background image

Using Kaspersky Anti-Virus

 

33

 

You can also configure additional

 

settings:  

  Use the settings 

ExcludeDirs

 and

 ExcludeMask 

to

 

define directories that 

will be excluded from the scan.

 

  Use the heuristic code analyzer and the iChecker technologies.

 

 

  Reduce the server load, by defining the maximum number of objects that 

can be scanned at the same time.  

 

Avoid making chages to the 

[monitor.*] 

section of the application con-

figuration  file  if  remote  administration  of  appplication  via  Kaspersky 
Administration Kit is planned. These sections‟ parameters are overriden 

by the settings made via Kaspersky Administration Kit. 

4.4.

 

Managing license keys 

The  license  key  file  gives  you  the  right  to  use  the  application,  and  contains  all 
required information pertaining to the license that you have purchased, including 
the type of the license, the license expiration date, and details of the dealer. 

In  addition  to  the  right  to  use  the  application,  during  the  license  period  you 
obtain: 

  24/7 technical support; 

  new updates of the anti-virus database on an hourly basis; 

  application updates (patches); 

  receiving new versions of the application (upgrades); 

  up-to-date information about new viruses. 

Upon the expiration of the license you automatically lose the right to receive the 
above  services.  Kaspersky  Anti-Virus  will  continue  performing  anti-virus 
processing,  but  it  will  use  the  anti-virus  database  that  was  up-to-date  on  the 
license  expiration  date.  The  anti-virus  database  updating  function  will  not  be 
available.  

Therefore, it is extremely important to regularly review report files that contain the 
license key details, and to keep track of the license expiration date.  

4.4.1.

 

Viewing license key details 

You  can  view  information  about  installed  license  keys  in  reports  about  of  the  

kavscanner, kavmonitor 

and

 keepup2date

  components,  because  each  of  these 

components loads information about these keys when they launch. 

Содержание ANTI-VIRUS 5.7 - FOR LINUX FILE SERVER

Страница 1: ...KASPERSKY LAB KasperskyAnti Virus 5 7 for Linux Workstation ADMINISTRATOR SGUIDE...

Страница 2: ...K AS P ER SKY AN T I VIR U S 5 7 F OR L IN U X W OR K ST AT ION Administrator s Guide Kaspersky Lab Ltd http www kaspersky com Revision date September 2008...

Страница 3: ...n procedure 14 3 3 Post install configuration 15 3 4 Installing Network Agent 16 3 5 Configuring Network Agent 16 3 6 Updating the application to version 5 7 17 3 7 Locating the application files 17 3...

Страница 4: ...ation settings 42 CHAPTER 6 ADMINISTERING THE PROGRAM WITH KASPERSKY ADMINISTRATION KIT 45 6 1 Administering the application 47 6 1 1 Configuring application settings 48 6 1 1 1 Settings tab Real time...

Страница 5: ...codes of the kavscanner component 76 A 4 Command line parameters for component kavmonitor 77 A 5 Command line parameters for component licensemanager 77 A 6 Return codes of the licensemanager compone...

Страница 6: ...contain viruses or mail worms When you open an e mail message or save an attached file to your hard drive you may infect data stored in your computer Software vulnerabilities In most cases hackers att...

Страница 7: ...For instance depending on the particular conditions they can erase information on hard drives freeze the system or steal confidential information In the strict sense Trojan Horses are not viruses sinc...

Страница 8: ...from a local directory Control and configure Kaspersky Anti Virus using the application configu ration file the web based interface of Webmin or the Kaspersky Adminis tration Kit 1 3 What s new in ver...

Страница 9: ...ystems for 64 bit platforms o Red Hat Enterprise Linux 5 2 Desktop o Fedora 9 o SUSE Linux Enterprise Desktop 10 SP2 o openSUSE Linux 11 Webmin program www webmin com for remote administration of Kas...

Страница 10: ...the terms of the License Agreement you can return Kaspersky Anti Virus to your dealer for a full refund 1 6 2 Services for registered users Kaspersky Lab Ltd offers all legally registered users an ex...

Страница 11: ...s dialog boxes and their elements etc Note Additional information notes Attention Information requiring special attention In order to perform 1 Step 1 2 Description of the user s steps and possible ac...

Страница 12: ...omponent The component operates as follows 1 When any application on your computer attempts to access a file system object whether to open run or close the file the call is intercepted by kavmonitor s...

Страница 13: ...Infected the object is infected Cured infected object has been successfully disinfected CureFailed the infected object could not be disinfected Warning object code resembles the code of a known virus...

Страница 14: ...following format rpm for systems that support RPM Package Manager deb for Debian based OS distributions To start the installation of Kaspersky Anti Virus from a rpm package type the following at the...

Страница 15: ...net in the following format http IP of the proxy server port or http user_name password IP of the proxy serv er port depending upon authorization necessity for the proxy The updating component of the...

Страница 16: ...twork Agent After installation the Network Agent has to be configured for its proper interaction with Kaspersky Administration Kit To start configuration run the postinstall pl script located in the o...

Страница 17: ...letion of the upgrade procedure the configuration file of product version 5 5 will be replaced with its counterpart for version 5 7 Add necessary modifications to the configuration file manually 3 7 L...

Страница 18: ...disinfecting archives opt kaspersky kav4ws share doc LICENSE license agreement opt kaspersky kav4ws share man directory containing manual files var opt kaspersky kav4ws bases directory containing the...

Страница 19: ...twork Agent bin setup directory containing configuration scripts for Network Agent share man directory containing manual files sbin directory containing the executable file of the Network Agent servic...

Страница 20: ...ore appropriate to business needs 4 1 Updating the anti virus database Updating the anti virus database is performed by the keepup2date component and is an integral factor in full fledged anti virus p...

Страница 21: ...ommand automatically reloads the anti virus database If an invalid change is made to this setting the application may fail to use the updated database or will function improperly All settings of the k...

Страница 22: ...figure the downloading of anti virus database updates from Kaspersky Lab s updates servers to automatically select the URL of the updates server from the list included in the keepup2date component Sol...

Страница 23: ...any time To do that type the following command opt kaspersky kav4ws bin kav4ws keepup2date Task start the update of the anti virus database and record the results in the file tmp updatesreport log So...

Страница 24: ...ile structure as Kaspersky Lab s updates servers Provided below is a detailed discussion of this task Task create a network directory from which anti virus database up dates can be copied to local com...

Страница 25: ...etting of the updater options section is missing or is assigned value Yes 4 2 Anti virus protection of file systems The kavscanner component provides anti virus protection of the computer s file syste...

Страница 26: ...nt directory To scan all file systems of the computer you have to switch to the root directory or specify the scan scope at the command line as You can redefine the scan path by the following methods...

Страница 27: ...lt behaviour is to scan objects and to notify about detected viruses and other suspicious or corrupted files by printing messages to the screen and in the report see 5 6 on p 42 As a result of an anti...

Страница 28: ...s discriminates between simple objects files and container objects consisting of several objects for example an archive Actions performed with such objects are also discriminated in the configuration...

Страница 29: ...scan of the tmp directory with automatic disinfection of all infected objects detected Delete all objects that cannot be disinfected Create the files infected lst suspicion lst corrupted lst and warn...

Страница 30: ...x commands and script files Using these tools experienced administrators can define actions to be performed on objects of different statuses and thus expand the functionality of Kaspersky Anti Virus 4...

Страница 31: ...pecified in the kav4ws conf configuration file Enable resolving of the symbolic links to the checked objects Solution to perform this task do the following Enter these rules for processing simple obje...

Страница 32: ...he target object is excluded from protection If a symbolic link is added to the IncludeDirs list then it will not be re solved by the kavmonitor component Based on the scan results anti virus object p...

Страница 33: ...ate and details of the dealer In addition to the right to use the application during the license period you obtain 24 7 technical support new updates of the anti virus database on an hourly basis appl...

Страница 34: ...Copyright C Lan Crypto License file 0003D3EA key serial 0038 000419 0003D3EA Kaspersky Anti Virus for Unix expires 04 07 2003 in 28 days License file 0003E3E8 key serial 011E 000413 0003E3E8 Kaspersky...

Страница 35: ...ersky Labs by sending a request directly to our Sales Department sales kaspersky com or filling out a form at our website http www kaspersky com section eStore Re newal Upon receipt of your payment we...

Страница 36: ...x Workstation To remove a license key Enter at the command line opt kaspersky kav4ws bin kav4ws licensemanager da to remove the active license key or opt kaspersky kav4ws bin kav4ws licensemanager dr...

Страница 37: ...ed remotely using the Webmin program are saved in the default configuration file of the application To create an alternative configuration file using Webmin you must 1 Copy data from the existing conf...

Страница 38: ...wo levels The first level stores information about clean files that are accessed relatively of ten This cache is located in the kernel module which considerably re duces the time needed to access it I...

Страница 39: ...increased while it continues to perform other tasks Therefore it is desirable to have a tool that pauses the anti virus scan once a specified load threshold has been exceeded Kaspersky Anti Virus has...

Страница 40: ...e tmp download lst for viruses and move any infected objects detected with the full paths to these ob jects to the directory tmp infected Print information about infected suspicious and corrupted obje...

Страница 41: ...s the ability to copy files to backup storage Before the attempt to disinfect or delete an object a copy of the object will be automatically created in the backup directory section monitor path settin...

Страница 42: ...tting in format year month day and month day year respectively 5 6 Kaspersky Anti Virus report generation settings Results of the operation of all components of Kaspersky Anti Virus are logged in repo...

Страница 43: ...se the application to close for example information about insufficient free disk space or license key expiration Such messages are marked with W symbol in the log file 3 Info Notice Important informat...

Страница 44: ...ed for the on demand scan or up date tasks launched via the Kaspersky Administration Kit Specify the report detail level and report storage directory via the Re portLevel and ReportsDir parameters in...

Страница 45: ...istration Server in the network and install Administration Console on the administrator s workstation For details see the Adminis trator s Guide for implementing Kaspersky Administration Kit deploy th...

Страница 46: ...otection settings and protection scope settings A task is a specific action performed by the application Tasks for Kaspersky Anti Virus are of several types including on demand scan tasks anti virus d...

Страница 47: ...tion settings 1 Select the group that contains the target client computer in the list of Groups see Figure 1 2 In the result pane select the client computer for which you need to modify application se...

Страница 48: ...ent computer on the Applications tab see Figure 2 2 Select Kaspersky Anti Virus 5 7 for Linux Workstation and File Server Click the Properties button to open the application settings window All the ta...

Страница 49: ...the Settings tab you can configure general protection settings and protection scope settings The following sections describe this process in more detail 6 1 1 1 Settings tab Real time protection gener...

Страница 50: ...ing and configuring tasks for Kaspersky Anti Virus Centralized administration with Kaspersky Administration Kit allows you to create and use the following tasks on demand scan task anti virus database...

Страница 51: ...of a single network group global tasks configured for a selected subset of all client computers from all network groups You can modify task settings monitor their performance copy and move tasks from...

Страница 52: ...When you press the Add button a task creation wizard will start up The wizard provides a series of windows which can be navigated using the Back and Next buttons You can finish the wizard by pressing...

Страница 53: ...source to download updates from You can use the update servers of Kaspersky Lab or specify a user defined source whether passive FTP mode is required the connection timeout in seconds You can enable...

Страница 54: ...reation wizard will start similar to the local task creation wi zard for more see 6 2 1 1 on pg 52 The only difference is in selecting the networked client computers to which the task will apply 3 Sel...

Страница 55: ...eneral view general information about a task about starting the task or pausing it Schedule create a schedule for running tasks Notifications configure notifications on the results of tasks for more d...

Страница 56: ...e FTP mode is required the connection timeout in seconds You can enable disable using a proxy server and configure its settings in the dialog that opens after clicking the Configure proxy server 6 2 3...

Страница 57: ...ck and Next buttons You can finish the wizard by pressing Finish The Cancel button will stop the Wizard at any point The following sections describe how to create a task using the wizard During each s...

Страница 58: ...ject types to be protected The lists of directories and object masks are colon delimited Step 4 Finishing creating a policy The final window of the wizard tells you that you have successfully created...

Страница 59: ...he policies created for the group 3 Select the policy to edit from the list of policies for Kaspersky Anti Virus 5 7 for Linux Workstation and File Server the application name is specified in the Appl...

Страница 60: ...application or task properties 6 3 2 1 Configuring the protection scope You can use the Protection scope and objects types section of the Settings tab to define the trusted area directories to be excl...

Страница 61: ...he Protection general settings section of the Settings tab to enable disable disinfection of objects affected by malware enable disable real time protection enable disable the heuristic analyzer enabl...

Страница 62: ...t the application installation process you will have to stop the kavmonitor component To do that type the following in the command line etc init d kav4ws stop Then you will have to uninstall the appli...

Страница 63: ...his test virus from the official website of the EICAR organization at http www eicar org anti_virus_test_file htm The file downloaded from the EICAR website or created as described above contains the...

Страница 64: ...lly deleted The first table column lists the prefixes to be added at the beginning of the string of the standard test virus for example CORR X5O P AP 4 PZX54 P 7CC 7 EICAR STANDARD ANTIVIRUS TEST FILE...

Страница 65: ...file settings default values will be indicated if such default values are provided Section path includes settings that define paths to the most important files without which the application will not...

Страница 66: ...scan mode To disable this mode assign value no to this setting If the archive scan mode is enabled Archives yes then self extracting archives will be scanned even if SelfExtArchives is assigned the va...

Страница 67: ...icious file is detected The file contains code which resembles a virus but one not known yet to Kaspersky Lab OnWarning action actions to be performed in case of a detection of a file containing code...

Страница 68: ...scanning the server s file systems Archives yes archives scan mode To disable this mode assign value no to this setting Cure no mode for disinfecting infected objects In order to enable this mode assi...

Страница 69: ...ile In or der to disable this mode assign value no to this setting ReportFileName a name of the report file into which results of the compo nent operation will be logged If the syslog value is specifi...

Страница 70: ...performed on simple objects of certain types during the anti virus protection of workstations OnCorrupted action actions to be performed in case of a detection of a corrupted file OnInfected action ac...

Страница 71: ...function BackupPath path full path to the backup storage directory for backup copies of objects being scanned by the component Section updater path includes settings that define paths to the files req...

Страница 72: ...lue no then in case of an unsuccess ful update of the anti virus database from address UpdateServerUrl another address from the list of the updates servers will be used UpdateServerUrl no http url ftp...

Страница 73: ...files A 2 Command line parameters for component kavscanner Settings of the configuration file can be overridden from the command line at application startup using command line parameters A detailed d...

Страница 74: ...he screen o name Specify the filename for the file into which report about the operation of the component will be logged if the filename is not specified the report will not be generated Information a...

Страница 75: ...out scan of a sim ple object Short extended format for messages about scan of an archive N n Enable Disable printing messages about clean files to the report file File options p option file_name Save...

Страница 76: ...ected object if disinfection is not possible and if the object is simple object then delete it if the infected object is located in the container then delete the entire container i4 Delete infected ob...

Страница 77: ...cified in the configuration file 66 Invalid configuration file option 65 Unable to load configuration file 70 The kavscanner component has been corrupted 75 The kavscanner component has been corrupted...

Страница 78: ..._to_file Install the license key path_to_key_file d path_to_file Remove license key A 6 Return codes of the licensemanager component During its operation the licensemanager component may return the fo...

Страница 79: ...Cmd command after the anti virus database update has been successfully completed q The mode of the component operation during which no system messages will be printed to the screen e The mode of the c...

Страница 80: ...elp information about the command line parameters supported by the component and close the component 0 The anti virus database does not need to be updated 1 The anti virus database has been updated su...

Страница 81: ...e a considerable load on the pro cessor The process of virus detection is a computational mathematical task that involves analysis of structures checksum calculation and mathe matical data transformat...

Страница 82: ...will be blocked Question What happens when my Kaspersky Anti Virus license ex pires After the expiration of the license Kaspersky Anti Virus will continue op erating but anti virus bases updating feat...

Страница 83: ...buted via floppy disks and at that time it was sufficient to install an anti virus program and update the anti virus database from time to time to ensure adequate computer protection Yet recent virus...

Страница 84: ...ted to an overloaded server while another server is idle The use of key black lists This allows preventing updates to be performed by those users who do not have license for using Kaspersky Anti Virus...

Страница 85: ...of the application s configuration file and de termines the number of files processed at the same time Therefore the number of monitor processes always exceeds 1 by default 20 processes will be start...

Страница 86: ...ask via the Kaspersky Administration Kit Logging of the application activity launched via Administration Kit is dis abled by default Make the following changes to the application s configuration file...

Страница 87: ...omprehensive protection from current and future threats Resistance to future attacks is the basic policy implemented in all Kaspersky Lab s products The company s products consistently remain at least...

Страница 88: ...olutions offered by Kaspersky Lab Ltd Kaspersky OnLine Scanner This program is a free service provided to the visitors of Kaspersky Lab s corporate website The service delivers an efficient online ant...

Страница 89: ...a per component basis It helps protect application integrity against the influence of mali cious software Monitors processes in random access memory Kaspersky Anti Virus 6 0 in a timely manner notifie...

Страница 90: ...s to paid phone services and blocks such activity Kaspersky Internet Security 6 0 registers attempts to scan the ports of your computer which frequently precede network attacks and successfully defend...

Страница 91: ...s server file systems in real time All server files are scanned when opened or saved on the server Prevents virus outbreaks On demand scans of the entire file system or individual files and folders Us...

Страница 92: ...nd outside of corporate networks from all of today s Internet threats viruses spyware hacker attacks and spam Features and functionality Comprehensive protection from viruses spyware hacker attacks an...

Страница 93: ...for users Features and functionality Remote administration of the software package including centralized in stallation configuration and administration Support for Cisco NAC Network Admission Control...

Страница 94: ...otection from phishing attacks and junk mail preventing mass mailings and virus outbreaks scalability of the software package within the scope of system resources available Remote administration of th...

Страница 95: ...local area network in real time scalability of the software package within the scope of system resources available Blocking access from infected workstations Prevents virus outbreaks Centralized repor...

Страница 96: ...Virus for Lotus Notes Domino Kaspersky Anti Virus for Microsoft Exchange Kaspersky Anti Virus for Linux Mail Server Its features include Reliable protection from malicious or potentially dangerous pro...

Страница 97: ...am operation Support for hardware proxy servers Scalability of the software package within the scope of system resources available Automatic database updates Kaspersky Anti Spam Kaspersky Anti Spam is...

Страница 98: ...Web The program is a plug in and scans for viruses and processes inbound and outbound e mail traffic in real time C 2 Contact Us If you have any questions comments or suggestions please refer them to...

Страница 99: ...CD s SLEEVE DOWNLOAD INSTALL OR USE THIS SOFTWARE In accordance with the legislation regarding KASPERSKY SOFTWARE intended for individual consumers KASPERSKY ANTI VIRUS PERSONAL KASPERSKY ANTI VIRUS...

Страница 100: ...on 1 1 1 The Software is in use on a Client Device when it is loaded into the temporary memory i e random access memory or RAM or installed into the permanent memory e g hard disk CD ROM or other stor...

Страница 101: ...obtained then you must have a reasonable mechanism in place to ensure that your use of the Software does not exceed the use limits specified for the license you have obtained This license authorizes...

Страница 102: ...ly consent to the transfer of data to other countries outside your own as set out in the Privacy Policy iv Support Services means a Daily updates of the anti virus database b Free software updates inc...

Страница 103: ...The warranty in i shall not apply if you a make or cause to be made any modifications to this Software without the consent of Kaspersky Lab b use the Software in a manner for which it was not intende...

Страница 104: ...sedes all and any prior understandings undertakings and promises between you and Kaspersky Lab whether oral or in writing which have been given or may be implied from anything written or said in negot...

Отзывы: