Administrators manual
Kaspersky Lab
http://www.kaspersky.com
Revision date: April 2004
Contents
CHAPTER 1. KASPERSKY ANTI-VIRUS FOR WINDOWS FILE SERVERS............. 6
1.1. What's new in version 5.0 ..................................................................................... 7
1.2. Hardware and software system requirements ..................................................... 8
1.3. Product package.................................................................................................... 9
1.4. Services for registered users ................................................................................ 9
1.5. Adopted conventions........................................................................................... 10
CHAPTER 2. SOFTWARE INSTALLATION AND REMOVAL ................................... 12
2.1. Software installation ............................................................................................ 13
2.2. Software removal................................................................................................. 15
2.3. Version upgrade from 4. to 5.0.......................................................................... 15
CHAPTER 3. APPLICATION MANAGEMENT CONCEPTS ...................................... 16
3.1. Introduction to software administration ............................................................... 17
3.2. User interface concepts....................................................................................... 17
3.2.1. Main application window .............................................................................. 18
3.2.2. Console tree.................................................................................................. 18
3.2.3. Context-sensitive (Right-click) menu............................................................ 19
CHAPTER 4. DEFAULT SERVER PROTECTION...................................................... 20
4.1. Levels of anti-virus protection.............................................................................. 20
4.2. Default settings .................................................................................................... 22
CHAPTER 5. RECOMMENDED SETUP DEPENDING UPON SERVER
CONFIGURATION..................................................................................................... 24
CHAPTER 6. LOCAL MANAGEMENT......................................................................... 25
6.1. Using the command line...................................................................................... 25
6.1.1. Scanning selected objects............................................................................ 26
6.1.2. Full scan........................................................................................................ 27
6.1.3. Launching update ......................................................................................... 28
6.1.4. Rolling back the last update ......................................................................... 29
6.1.5. Real-time protection...................................................................................... 29
The ability to disinfect files in ZIP, ARJ, CAB, and RAR archives has been
added.
Backup storage for original objects has been created in order to preserve
backup copies of suspicious or infected objects created prior to their
disinfection or removal.
The event report functionality has been extended, enabling logged events
to trigger corresponding actions, for example: saving to Windows Event
Log, E-mail notification, notification using NET SEND or run an operating
system command.
32 MB of free RAM;
64 MB of free RAM;
user's manual;
license agreement.
Please read the license agreement carefully before opening the CD
envelope.
If you purchase our product from a web shop, you will copy it from the Kaspersky
Lab's website; the copy also contains this manual. Your license key is either
included in the installation file or sent to you by e-mail after payment.
The license agreement constitutes a legal agreement between you and
Kaspersky Lab containing the terms and conditions under which you may use the
purchased software.
Please read the license agreement carefully!
If you do not agree with the terms of the license agreement you must return the
box containing Kaspersky Anti-Virus to the distributor where you purchased it;
you will be refunded the amount you've paid for subscription, provided the CD
envelope remains sealed.
Opening the sealed envelope of the installation CD or installing the product to a
computer confirms your acceptance of all the terms and conditions of the license
agreement.
10
software upgrades;
notifications about new software products from the Kaspersky Lab, and
new viruses outbreaks. This service is provided to users who have
subscribed to the Kaspersky Lab e-mail newsletter service.
No consulting is offered for issues pertaining to operating systems'
functioning or use, or to the use of non-Kaspersky technologies.
Purpose
Used to indicate menu titles, menu
items, window titles, parts of dialog
boxes, and other graphical interface
items.
Bold type
Note.
Attention!
Step 1.
2.
Task, example
11
Style
Solution
Purpose
Text of information
messages and the command
line
CHAPTER 2. SOFTWARE
INSTALLATION AND
REMOVAL
There are two main choices for the installation of Kaspersky Anti-Virus: local
installation, and remote installation, through a centralized administration
computer using Kaspersky Administration Kit 5.0. This manual describes the
local installation of Kaspersky Anti-Virus. For details regarding remote
product installation please consult the administrators guide for Kaspersky
Administration Kit 5.0.
Further installation choices must be made depending upon the intended use of
the application:
Management through Administration console: install Kaspersky AntiVirus on the server, together with Administration Agent and Administration
console which are included in the Kaspersky Administration Kit package.
In this case the application is managed locally through Administration
console.
If you are planning to control the Anti-Virus later remotely via
Kaspersky Administration Kit 5.0, then ensure during
installation of Administration Agent that the Administration
Server name has been specified correctly.
13
14
support information
information);
(support
provider
and
its
contact
The License key window may have a different look depending on key
availability; the key may be bundled with the installation package or you may
have to load it from the Internet.
The installer will add the license key file automatically, if it can be found on the
installation disk or in the target directory specified for installation. Information
about the key being installed will appear on the screen during the procedure.
If the installer cannot locate the license key file, you will be offered this choice of
license file locations:
Local license key to install a key located on the computer.
Internet license key to obtain the key via Internet from the Kaspersky
Lab's website.
Selection of the first option opens a window where you should locate your license
key file with the .key extension using the Browse button.
Selection of the Internet license key option opens a dialog box where you
should fill in the information fields and enter your key activation code (provided at
the time of product purchase). When you have entered the information, click
Next.
15
CHAPTER 3. APPLICATION
MANAGEMENT CONCEPTS
Kaspersky Anti-Virus is installed on servers and can either be controlled locally,
or remotely through Kaspersky Administration Kit if the computer is included in a
centralized control system.
The application recognizes two categories of users:
to
as
17
. Settings
18
In this section we shall discuss the interface's most important elements: the main
window, console tree and right-click context menu.
The menu it contains the main features used to manage files and dialog
boxes and provides access to Help topics.
The toolbar its buttons provide quick access to frequently used menu
options.
The view pane, which displays the list of anti-virus system objects as a
console tree.
The results pane, which shows a list of elements for the object selected
in the console tree.
19
The Local computer object is designed for the local management of Kaspersky
Anti-Virus installed on the server computer. The context-sensitive (right-click)
menu allows to you to open the application settings dialog box, which also allows
the tuning of local server tasks.
If an Administration server is present on the LAN you can control Kaspersky AntiVirus on remote servers. When a connection to an Administration server is
established the <Server name> node will display a list of folders (please see
details in the Administrator's guide for Kaspersky Administration Kit 5.0).
Selecting a folder in the console tree displays its contents in the results pane.
Objects within the folders can be managed using the context-sensitive menu.
The Policies and Tasks folders in the Groups folder are intended for the
management of group policies (see Chapter 6 on p. 25) and tasks (see section
7.2 on p. 76). You can modify application settings (see section 7.3 on p. 80) and
local task parameters (see section 7.2 on p. 76) for all remote computers on
which Kaspersky Anti-Virus is installed, provided that they are included in the
Groups folder.
If you modify any of the predefined level settings the level of anti-virus protection
will change to Customized. It is the fourth anti-virus protection level using
custom user settings.
The table below contains the settings of real-time protection tasks (protection)
and on-demand scanning tasks (scanning) for the predefined security levels.
Legend:
+
enabled setting;
disabled setting;
the setting is not applicable for the task.
21
Recommended
High speed
Protection
Scanning
Protection
Scanning
Protection
Scanning
+
Files by
format
Files by
format
All files
Files by
format
All files
Files by
extension
60
60
60
60
22
infectable files are analyzed when they are opened for reading, writing
and execution, namely:
Archives, e-mail databases, are files in e-mail text formats are not
checked.
startup objects;
23
objects in RAM;
e-mail databases and files in e-mail text formats are not scanned;
CHAPTER 5. RECOMMENDED
SETUP DEPENDING UPON
SERVER CONFIGURATION
A computer may perform several roles simultaneously. For instance, it can act at
the same time as a file server, e-mail server, application server, and database
server etc.
During Anti-Virus setup you are advised to configure your server following the
guidelines below:
You are advised to avoid double scanning of the same objects by different
anti-virus tools, as rescanning reduces application performance. This is
especially true for data transferred by client-server applications, which
should only be scanned on the server.
CHAPTER 6. LOCAL
MANAGEMENT
6.1. Using the command line
Kaspersky Anti-Virus can be controlled using the command line, which supports
the following tasks:
SCAN
FULLSCAN
UPDATE
ROLLBACK
RTP
START
STOP
TASK
CONVERT
IMPORT
EXPORT
26
PREDEFINED
/L[!]:objects_file
[/F(A|E|C)]
/FA
27
Local management
/FC
/FE
/W:report_file
/WA:report_file
/DISINFECT
/DELETE
Examples:
KAVSHELL SCAN "C:\Program Files" C:\Downloads\test.exe
/MEMORY /STARTUP /FA /DISINFECT /WA:log.txt
KAVSHELL SCAN /MEMORY /STARTUP C:\Downloads\test.exe /FC
/W:log.txt
28
/WA:report_file
Example:
KAVSHELL FULLSCAN
KAVSHELL FULLSCAN /WA:fullscan.log
/W:report_file
/WA:report_file
/APP
Examples:
KAVSHELL UPDATE /WA:avbases_upd.txt
KAVSHELL UPDATE /APP
29
Local management
/WA:report_file
Examples:
KAVSHELL ROLLBACK /WA:rollback.log
/W:report_file
/WA:report_file
/STOP
30
taskid
Examples:
KAVSHELL RTP /START /W:rtp.log
KAVSHELL RTP on-access /START /WA:oas.log
KAVSHELL RTP script-checker /STOP
31
Local management
/START
/W:report_file
/WA:report_file
/STOP
/PAUSE
/RESUME
/DELETE
taskid
32
Examples:
KAVSHELL TASK
KAVSHELL TASK update-app /START /WA:update_
application.log
KAVSHELL TASK _LOCAL_0630cddf-0793-4c2d-be1e-a3daed0904c6
/START /WA:task.log
KAVSHELL TASK _LOCAL_0630cddf-0793-4c2d-be1e-a3daed0904c6
/DELETE
/O:output_report_file
Examples:
KAVSHELL CONVERT /I:scan.log /O:scan.txt
33
Local management
settings_file
Examples:
KAVSHELL IMPORT c:\kav50settings.xml
KAVSHELL EXPORT c:\kav50settings.xml
34
Local management
35
In the console tree select the Local computer item. Open its right-click
menu and select the Properties command, or press the Properties
button.
2.
The Task properties dialog box (see Fig. 3) contains the following tabs:
General, Settings, Account, Schedule, and Notification. The caption of the
dialog box contains the task name.
36
All tabs (except for the Settings and Account tabs) are standard tabs for
Kaspersky Administration Kit 5.0. More information about these tabs is available
in the administrators guide for that product. The Account tab can be used to set
up task launch from a selected account (see section 6.2.1.3 on p. 52). The
Settings tab displays specific settings for Kaspersky Anti-Virus depending on the
type of the selected task: the next section contains a detailed description of this
tab.
37
Local management
The Scan Scope field displays a list of objects to be scanned while the current
task is running. Objects for scanning (for instance, a drive, directory or file) can
be added in the window which opens after clicking the Add button. The list of
objects can be edited using the Edit button, and objects can be removed from
the scan list by clicking the Delete button.
In the Protection Level drop-down list you can select one of the three preset
levels of anti-virus protection (see section 4.1 on p. 20).
Clicking the Advanced button opens a window where you can review the
settings corresponding to the selected level or use them as the basis for your
own setup. The protection level value in that case will be changed to
Customized.
The window for advanced task configuration contains the Scan Scope, Actions
and Additional tabs.
The Scan Scope tab (see Fig. 5) can be used to specify the objects to be
included in and excluded from scanning.
38
In the Scan Scope area you can select and deselect the resources which will be
scanned while running the task by checking the appropriate boxes.
In the Objects to scan area, select the types of objects to be scanned:
In the Exclusion mask field, you can define objects to be excluded from ondemand scans. To add new masks, enable the Exclusion mask checkbox, click
the button to the right and edit the list of excluded masks using the Add, Edit
and Delete buttons in the new dialog box.
39
Local management
dir\ all files in all dir\ directories and all their subdirectories.
Disinfect; delete if disinfection fails means that the application will attempt
disinfection; if the object cannot be restored, it will be deleted.
40
Within the Additional tab (see Fig. 7) you can enable/disable scanning for
various types of compound files, exclude the trusted riskware from scanning and
also enable some restrictions for the scanning process.
Do not detect trusted riskware (see section 6.2.2.3 on p. 60
Check the box
for details) to skip scanning of riskware installed on your computer.
You can restrict the duration of scanning. In order to do so enter the maximum
value (in seconds) in the Maximum scan time, sec. box. Scanning will be
terminated if its duration exceeds the defined limit. Enter the desired limits for
41
Local management
42
Clicking the Advanced button opens a window where you can review the
settings corresponding to the selected level, or use them as the basis for your
own setup. The protection level value in that case will be changed to
Customized.
The window for advanced setup contains the Scan Scope, Actions and
Additional tabs.
Use the Scan Scope tab (see Fig. 9) to define the objects to be scanned, and
those to be excluded from real-time scanning. The range of settings is similar to
that within the Scan Scope tab for on-demand scans (see details in section
6.2.1.2.1 on p. 36).
The Anti-Virus will scan boot sectors only if the Sectors / Hard Drives or
Sectors / Removable Media checkboxes are enabled.
43
Local management
Use the Actions tab (see Fig. 10) to determine the action taken when the
application detects infected or suspicious objects:
Block access and disinfect; delete if disinfection fails means that the
application will attempt disinfection using the records from its anti-virus
database; if the object cannot be disinfected, it will be deleted.
44
Use the Additional tab (see Fig. 11) to enable/disable scanning for various types
of compound files, to exclude the trusted riskware from scanning, to restrict
scanning duration and to enable/disable iChecker and iStreams technologies.
Do not detect trusted riskware (see section 6.2.2.3 on p. 60
Check the box
for details) to skip scanning of riskware installed on your computer.
You can restrict the duration of scanning. In order to do so, enter the maximum
value (in seconds) in the Maximum scan time, sec. box. Scanning will be
terminated if its duration exceeds the defined limit.
Use iChecker, Use iStreams checkboxes enable your scanner to use
these technologies for scanning acceleration.
45
Local management
46
Local management
47
Figure 13. Setting up a task for update of the anti-virus database and application modules
Update anti-virus database check this box to receive updates for the
anti-virus database.
Copy updates automatically check this box to enable automatic
downloading and installation of updates to application modules:
All available updates all available updates for the
application components will be installed automatically.
Urgent updates only urgent (critical) updates for the
application components will be installed automatically.
Disable installation of updates that require reboot. If the checkbox is
disabled, the server will be automatically restarted after downloading and
installation of updates, which require a mandatory restart
If the box is checked and computer restart is forbidden, application of updates
will depend upon the Allow partial updating checkbox:
48
Use the Updates' source section to specify the source of updates and its
settings:
49
Local management
Use passive FTP mode if possible check this box if your server is
protected with a firewall and you cannot connect to an FTP-site in active
mode.
Use the Connection timeout, sec. field to enter the desired timeout for
connecting to an updates' server of Kaspersky Lab.
If you are accessing the source of updates through a proxy server, enable
proxy use and select the connection settings:
Use proxy for Kaspersky Lab servers to receive updates from the
updates servers of Kaspersky Lab through the proxy.
Use a proxy for customs servers to retrieve updates from a local
server / folder through the proxy:
Use IE Proxy Settings when connecting through a proxy-server,
use the MS Internet Explorer proxy settings.
Use custom settings to customize proxy settings, type the IP
address of the proxy server and the port number into the Address
and Port fields, respectively.
In the Authorization settings section select the type of authorization to be used
it can be either NTLM or Basic. If you select Basic authorization fill in the User
name and Password fields.
50
Use the window (see Fig. 15) displayed after clicking the Sharing settings
button to configure the updates' sharing service. The service allows downloaded
updates to the anti-virus database and application modules to be stored in a local
directory for future sharing with other LAN computers, saving thus web traffic.
Check the
Copy to updates' shared folder box in order to enable the
updates sharing service. Specify below the types of updates to be added to the
local folder for further sharing:
Anti-virus database updates means that received updates for the antivirus database will be saved in the shared folder containing updates.
Application modules updates means that received updates for
application components will be saved in the shared folder containing
updates:
All available updates means that all application modules
updates will be shared.
Urgent updates means that only urgent (critical) updates for
application modules will be shared.
In addition, you can select the method to be used while downloading updates:
Specify the path to the shared folder in the Updates' shared folder field.
51
Local management
2.
On the client computer, specify the network path to the local source
directory in the update task settings.
52
53
Local management
Default account option means that the current account will be used.
Specified account option serves to enter the parameters of a different
account. If you select that variant, fill in the Run as user, Password
and Confirm password fields.
Select the Local computer object in console tree. Open its rightclick menu and select the Properties command.
2.
Switch to the Tasks tab (see Fig. 2), which lists the available tasks.
3.
Click Add to open the new task creation wizard, which will guide
you through the process. To navigate the wizard dialogs boxes
click Back and Next. To finish working with the wizard, click Finish.
To stop working with the wizard at any stage, click Cancel.
54
On-demand scan;
Local management
55
56
Select the desired task frequency from the Schedule for drop-down list. The
following variants are possible: Every N hours, Every N days, Every N weeks,
Manually, and At application launch. Depending on your choice, the elements of
this dialog box will vary.
Tasks for rolling back the anti-virus database and installing license keys
can be launched manually only.
Please see details on setup of scheduled task launch in the Administrators guide
for Kaspersky Administration Kit 5.0.
57
Local management
In the console tree, select the Local computer item and click the
Properties command in the right-click menu.
2.
3.
58
Local management
59
In the window (see Figure 24), which opens after clicking the Troubleshooting
options button, you can define the system load while on-demand scanning
tasks are running. That can be accomplished by enabling the checkbox
Limit
system usage (%) and then using the field to the right to specify the peak load
value (in percents). The recommended value established during testing is 30%.
Lower values result is longer scanning and migration of resources to user
applications.
60
In the window (see Figure 25) that opens upon clicking the Notifications
button you can enter the conditions for receipt of notifications about the status of
tasks for updating of the anti-virus database and full computer scanning. Two
levels of events exist for both of those task types, they are warning and error.
Specify in the field to the right of each event the interval in days, after which a
user should see the respective notification displayed every day at the launch of
Kaspersky Anti-Virus. The specified time period will be counted beginning with
the date, when the respective task was performed last time.
61
Local management
62
Use the Trusted riskware to create a list of exceptions, which will be skipped
during riskware scanning. Programs in the list are considered to be approved
and may be executed on a computer. You can fill the list or modify it using the
buttons to the right.
Pressing the Add/Edit button opens an additional window (see Fig. 26). Fill in
one of the window fields to add/edit a program name.
Use the File path mask field to specify the path to the directory containing
program files. In the Riskware verdict mask: field you can enter any of the
following:
versions
of
remote
63
Local management
64
You can select the process file name using the Browse button. Upon name
selection, Kaspersky Anti-Virus registers internal attributes of the process file and
then uses them to identify the process as a trusted one during anti-virus
scanning.
File path will be substituted automatically after name selection. You can modify it
manually or specify the path as a mask.
In case of remote management using the Administration Console, you
will have to specify the path to process file on a remote host.
65
Local management
Enter the location of the quarantine directory in the Storage path box.
Delete objects stored longer than, days a restriction for the objects
storage duration. Quarantined files are preserved for 90 days by default.
You can modify the period by entering the corresponding number in the
box to the right.
Maximum quarantine size, MB a restriction for the combined size of
preserved quarantined files. The Anti-Virus will delete the oldest
quarantined files when this limit is exceeded.
Rescan quarantine upon anti-virus database update. Check the box if
you wish to enable automatic rescanning of quarantined suspicious
objects after each update of the anti-virus database.
66
To do so, click the List of objects button in the Quarantine or Backup copy
storage section respectively.
The dialog boxes displaying the contents of both storage areas are similar (see
Fig. 31). In the central part of the dialog box, you can see a list of quarantined or
backup files. The following information is available for each object: name, status,
the date when an object has been added to storage directory and its original
path.
Above the list there is an object management toolbar. Use the buttons to:
Restore an object. Click this button to restore the selected object,
specifying the location in which it will be restored. Objects can be
restored only to a computer where Administration console is installed.
In case of remote management via Kaspersky Administration
Kit objects are restored only to the computer used for remote
control.
Delete the object from the storage folder.
Refresh the storage contents.
67
Local management
68
69
Local management
Kaspersky Anti-Virus generates events during its operation (see Table 2), each
with its own priority status. There are four priority statuses:
Critical event;
Error;
Warning;
Informational message.
Events of the same type can be assigned different priority statuses, depending
on the particular situation in which the event occurred.
Select the priority level from the Events severity drop-down list to define event
status. In the information field below the list, you can view the types of events for
the selected priority level.
70
Priority status
Warning
Warning
Informational
message
Warning
Critical event
Error
Warning
Malfunction
Warning
Error
Warning
Critical event
Critical event
Internal error
Error
Warning
Warning
Warning
Warning
Critical event
Local management
71
* Those are the default values. You can modify them in the Notifications window
(see section 6.2.2.2 on p. 59).
For each event you can specify whether it should be appended to a report, and
the method used to notify the administrator when the event occurs.
For more detailed description of the Event processing tab refer to the
Kaspersky Administration Kit 5.0 administrators manual.
CHAPTER 7. REMOTE
MANAGEMENT
Using centralized management of Kaspersky Anti-Virus via Kaspersky
Administration Kit you can control the policies, tasks and settings of Kaspersky
Anti-Virus application installed on remote computers in your LAN.
2.
Select the Policies folder within the selected group, open the right-click
menu, and click NewPolicy to launch the new policy wizard.
To switch between the wizard dialog boxes, use Back and Next. To finish
working with the wizard, click Finish. To cancel the program at any stage, click
Cancel.
During policy creation (Step 2. Step 6. ) you can prohibit modification
of settings in the policies of nested groups, in application and task
settings. To disable the modification of settings "lock" them up:
. The
settings allowed for modification will be marked with
.
Remote management
73
74
Remote management
75
76
2.
Select the Policies folder in this group. All policies available for this
group will be displayed on the results pane.
3.
4.
Open the right-click menu for the selected policy and click
Properties. You will see a dialog box with the policy properties for
Kaspersky Anti-Virus 5.0 for Windows File Servers application.
In this dialog box, the General, Enforcement, and Event processing tabs are
standard Kaspersky Administration Kit tabs (please refer to the Administrators
guide for Kaspersky Administration Kit for details).
The remaining tabs display specific settings for Kaspersky Anti-Virus and
correspond to the task setup tabs (see section 6.2.1.2 on p. 35) and application
setup tabs (see section 6.2.2 on p. 57).
Remote management
77
You can change task settings, control their execution, and copy, move and
delete tasks using the Copy/Paste, Cut/Paste, and Delete commands, either on
the right-click menu or in the Action menu.
The parameters used by a client computer to execute tasks comply with the
group policy, specific task settings, and the application settings on the client
computer.
All tasks are scheduled by default. Tasks can be temporarily excluded from the
list of scheduled tasks, in which case they remain in the task list but are not
launched.
You can manually launch, abort, suspend, or resume a task using the commands
Start/Stop/Pause/Resume in the right-click menu or in the Action menu.
In the Groups folder select a folder bearing the name of the group
containing the target client computer.
2.
In the results pane select the computer for which the local task is to
be created. Then select the Properties command, either on the
right-click menu or the Action menu. The <Computer name>
Properties window will open, where you can review client
computer properties.
3.
Select the Tasks tab (see Fig. 36), which contains a list of existing
tasks available for the selected client computer. You can create a
new task by clicking the Add button.
A wizard for creating a new task will appear. The wizard is organized similarly to
the task creation wizard used in case of local application management (see
section 6.2.1.3 on p. 52 for details). Follow the guidelines offered by the wizard.
78
In the console tree, select a group of computers the new task will be
applied to.
2.
Select the Tasks folder within this group, and select the NewTask
command on the right-click menu or the Action menu. The new group
task wizard for appear and guide you through the creation process. The
wizard is organized similarly to the local task wizard (see section 6.2.1.3
on p. 52 for details). Follow the instructions offered by the wizard.
After the task is created, it will be added to the Tasks folder for the selected
group and displayed within the results pane.
79
Remote management
In the console tree, select the Tasks node, and select the NewTask
command, either on the right-click menu or the Action menu.
2.
A global task creation wizard will appear to guide you through the
creation procedure. The wizard is organized similarly to the local task
wizard (see section 6.2.1.3 on p. 52 for details). The only difference is
that you should additionally define a list of client computers on the
logical network to which this global task applies.
3.
Select within the logical network the desired computers that the new
task will be assigned to. You can either select computers from different
folders or select the entire folder (for more details refer to the
Administrators guide for Kaspersky Administration Kit 5.0).
Global tasks are applied only to a specified set of computers. A
task assigned to a group will not be performed on new client
computers added to this group later. You will have to create a
new task or make appropriate changes to the existing task.
After the task is created, it will be added to the Tasks node of the console tree
and displayed within the results pane.
For a local task, in the Groups folder select the folder containing the
client computer. Then select the required computer in the results pane
and use the Properties command in the right-click menu. It will open the
<Computer name> Properties dialog box. In this dialog box, switch to
the Tasks tab (see Fig. 36), select the task, and click Properties to view
and edit the task settings.
The Tasks tab displays a full list of tasks assigned to this local
computer, including both global and group tasks. Global and
group tasks are indicated with the "folder" icon. Note that you
can view settings for all tasks but you will be able to edit only
those for local tasks.
80
For a group task, select the required group in the console tree and
choose the Tasks folder within this group. The results pane will display all
tasks assigned to this group. Select the desired task and click the
Properties command, either on the right-click menu or the Action menu.
To modify global task settings, select the Tasks node in the console tree.
Select the desired task and click the Properties command, either on the
right-click menu or the Action menu.
You will see the <Task name> Task properties dialog box consisting of the
following tabs: General, Settings, Account, Schedule, and Notification. The
global task configuration dialog box contains the additional Target computers
tab.
All tabs, except for the Settings and Account tabs, are standard tabs for
Kaspersky Administration Kit 5.0. Details about these tabs are available in the
Kaspersky Administration Kit administrators guide.
The Account tab can be used to set up task launch from a selected account
(see section 6.2.1.3 on p. 52). The Settings tab displays specific settings for
Kaspersky Anti-Virus for Windows File Servers depending on the type of the
selected task (see section 6.2.1.2 on p. 35 for details).
In the Groups folder select the folder bearing the name of the
group which contains the target client computer.
2.
In the results pane select the target computer for which application
settings are to be modified, and click the Properties command
from the right-click menu or on the Action menu.
3.
81
Remote management
4.
The test "virus" IS NOT ACTUALLY A VIRUS because it does not contain code
that can really harm your computer. However, most anti-virus products identify
this file as a virus.
Never use real viruses for testing the operation of an anti-virus product!
You can download the test "virus" from the official website of the EICAR
organization at http://www.eicar.org/anti_virus_test_file.htm. If you have no
Internet connection, you can create your own test "virus". To create a test "virus",
type the following string in any text editor and save the file as eicar.com:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TESTFILE!$H+H*
The file downloaded from the EICAR website or created as described above
contains the body of a standard test "virus". The anti-virus application will detect
it, assign the Infected type to it and apply the action defined by the administrator
for handling objects belonging to that type.
To test the response of your anti-virus application to other types of objects,
modify the body of this standard test "virus" by adding one of the prefixes listed
in Table 3.
83
Object type
No
prefix,
standard test
"virus"
CORR
Corrupted.
SUSP
WARN
ERRO
CURE
DELE
The first table column lists prefixes to be added at the beginning of the string of
the standard test "virus" (for example,
DELEX5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUSTEST-FILE!$H+H*).
After adding a prefix to the test "virus" save it, for example, to a file under the
name eicar_dele.com; assign names to all the modified "viruses" in the same
manner.
The second column of this table contains the types of objects identified by an
anti-virus application after you have added a prefix. The actions for each type of
objects are defined by anti-virus application settings customized by the
administrator.
84
Make a directory on disk and save to it the test "viruses", which you have
created.
Create an on-demand scanning task for that directory (see section 6.2.1.3
on p. 52).
Check the reports for correct event description and the presence of the
respective objects in quarantine or backup storage if the settings define
their relocation (see section 6.2.2.6 on p. 65).
CHAPTER 9. ANTI-VIRUS
PROTECTION AND SERVER
MAINTENANCE
During server maintenance, follow the recommendations of operating systems
vendors and disable anti-virus protection in the following situations:
Disk defragmentation.
Installation of new data media. When a new disk or any removable media
already containing some data is connected to a server you are advised to:
The anti-virus complex does not have to be stopped during operations which do
not require fast access to large data arrays (e.g. during replication on a server).
Kaspersky Anti-Virus for Windows File Servers works correctly with other
Windows applications.
It is not possible for the same computer to run Kaspersky Lab
applications together with the anti-virus products of other vendors. We
cannot guarantee the correct operation either of applications or of the
operating system as a whole in that case.
87
88
89
MS Windows 2000, Kaspersky Anti-Virus 5.0 for File Servers, antivirus database updates do not work.
2.
3.
4.
5.
Send the following data, packed into one archive, to the Technical
support service:
6.
License key.
SCSI controller;
90
Each year Kaspersky Lab increases the frequency of its issued updates
to the anti-virus database. Currently it is updated every hour.
Updating of the Anti-Virus application modules is an additional feature
that allows both correction of discovered vulnerabilities and addition of
new functions.
Question: What are the changes to the updating service of version 5.0?
The Kaspersky Lab 5.0 product suite features a new updating service
which has been developed in accordance with the requests of our
users. It automates the whole updating procedure, from the preparation
of updates in Kaspersky Lab to the moment that relevant files are
updated on clients' computers.
Advantages of the new updating service include:
Accelerated downloading from the Internet. Kaspersky AntiVirus picks up a Kaspersky Lab's updates server located in your
region. Furthermore, servers are allocated according to their
performance, so you will not be sent to an overloaded server
while there is another idle server available.
Use of key black lists. Unlicensed and illegal users are now
prevented from using the updating service. Licensed users
therefore do not suffer from inability to contact overloaded
updates servers.
91
92
Question: I use a proxy server and the updater does not work on my
computer. What should I do?
The following problems may cause inability to retrieve updates while
working through a proxy server:
Launch regedit
93
The example will be valid for Kaspersky Anti-Virus 5.0 for Windows File
Servers; for other applications select the branch bearing the name of
that application.
APPENDIX A. GLOSSARY
These documents use terms and concepts specific to the sphere of anti-virus
protection. This glossary serves as a dictionary containing definitions for those
concepts. For convenience the glossary is arranged in alphabetic order.
A
Administration agent a special application, which provides for interaction
between an administration server and applications from the corporate
products of Kaspersky Lab. The administration agent is included in the
Kaspersky Administration Kit 5.0.
Administration console a component, which provides a graphical
interface for controlling Kaspersky Anti-Virus for Windows File Servers.
It is included into Kaspersky Administration Kit 5.
Administration group a number of computers combined into a group for
convenient control. The group is managed as a whole entity, may have
a group policy, may include other groups and may receive
administration commands.
Administration server a special application functioning as a controller
and centralized data storage for Kaspersky Lab applications installed in
a corporate network. Administration server is included in the Kaspersky
Administration Kit 5.0 application package.
AdWare software code for advertisement demonstration added into a
program without informing the users about that. As a rule, adware is
built into free software. The advertisement appears within the program
interface. Such programs frequently collect and transmit to their
developers some personal information about users, change various
browser parameters (home and search pages security levels, etc.),
generating additional traffic, which users do not control. All of the above
may cause violations of the security policy or even direct financial
losses.
Alternate NTFS streams (NTFS streams) data streams on a drive with
NTFS file system, supplementing the main stream.
Anti-virus database database created by Kaspersky Lab, containing
detailed descriptions of all currently existing viruses and methods for
their detection and disinfection. Our anti-virus database is regularly
updated with information about new viruses; therefore, to keep your
computer constantly protected from viruses, you need to keep your antivirus database updated.
Anti-virus protection status the current status of anti-virus protection
that characterizes the security level for your computer.
Application management plug-in a specialized component which
provides an interface for control of application through an Administration
Appendix A
95
96
Appendix A
97
I
iChecker the technology which allows the application to skip the
rescanning of objects which are unchanged since their previous
scanning. The technology is implemented using a database of objects
checksums.
Infected object an object containing harmful code. You are advised to
abandon working on these objects because they can infect your
computer.
iStreams the technology which allows the application to skip the
rescanning of objects located on drives with NTFS file system and
unchanged since the last scanning. The technology is implemented on
the basis of checksum storage in alternate NTFS streams.
K
Kaspersky Administration Kit 5.0 an application included in Kaspersky
Business Optimal and Kaspersky Corporate Suite and designed for
centralized administration of an anti-virus protection system in a
corporate network built on the basis of Kaspersky Lab applications.
L
License key a file with the *.k extension that serves as your personal
"key". This file is required for correct operation of Kaspersky Anti-Virus.
The license key is included in the distribution kit if you purchased your
copy of Kaspersky Anti-Virus from Kaspersky Lab distributors. If you
purchased the product online, the license key is sent to you via e-mail.
Without the license key, Kaspersky Anti-Virus DOES NOT WORK.
License period a period during which you have the right to use full
functionality of Kaspersky Anti-Virus. As a rule, the license period
defined by the license key is one calendar year from the date of license
key activation. After your license expires, the product will operate but
you will not be able to update the anti-virus database and application
modules.
Logical network administrator a person who controls the operation of
the application via the remote centralized administration system of the
Kaspersky Administration Kit 5.0.
M
Maximum protection the level of computer security which corresponds to
maximum possible protection, at the expense of a certain performance
decrease.
O
Object blocking denying access to an object to external applications. A
blocked object cannot be accessed for reading, execution, modification
or removal.
98
Appendix A
99
Description
-1
-2
Service unavailable
-3
-4
-5
-6
-99
Internal error
101
Appendix B
Code
Description
101
102
103
104
105
106
107
108
Description
200
201
Not all the updates have been applied (e. g., updates that
require service restart have not been installed (section
6.2.1.2.4 on p. 46)
-2
102
Code
Description
08, 11, 12, 15, 27, 31 internal application error
09 error connecting to the list of available servers
17 file signature error
18 file operation error
20 an attempt to update with an older version
21 rollback impossible (no available backup copies of
files)
22 corrupted index file
28 failure downloading files
32 error during authorization on a proxy server
33 DNS error
34 error while connecting to an Administration Server of
Kaspersky Administration Kit
Description
-301
-302
104
Kaspersky Anti-Virus Personal does not re-scan objects that had been already
scan during a previous scan and have not changed since then not only when
performing real-time protection, but also during an on-demand scan. This
considerably increases the speed of the programs operation.
The application creates a reliable barrier to viruses when they attempt to intrude
your computer via e-mail. Kaspersky Anti-Virus Personal performs automatic
scan and disinfection of all incoming and outgoing mail sent or received using
POP3 and STMP protocol and provides highly efficient detection of viruses in
mail databases.
The application support over 700 formats of archived and compressed files and
provides automatic scan of their content as well as removal of malicious code
from ZIP, CAB, RAR and ARJ archives.
Configuring the application is made simple and intuitive due to the possibility to
select of the preset protection levels: Maximum Protection, Recommended and
High Speed.
The anti-virus database is updated every three hours and its delivery to your
computer is guaranteed even when your computer gets temporarily disconnected
from the internet or the connection has been changed.
105
Mail Filter automatically scans and disinfects all incoming and outgoing
mail for any mail client that uses POP3 and SMTP protocols and
effectively detects viruses in mail databases;
Kaspersky Anti-Hacker
106
protection for your computer from unauthorized access, and also from
network hacker attacks from your LAN or the Internet.
anti-virus scanner that scans information (saved both on the PDA and
smartphones) on user demand;
anti-virus monitor to intercept viruses in files that are either copied from
other handhelds or are transferred using HotSync technology.
Kaspersky Security for PDA protects your handheld (PDA) from unauthorized
intrusion by encrypting both access to the device and data stored on memory
cards.
Kaspersky Anti-Virus Business Optimal
This package provides a configurable security solution for small- and mediumsized corporate networks.
Workstations running
Workstation, and Linux;
Windows
98/ME,
Windows
NT/2000/XP
107
Lotus
You are free to choose from any of these anti-virus applications, according to the
operating systems and applications you use.
Kaspersky Corporate Suite
This package provides corporate networks of any size and complexity with
comprehensive, scalable anti-virus protection. The package components have
been developed to protect every tier of a corporate network, even in mixed
You are free to choose from any of these anti-virus applications, according to the
operating systems and applications you use.
108
Kaspersky Anti-Spam
Kaspersky Anti-Spam is a cutting-edge software suite that is designed to help
organizations with small- and medium-sized networks wage war against the
onslaught of undesired e-mail (spam). The product combines the revolutionary
technology of linguistic analysis with modern methods of e-mail filtration,
including RBL lists and formal letter features. Its unique combination of services
allows users to identify and wipe out up to 95% of unwanted traffic.
Installed at the entrance to a network, where it monitors incoming e-mail traffic
streams for spam, Kaspersky Anti-Spam acts as a barrier to unsolicited e-mail.
The product is compatible with any mail system and can be installed on either an
existing mail server or a dedicated one.
Kaspersky Anti-Spams high performance is ensured by daily updates to the
content filtration database by samples provided by the Companys linguistic
laboratory specialists.
Kaspersky SMTP Gateway
C.2. Contact Us
If you have any questions, comments, or suggestions, please refer them to one
of our distributors or directly to Kaspersky Lab. We will be glad to assist you in
any matters related to our product by phone or via email. All of your
recommendations and suggestions will be thoroughly reviewed and considered.
Technical
support
General
information
WWW: http://www.kaspersky.com
http://www.viruslist.com
Email: sales@kaspersky.com
APPENDIX D. LICENSE
AGREEMENT
End User License Agreement
NOTICE TO ALL USERS: CAREFULLY READ THE FOLLOWING LEGAL
AGREEMENT ("AGREEMENT") FOR THE LICENSE OF SPECIFIED
SOFTWARE ("SOFTWARE") PRODUCED BY KASPERSKY LAB
("KASPERSKY LAB").
IF YOU HAVE PURCHASED THIS SOFTWARE VIA THE INTERNET BY
CLICKING THE ACCEPT BUTTON, YOU (EITHER AN INDIVIDUAL OR
A SINGLE LEGAL ENTITY) CONSENT TO BE BOUND BY AND
BECOME PARTY TO THIS AGREEMENT. IF YOU DO NOT AGREE TO
ALL OF THE TERMS OF THIS AGREEMENT, CLICK THE BUTTON
THAT INDICATES THAT YOU DO NOT ACCEPT THE TERMS OF THIS
AGREEMENT, AND DO NOT INSTALL THE SOFTWARE.
IF YOU HAVE PURCHASED THIS SOFTWARE ON A PHYSICAL
MEDIUM, HAVING BROKEN THE CD'S SLEEVE YOU (EITHER AN
INDIVIDUAL OR A SINGLE ENTITY) ARE CONSENTING TO BE
BOUND BY THIS AGREEMENT. IF YOU DO NOT AGREE TO ALL OF
THE TERMS OF THIS AGREEMENT DO NOT BREAK THE CD's
SLEEVE, DOWNLOAD, INSTALL OR USE THIS SOFTWARE.
IN ACCORDANCE WITH THE LEGISLATION, REGARDING
KASPERSKY SOFTWARE INTENDED FOR INDIVIDUAL CONSUMERS
(KASPERSKY ANTI-VIRUS PERSONAL, KASPERSKY ANTI-VIRUS
PERSONAL PRO, KASPERSKY ANTI-HACKER, KASPERSKY ANTISPAM PERSONAL, KASPERSKY SECURITY SUITE PERSONAL,
KASPERSKY SECURITY FOR PDA) PURCHASED ON LINE FROM THE
KASPERSKY LAB INTERNET WEB SITE, CUSTOMER SHALL HAVE A
PERIOD OF 7 WORKING DAYS AS FROM THE DELIVERY OF
PRODUCT TO MAKE RETURN OF IT TO THE MERCHANT FOR
EXCHANGE OR REFUND, PROVIDED THE SOFTWARE IS NOT
UNSEALED.
REGARDING THE KASPERSKY SOFTWARE INTENDED FOR
INDIVIDUAL CONSUMERS (KASPERSKY ANTI-VIRUS PERSONAL,
KASPERSKY ANTI-VIRUS PERSONAL PRO, KASPERSKY ANTIHACKER, KASPERSKY ANTI-SPAM PERSONAL, KASPERSKY
SECURITY SUITE PERSONAL, KASPERSKY SECURITY FOR PDA)
NOT PURCHASED ONLINE VIA INTERNET, THIS SOFTWARE
NEITHER WILL BE RETURNED NOR EXCHANGED EXCEPT FOR
CONTRARY PROVISIONS FROM THE PARTNER WHO SELLS THE
110
Appendix D
111
112
Appendix D
113
114