • i386 (Linux, FreeBSD, OpenBSD, SunOS) or PowerPC (Linux) or Sparc (SunOS) processor;...
  • Page 12: Installation

    Installation Installation You can find the current version of AntiVir UNIX Server on the Internet. If you have a Convenience Package AntiVir CD-ROM, you may also install the product from it. AntiVir is supplied as a packed archive. It contains AntiVir Guard, AntiVir Command line scanner and the Internet Updater.
  • Page 13: Licensing

    Page 8). The license comes in a file named hbedv.key. This license file contains information regarding the scope and period of the license. Without the license file, AntiVir UNIX Server runs only as a demo version with restricted features. Purchasing the License You may contact us by telephone or by email (info@avira.com) to acquire a license file...
  • Page 14 Check the configuration of your computer with the configure script. Based on this information, it will provide appropriate guidance for further installation of the software: ./configure Compile Dazuko: make Optionally: verify if the newly installed module works with the computer's running kernel: make test Avira GmbH Avira AntiVir UNIX Server...
  • Page 15: Integration On Samba

    You do not have to translate and install the entire Samba sources, only samba- vscan pack. The installation of the translated Samba is of course the best way to ensure that the Service and VFS plugin match one another. Avira AntiVir UNIX Server Avira GmbH...
  • Page 16 To integrate AntiVir Samba Scanner in smb.conf for monitoring of the released files, you must activate the vscan-antivir.so plug-in (see Configuring AntiVir Samba Scanner – Page 40). There is no need to start additional services apart from Samba, as the plug-in vscan-antivir.so handles this aspect by itself. Avira GmbH Avira AntiVir UNIX Server...
  • Page 17: Installing Antivir

    Please note the dot and slash in the command syntax. Typing the command without this path specification, leads to another command, which is not related to AntiVir installation process and this would result in error messages and unwanted actions. Press q to close the license text view. Avira AntiVir UNIX Server Avira GmbH...
  • Page 18 Installation If you choose not to install the Internet Update Daemon, or to do this later, manually: without Update Type N or press Enter. Daemon Confirm with Enter. Avira GmbH Avira AntiVir UNIX Server...
  • Page 19 4) installing GUI (+ SMC support) Would you like to install the GUI (+ SMC support)? [y] AntiVir UNIX Server is provided with a GUI, which enables monitoring of realtime activity, the display of log entries and configuration of the product. However, AntiVir is fully functional even without the GUI.
  • Page 20 You can perform this operation manually via the Internet. See Updating AntiVir Manually – Page 55 However, for the initial installation, it is recommended to install the Updater. You can later deactivate it in the configuration settings. Avira GmbH Avira AntiVir UNIX Server...
  • Page 21 You will be asked to enter the path to the compiled Dazuko module dazuko.ko (or dazuko.o): Enter the full path to dazuko.ko: Enter the full path. For example: If dazuko.ko is in /tmp/antivir-server-prof-<version>/contrib/dazuko/ dazuko-<version>/ you should type: /tmp/antivir-server-prof-<version>/contrib/dazuko/dazuko- <version>/dazuko.ko Avira AntiVir UNIX Server Avira GmbH...
  • Page 22 4) installing GUI (+ SMC support) Would you like to install the GUI (+ SMC support)? [y] AntiVir UNIX Server is provided with a GUI, which enables monitoring of realtime activity, the display of log entries and configuration of the product. However, AntiVir is fully functional even without the GUI.
  • Page 23: Reinstalling Antivir

    Open the temporary directory where you unpacked AntiVir: cd /tmp/antivir-server-prof-<version> Type: ./install The installation script performs as described in Installing AntiVir – Page 16). Make the changes you need during installation procedure. AntiVir is installed with the required features. Avira AntiVir UNIX Server Avira GmbH...
  • Page 24: Installing Antivir Unix Server Using The Graphical Installation Routine

    The graphical installation routine serves for installation only. It is in no way related to the GUI for operating and configuring AntiVir UNIX Server. AntiVir UNIX Server with graphical installation only applies to Linux. It needs Java 1.4.0 or higher. Unpack the program into the following directory: /tmp/antivir-server-linux-gui_installer.
  • Page 25 You must agree with these conditions in order to continue with the installation. If Disagree is active, you cannot proceed. Select Agree and click Next. You will see the following window: There are three possibilities for installing AntiVir UNIX Server: • Express setup: The program is installed with basic settings. •...
  • Page 26 Manual install: Dazuko kernel module is created manually (see Installing the Dazuko Kernel Module – Page 12) • No Install: AntiVir Guard is not installed. Select Auto install in order to install Dazuko automatically and click Next. Avira GmbH Avira AntiVir UNIX Server...
  • Page 27 Select Yes and click Next (in this case, an additional question appears at the end of the installation, regarding the automatic start of the Update Daemon). The following step is to copy the license file: Avira AntiVir UNIX Server Avira GmbH...
  • Page 28 Installation Follow the instructions and click Next. The following question refers to the automatic start of AntiVir Guard on system start-up: Select Yes or No and click Next. Avira GmbH Avira AntiVir UNIX Server...
  • Page 29 Choose this option if you wish to install only the GUI. Select GUI only and click Next. The GUI is installed in the following directory: /usr/lib/AntiVir All settings and further instructions appear in a window. Click Install. GUI is installed. Avira AntiVir UNIX Server Avira GmbH...
  • Page 30 According to the installation type you selected, a window will list the performed installation steps: Click Next. You will see the following window: If you want to start the GUI directly: Activate the option Start GUI now and click Done. The installation is completed. Avira GmbH Avira AntiVir UNIX Server...
  • Page 31: Integrating Third-Party Products

    AntiVir MailGate or SAVAPI-based products. You need a license to integrate the Command line scanner with AMaViS. This allows you to generate antivirus scan services for other computers. Avira AntiVir UNIX Server Avira GmbH...
  • Page 32: Configuration

    Configuration Configuration You can adjust AntiVir UNIX Server for optimum performance. You can make the main adjustments immediately after installation. The most common settings are suggested. You can modify these settings anytime, to adjust the product to your requirements. After a short overview, you will be guided step by step through the configuration process: •...
  • Page 33 This section provides a short description of the entries in avguard.conf . The settings affect only the behavior of AntiVir UNIX Server and no other AntiVir programs. You can also learn how to make these settings using a graphical user interface in...
  • Page 34 Size This option limits the scanning process to the files with unpacked size smaller than ArchiveMaxSize (in Bytes). The zero value means no limit. The default setting is 1 Gigabyte (1073741824 Bytes): ArchiveMaxSize 1073741824 Avira GmbH Avira AntiVir UNIX Server...
  • Page 35 ScanMode Configuring files to be scanned: This entry sets the procedure to determine whether a file is to be scanned or not. The available methods are: • extlist: scan only files with certain extensions; Avira AntiVir UNIX Server Avira GmbH...
  • Page 36 Access mode of file operation Name of the detected virus / unwanted program Extra information (if available) Type of detected virus or unwanted program Action performed by AntiVir Guard The user, who carried out the file operation Avira GmbH Avira AntiVir UNIX Server...
  • Page 37 This section provides a short description of the settings in avupdater.conf. These settings affect the Internet Updater of the AntiVir software. Instead of the manual settings, you can use the GUI (if installed) to conveniently edit this configuration file. Avira AntiVir UNIX Server Avira GmbH...
  • Page 38 If your computer is connected to the Internet via an HTTP proxy server, you must specify this so that the automatic Internet Updater functions properly. By default, the settings are deactivated; a direct connection to the Internet is needed. You must specify: Avira GmbH Avira AntiVir UNIX Server...
  • Page 39 (to download the new version on the local storage), the corresponding file is stored in the directory specified with UpdateStoreDir. The default path is a subdirectory in the installation directory: UpdateStoreDir /usr/lib/AntiVir/updcomp Avira AntiVir UNIX Server Avira GmbH...
  • Page 40: Configuration Script

    Type N to restart the configuration script and correct the values. If all settings correspond to the configuration you require: Confirm with Y or Enter to save the configuration file with the new values. Avira GmbH Avira AntiVir UNIX Server...
  • Page 41: Configuring Antivir Samba Scanner

    Your distributor may have already carried out this step or you could use a configuration interface to do this. You can activate the scanner for single shares or for the entire server by making the specific entries in the [global] section of the smb.conf file. Avira AntiVir UNIX Server Avira GmbH...
  • Page 42 (Default: yes). send warning message = yes concerning file File actions: action (infected Apart from blocking the access to concerning files, samba-vscan is also able to perform file action) further actions: Avira GmbH Avira AntiVir UNIX Server...
  • Page 43 AntiVir Samba Scanner is also able to scan within archives if the option antivir scan in archive is set to yes. However, there are limits and archives are skipped when they exceed these parameters (maximum compression ratio, maximum contents size, Avira AntiVir UNIX Server Avira GmbH...
  • Page 44: Configuring Regular Updates

    • You may use AntiVir with cron daemon. This is recommended if you have extensive UNIX knowledge. You have to carry out configuration yourself, but it gives you more flexibility. Avira GmbH Avira AntiVir UNIX Server...
  • Page 45 If not, refer to your UNIX documentation for the information you need. Proxyserver If your AntiVir UNIX Server computer is connected to the Internet via HTTP proxy server, you must make the necessary settings for AntiVir: Run configantivir:...
  • Page 46 The Internet Update Daemon is a very simple service which performs the following command at fixed intervals: antivir --update To enable the following settings, you must first install the Internet Updater i.e. if you have installed AntiVir UNIX Server with Update Daemon as described in Installing AntiVir – Page 16. Otherwise you...
  • Page 47 UNIX documentation. Using cron for updates, you have more configuration possibilities than with the Internet Update Daemon. Example: Enter the following cron job in /etc/crontab: 45 */2 * * * root /usr/lib/AntiVir/antivir --update -q Avira AntiVir UNIX Server Avira GmbH...
  • Page 48 --verify antivir.asc antivir If you do not get any error message, you can use GnuPG for AntiVir updates. Activate GnuPG for AntiVir. In /etc/avupdater.conf enter the path to GnuPG binaries, using the option GnuPGBinary: Avira GmbH Avira AntiVir UNIX Server...
  • Page 49: Testing Antivir Unix Server

    Testing AntiVir UNIX Server After completing the installation and configuration, you can test the functionality of AntiVir UNIX Server using a test virus. This will not cause any damage, but it will force the security program to react when the computer is scanned.
  • Page 50: Operation

    Please use the option --with-<type> --archive-max- Excludes archived files from scanning, when they exceed the count=N limit of file numbers on recursion level. Excludes archived files, if their unpacked size exceeds the --archive-max- given value. size=N Avira GmbH Avira AntiVir UNIX Server...
  • Page 51 Sends a scan report to the specified email address (in --log-email= addition to results displayed on the screen). <addr> Moves affected files to the specified directory (the so-called --moveto=<dir> Quarantine). Avira AntiVir UNIX Server Avira GmbH...
  • Page 52 Also scans the mailbox directory. --scan-in-mbox Sets the procedure for scanning a file. <mode> can be all, --scan-mode=<mode> smart or extlist. smart is the default for on demand scanner. AntiVir keeps its temporary files in <dir>. --temp=<dir> Avira GmbH Avira AntiVir UNIX Server...
  • Page 53 Macro detected in a file (when -dmse option is used). AntiVir does not start, because the parameter -once was used and the program has already run that day. Program aborted; not enough memory. The specified response file was not found. Avira AntiVir UNIX Server Avira GmbH...
  • Page 54: Using Antivir Command Line Scanner

    The specified log file could not be created. AntiVir could not find a required library. Program stopped, because self check failed. Could not read avira.vdf file. Initialization error. License key not found. AntiVir command line scanner has other exit codes when used with --update:...
  • Page 55 Type the command: antivir --scan-mode=all -del /home/myhome If you want to repair infected files from /home/myhome and to delete the files that could not be repaired: Type the command: antivir --scan-mode=all -e -del /home/myhome Avira AntiVir UNIX Server Avira GmbH...
  • Page 56 ------------------ BEGIN SCRIPT ------------------- #!/bin/sh /usr/lib/AntiVir/antivir --update -q case $? in echo "AntiVir is up-to-date" echo "AntiVir has been updated" echo "An error occured during update" esac ------------------- END SCRIPT -------------------- Avira GmbH Avira AntiVir UNIX Server...
  • Page 57: Reaction To Detecting Viruses/ Unwanted Programs

    Send us the virus or unwanted program packed in a password-protected archive (PGP, gzip, WinZIP, PKZip, Arj) attached to an email message to virus@avira.com. When packing, use the password virus. This way the file will not be deleted by virus scanners on the email gateway.
  • Page 58: Graphical User Interface (Gui)

    Overview The graphical user interface (GUI) assists you in operating and configuring AntiVir UNIX Server and it graphically displays the monitoring process. AntiVir UNIX Server is fully functional and configurable even without GUI. The interface is an independent application which can start and stop without influencing the AntiVir UNIX Server.
  • Page 59: Antivir Scanner

    The parameter GuiSupport must be set in avguard.conf. • The user must belong to the "antivir" group. If these requirements are not met, an error message appears: AntiVir UNIX Server is not available on the computer. AntiVir Scanner 6.2.1 Operating AntiVir Scanner Using the GUI You can conveniently configure and perform scanning processes using the AntiVir for UNIX Framework.
  • Page 60 Certificate management: to manage integrated certificates of the other computers in the network. • About...: displays Product information and Support information • Exit: closes GUI. It does not stop AntiVir UNIX Server. Tools • Configuration: to open the configuration window. Report •...
  • Page 61 AntiVir starts scanning, displaying the scan process window. The Scanner searches through the selected directories using the current configuration. All computers must have the executable antivir in the directory specified in the configuration. Status The Scanner status. Folder The currently scanned directory. Avira AntiVir UNIX Server Avira GmbH...
  • Page 62 When you expand the node (click the plus sign), the following data is listed: • Details of scan conducted on <Date> <Time> • Note in the case of cancelled scanning • Time taken for scan • Number of scanned directories • Number of scanned files Avira GmbH Avira AntiVir UNIX Server...
  • Page 63 The configuration settings are grouped in two categories: Basic and Expert settings. For access to the second category, you have to activate the Expertmode option. Click the desired tag in the left panel (Search, Archives, Report... ). The configuration options are displayed in the right panel. Avira AntiVir UNIX Server Avira GmbH...
  • Page 64 If you do not want to follow symbolic links during the scan process: Activate the check-box Do not follow symbolic links. Basic Mode - Scanner Archive Settings Search archives If you want the AntiVir Scanner to search within archives: Activate the Search archives option. Avira GmbH Avira AntiVir UNIX Server...
  • Page 65 Type the path to the report file. This is usually: /home/username/.AntiVir/avscanner.log Shorten report If you activate this option, you can select the maximum number of lines saved in the report file (Cut off after...). Avira AntiVir UNIX Server Avira GmbH...
  • Page 66 If you want the Scanner to create short reports: Activate the option Generate short report. Type the path to the output file. Set the number of entries. Expert Mode - Scanner Settings for Action by Malware Avira GmbH Avira AntiVir UNIX Server...
  • Page 67 If you have activated the archive scanning but you want to scan only those archives which Archive size do not exceed a certain size: Activate the Restriction of archive size option and type the desired size in bytes (Maximum size). Avira AntiVir UNIX Server Avira GmbH...
  • Page 68 Select Heuristic, in order to activate Win32-file heuristics, for detecting even unknown file viruses, worms, trojans etc. You can set the intensity of this method: • Detection level low • Detection level medium • Detection level high Avira GmbH Avira AntiVir UNIX Server...
  • Page 69: Antivir Guard

    Starting GUI The entry GuiSupport must be activated in avguard.conf in order for AntiVir UNIX Server to communicate with the GUI. Start the GUI: /usr/lib/AntiVir/antivir-gui The GUI appears, displaying the Folders view. Avira AntiVir UNIX Server Avira GmbH...
  • Page 70 • Certificate management: to manage integrated certificates of the other computers in the network. • About...: displays Product information and Support information. • Exit: closes GUI. It does not stop AntiVir UNIX Server. Avira GmbH Avira AntiVir UNIX Server...
  • Page 71 AntiVir Guard and the latest entries in the logfile. State AntiVir Guard’s current status: running or stopped. Guard Logfile Window Click on the Logfile button. – OR – Select the menu option Guard/Logfile. The Logfile window appears: Avira AntiVir UNIX Server Avira GmbH...
  • Page 72 Configuring AntiVir Guard Using the GUI – Page 72 Starting and Stopping AntiVir Guard Start Select the menu option Guard/Start Guard. Stop Select the menu option Guard/Stop Guard. Closing GUI Select System/Exit. The GUI is closed. Avira GmbH Avira AntiVir UNIX Server...
  • Page 73 /home. You can specify only one folder in a command line. You can enter more folders by typing the command for each one. Example: /home and /media. Avira AntiVir UNIX Server Avira GmbH...
  • Page 74 This option sets the access type of AntiVir Guard, when scanning files for viruses or unwanted programs: • Scan on file open • Scan on file close • Scan on file execute This option sets the AccessMask parameter in avguard.conf. Activate the required check-box(es). Avira GmbH Avira AntiVir UNIX Server...
  • Page 75 If you activate Move: Type in the path to the directory where concerning files will be stored. Email If AntiVir Guard should send emails when a virus or unwanted program is detected: Write the email address. Avira AntiVir UNIX Server Avira GmbH...
  • Page 76 3 and it is appropriate for smaller standard computers. For servers with a high level of traffic, a larger number would be necessary. Here you may also deactivate AntiVir Guard. These options correspond to NumDaemons in avguard.conf. Select the required number of daemons. Avira GmbH Avira AntiVir UNIX Server...
  • Page 77 If you want the Guard to scan in archives: Activate the option Search archives. Basic Mode - Guard Heuristic Settings Macrovirus- Select Macrovirusheuristic in order to activate heuristic methods when scanning heuristic your documents for macro viruses. Avira AntiVir UNIX Server Avira GmbH...
  • Page 78 Expert Mode - Guard Archive Settings The Expertmode enables the following configuration settings: Recursion Activate the option Restrict recursion depth and select the desired value. depth Archive size Activate the option Archive size and select the desired limit. Avira GmbH Avira AntiVir UNIX Server...
  • Page 79 Selection of You can configure AntiVir Guard to scan for so-called Extended threat categories. extended Activate the required categories. threat The tooltip contains details about every category. categories The list may change after updates. Avira AntiVir UNIX Server Avira GmbH...
  • Page 80: Service

    The expertise and experience of our developers is available to you. The experts of Avira answer your questions and help you with difficult technical problems. During the first 30 days after you have purchased a license, you can use our AntiVir Installation Support by phone, email or by online form.
  • Page 81: Online Shop

    Service Online Shop Would you like to buy our products with a mouse-click? You can visit Avira Online Shop at http://www.avira.com and buy, upgrade or extend AntiVir licenses quickly and safely. The Online Shop guides you step by step through the order menu.
  • Page 82: Appendix

    Demo version Without a license file, AntiVir UNIX Server runs as a demo version and it only reports the test virus EICAR. It will not block access to infected files. The update function is not available.
  • Page 83: Further Information

    Virtual File System Further Information You can find further information on viruses, worms, macro viruses and other unwanted programs at http://www.avira.com/en/threats/index.html . Avira AntiVir UNIX Server Avira GmbH...
  • Page 84: Golden Rules For Protection Against Viruses

    Set up a plan for data protection and recovery. Your network must be correctly configured and the access rights must be wisely assigned. This is good protection against viruses. Avira GmbH Avira AntiVir UNIX Server...
  • Page 85 Errors and technical subject to change. Issued May 2007 AntiVir is a registered trademark of the Avira GmbH. ® All other brand and product names are trademarks or registered trademarks of their respective owners. Protected trademarks are not marked as such in this manual. However, this does not mean that they may be used freely.

Table of Contents