Вы находитесь на странице: 1из 26

FOR MAC

User Guide
(intended for product version 6.0 and higher)

Click here to download the most recent version of this document


ESET, spol. s.r.o.
ESET Endpoint Antivirus was developed by ESET, spol. s r.o.
For more information visit www.eset.com.
All rights reserved. No part of this documentation may be reproduced,
stored in a retrieval system or transmitted in any form or by any means,
electronic, mechanical, photocopying, recording, scanning, or otherwise
without permission in writing from the author.
ESET, spol. s r.o. reserves the right to change any of the described
application software without prior notice.

Customer Care: www.eset.com/support

REV. 20. 2. 2015


Contents
9.1.2 Acti ve .............................................................................17
mode
1. ESET Endpoint
...............................................................4
Antivirus 9.1.3 URL l.............................................................................17
i s ts
1.1 What's
..................................................................................................4
new 9.2 Email
..................................................................................................17
protection
1.2 System
..................................................................................................4
requirements 9.2.1 POP3.............................................................................18
protocol checki ng
9.2.2 IMAP.............................................................................18
protocol checki ng
2. Users connecting via ESET Remote
...............................................................4 10. Update ...............................................................18
Administrator
2.1 ESET..................................................................................................5
Remote Administrator Server 10.1 Update
..................................................................................................18
setup
10.1.1 Adva.............................................................................19
nced Setup
2.2 Web ..................................................................................................5
Console
10.2 How..................................................................................................19
to create update tasks
2.3 Proxy..................................................................................................5
10.3 Upgrading
..................................................................................................19
to a new build
2.4 Agent..................................................................................................5
10.4 System
..................................................................................................19
updates
2.5 RD Sensor
..................................................................................................6

...............................................................6 11. Tools


3. Installation ...............................................................20
11.1 Log..................................................................................................20
files
3.1 Typical
..................................................................................................6
installation
11.1.1 Log ma .............................................................................20
i ntena nce
3.2 Custom
..................................................................................................6
installation 11.1.2 Log fi.............................................................................21
l teri ng
3.3 Remote
..................................................................................................7
installation
11.2 Scheduler
..................................................................................................21
3.3.1 Crea ti.............................................................................7
ng a remote i ns ta l l a ti on pa cka ge 11.2.1 Crea.............................................................................21
ti ng new ta s ks
3.3.2 Remote .............................................................................8
i ns ta l l a ti on on ta rget computers 11.2.2 Crea.............................................................................22
ti ng a us er-defi ned ta s k
3.3.3 Remote .............................................................................8
uni ns ta l l a ti on
11.3 Quarantine
..................................................................................................22
3.3.4 Remote .............................................................................8
upgra de
11.3.1 Qua ra .............................................................................22
nti ni ng fi l es
4. Product activation
...............................................................8 11.3.2 Res tori.............................................................................22
ng a qua ra nti ned fi l e
11.3.3 Submi .............................................................................22
tti ng a fi l e from Qua ra nti ne
5. Uninstallation
...............................................................9 11.4 Running
..................................................................................................23
processes
11.5 Live..................................................................................................23
Grid
6. Basic overview
...............................................................9 11.5.1 Sus pi.............................................................................23
ci ous fi l es
6.1 Keyboard
..................................................................................................9
shortcuts
6.2 Checking
..................................................................................................10
operation of the system
12. User interface
...............................................................24
6.3 What
..................................................................................................10
to do if the program does not work properly 12.1 Alerts
..................................................................................................24
and notifications
12.1.1 Al erts .............................................................................24
a nd noti fi ca ti ons a dva nced s etup
7. Computer
...............................................................10
protection 12.2 Privileges
..................................................................................................24
7.1 Antivirus
..................................................................................................10
and antispyware protection 12.3 Presentation
..................................................................................................25
mode
7.1.1 Genera .............................................................................10
l 12.4 Context
..................................................................................................25
menu
7.1.1.1 Excl us............................................................................11
i ons
7.1.2 Sta rtup.............................................................................11
protecti on 13. Miscellaneous
...............................................................25
7.1.3 Rea l.............................................................................11
-ti me fi l e s ys tem protecti on 13.1 Import
..................................................................................................25
and export settings
7.1.3.1 Sca n ............................................................................11
on (Event tri ggered s ca nni ng) 13.1.1 Import .............................................................................25
s etti ngs
7.1.3.2 Adva nced............................................................................11
s ca n opti ons 13.1.2 Export .............................................................................25
s etti ngs
7.1.3.3 When to modi fy Rea l -ti me protecti on 13.2 Proxy
..................................................................................................26
server setup
confi............................................................................12
gura ti on 13.3 Shared
..................................................................................................26
Local Cache
7.1.3.4 Checki ............................................................................12
ng Rea l -ti me protecti on
7.1.3.5 Wha t to do i f Rea l -ti me protecti on does not
work ............................................................................12
7.1.4 On-dema .............................................................................12
nd computer s ca n
7.1.4.1 Type ............................................................................13
of s ca n
7.1.4.1.1 Sma rt .............................................................................13
s ca n
7.1.4.1.2 Cus tom .............................................................................13
s ca n
7.1.4.2 Sca n ............................................................................13
ta rgets
7.1.4.3 Sca n ............................................................................13
profi l es
7.1.5 Threa .............................................................................14
tSens e engi ne pa ra meters s etup
7.1.5.1 Objects ............................................................................14
7.1.5.2 Opti ons ............................................................................14
7.1.5.3 Cl ea ni ............................................................................15
ng
7.1.5.4 Extens ............................................................................15
i ons
7.1.5.5 Li mi ts............................................................................15
7.1.5.6 Others ............................................................................15
7.1.6 An i nfi.............................................................................16
l tra ti on i s detected
7.2 Removable
..................................................................................................16
media blocking

8. Anti-Phishing
...............................................................16
9. Web and...............................................................16
email protection
9.1 Web..................................................................................................17
access protection
9.1.1 Ports.............................................................................17
1. ESET Endpoint Antivirus 1.2 System requirements

ESET Endpoint Antivirus 6 represents a new approach For optimal performance of ESET Endpoint Antivirus,
to truly integrated computer security. The most recent your system should meet the following hardware and
version of the ThreatSense® scanning engine utilizes software requirements:
speed and precision to keep your computer safe. The
result is an intelligent system that is constantly on System requirements:
alert for attacks and malicious software that might Processor Intel 32-bit, 64-bit
threaten your computer. architecture
ESET Endpoint Antivirus 6 is a complete security Operating system Mac OS X 10.6 and later
solution developed from our long-term effort to Mac OS X Server 10.7 and later
combine maximum protection and a minimal system Memory 300 MB
footprint. The advanced technologies, based on Free disk space 200 MB
artificial intelligence, are capable of proactively
eliminating infiltration by viruses, spyware, trojan
horses, worms, adware, rootkits, and other Internet- 2. Users connecting via ESET Remote
borne attacks without hindering system performance Administrator
or disrupting your computer.
ESET Remote Administrator (ERA) 6 is an application
ESET Endpoint Antivirus 6 is primarily designed for use that allows you to manage ESET products in a
on workstations in a small business/enterprise networked environment from one central location.
environment. It can be used with ESET Remote The ESET Remote Administrator task management
Administrator 6, allowing you to easily manage any system allows you to install ESET security solutions on
number of client workstations, apply policies and remote computers and quickly respond to new
rules, monitor detections and remotely administer problems and threats. ESET Remote Administrator
changes from any networked computer. does not provide protection against malicious code on
its own, it relies on the presence of an ESET security
1.1 What's new solution on each client.

The graphical user interface of ESET Endpoint Antivirus ESET security solutions support networks that include
has been completely redesigned to provide better multiple platform types. Your network can include a
visibility and a more intuitive user experience. Some combination of current Microsoft, Linux-based, OS X
of the many improvements included in version 6 and operating systems that run on mobile devices
include: (mobile phones and tablets).

Web access protection – monitors communication The picture below depicts a sample architecture for a
between web browsers and remote servers network protected by ESET security solutions managed
Email protection – provides control of email by ERA:
communication received via the POP3 and IMAP
protocols
Anti-Phishing protection – protects you from
attempts to acquire passwords and other sensitive
information by restricting access to malicious
websites that impersonate legitimate ones
Presentation mode – allows you to run ESET
Endpoint Antivirus in the background and suppresses
pop-up windows and scheduled tasks
Shared local cache allows for scanning speed
improvements in virtualized environments

NOTE: For more information see the ESET Remote


Administrator online documentation.

4
2.1 ESET Remote Administrator Server 2.3 Proxy

ESET Remote Administrator Server is the executive ERA Proxy is another component of ESET Remote
component of ESET Remote Administrator. It processes Administrator with two main purposes. In a medium-
all data received from clients that connect to the sized or enterprise network with many clients (for
Server (through the ERA Agent 5 ). The ERA Agent example, 10,000 clients or more), you can use ERA
facilitates communication between the client and the Proxy to distribute load between multiple ERA Proxies
server. Data (Client logs, configuration, agent facilitating the main ERA Server 5 . The other
replication, etc.) are stored in a database that ERA advantage of the ERA Proxy is that you can use it when
accesses to provide reporting. connecting to a remote branch office with a weak link.
This means that the ERA Agent on each client is not
To correctly process the data, the ERA Server requires a connecting to the main ERA Server directly via ERA
stable connection to a Database server. We Proxy, which is on the same local network as the
recommend that you install ERA Server and your branch office. This configuration frees up the link to
database on separate servers to optimize the branch office. The ERA Proxy accepts connections
performance. The machine on which ERA Server is from all local ERA Agents, compiles data from them
installed must be configured to accept all Agent/ and uploads it to the main ERA Server (or another ERA
Proxy/RD Sensor connections which are verified using Proxy). This allows your network to accommodate
certificates. Once ERA Server is installed, you can open more clients without compromising the performance
ERA Web Console 5 which allows you to manage of your network and database queries.
endpoint workstations with ESET solutions installed.
Depending on your network configuration, it is
2.2 Web Console possible for ERA Proxy to connect to another ERA Proxy
and then connect to the main ERA Server.
ERA Web Console is a web-based user interface that
presents data from ERA Server 5 and allows you to For proper function of the ERA Proxy, the host
manage ESET security solutions in your network. Web computer where you install ERA Proxy must have an
Console can be accessed using a browser. It displays an ESET Agent installed and must be connected to the
overview of the status of clients on your network and upper level (either ERA Server or an upper ERA Proxy,
can be used to deploy ESET solutions to unmanaged if there is one) of your network.
computers remotely. You can choose to make the web
server accessible from the internet to allow for the use 2.4 Agent
of ESET Remote Administrator from virtually any place
or device. ERA Agent is an essential part of the ESET Remote
Administrator product. ESET security solutions on
The Web Console Dashboard: client machines (for example ESET Endpoint Antivirus)
communicate with ERA Server through the Agent. This
communication allows for the management of ESET
security solutions on all remote clients from a one
central location. The Agent collects information from
the client and sends it to the Server. When the Server
sends a task to a client, the task is sent to the Agent
which then communicates with the client. All network
communication happens between the Agent and the
upper part of the ERA network – Server and Proxy.

The ESET Agent uses one of the following three


methods to connect to the Server:
The Quick Search tool is located at the top of the Web
Console. Select Computer Name, IPv4/IPv6 Address or 1. The Client's Agent connected directly to the Server.
Threat Name from the drop-down menu, type your 2. The Client's Agent connects via a Proxy that is
search string into the text field and then click the connected to the Server.
magnifier symbol or press Enter to search. You will be 3. The Client's Agent connects to the Server through
redirected to the Groups section, where your search multiple Proxies.
result will be displayed.
The ESET Agent communicates with ESET solutions

5
installed on a client, collects information from After agreeing to the End User License Agreement, you
programs on that client and passes configuration can choose from the following installation types:
information received from the Server to the client. Typical installation 6
Custom installation 6
NOTE: The ESET proxy has its own Agent which handles Remote installation 7
all communication tasks between clients, other
proxies and the Server. 3.1 Typical installation

2.5 RD Sensor Typical installation mode includes configuration


options that are appropriate for most users. These
RD (Rogue Detection) Sensor is a part of ESET Remote settings provide maximum security combined with
Administrator designed to find computers on your excellent system performance. Typical installation is
network. It provides a convenient way of adding new the default option, and is recommended if you do not
computers to ESET Remote Administrator without the have particular requirements for specific settings.
need to find and add them manually. Every computer
found on your network is displayed in the Web ESET Live Grid
Console and added to the default All group. From here, The ESET Live Grid Early Warning System helps ensure
you can take further actions with individual client that ESET is immediately and continuously informed of
computers. new infiltrations in order to quickly protect our
customers. The system allows new threats to be
RD Sensor is a passive listener that detects computers submitted to the ESET Threat Lab, where they are
that are present on the network and sends information analyzed, processed and added to the virus signature
about them to the ERA Server. The ERA Server database. Click Setup to modify detailed settings for
evaluates whether the PCs found on the network are the submission of suspicious files. For more
unknown or already managed. information see Live Grid 23 .

3. Installation Potentially Unwanted Applications


The last step of the installation process is to configure
There are two ways to launch the ESET Endpoint detection of Potentially unwanted applications. Such
Antivirus for Mac installer: programs are not necessarily malicious, but can often
negatively affect the behavior of your operating
If you are installing from the installation CD/DVD, system. These applications are often bundled with
insert the disk into the CD/DVD-ROM drive and other programs and may be difficult to notice during
double-click the ESET Endpoint Antivirus installation the installation process. Although these applications
icon to launch the installer. usually display a notification during installation, they
If you are installing from a downloaded file, double- can easily be installed without your consent.
click the file you downloaded to launch the installer.
After installing ESET Endpoint Antivirus, you should
perform a computer scan for malicious code. From the
main program window click Computer scan and then
click Smart scan. For more information about On-
demand computer scans, see the section On-demand
computer scan 12 .

3.2 Custom installation

Custom installation mode is designed for experienced


users who want to modify advanced settings during
the installation process.
The installation wizard will guide you through basic Program components
setup. During the initial phase of installation, the ESET Endpoint Antivirus allows you to install the
installer will automatically check online for the latest product without some of its core components (for
product version. If a newer version is found, you will example, Web and Email protection). Deselect the
be given the option to download the latest version check box next to a product component to remove it
before continuing the installation process. from installation.

6
Proxy Server
If you are using a proxy server, you can define its 3.3 Remote installation
parameters by selecting I use a proxy server. In the
next window, enter the IP address or URL of your proxy Remote installation allows you to create an installation
server in the Address field. In the Port field, specify package that can be installed on target computers
the port where the proxy server accepts connections using remote desktop software. When installation is
(3128, by default). If the proxy server requires complete, ESET Endpoint Antivirus can be managed
authentication, enter a valid Username and Password remotely via ESET Remote Administrator.
to grant access to the proxy server. If you do not use a
proxy server, select I do not use a proxy server. If you Remote installation is done in two phases:
are not sure whether you use a proxy server or not, 1. Creating a remote installation package using ESET
you can use your current system settings by selecting installer 7
Use system settings (Recommended). 2. Remote installation using remote desktop software
8

Privileges
Using the latest version of ESET Remote Administrator
In the next step you can define privileged users who
6, you can also perform a remote installation on OS X
will be able to edit the program configuration. From
client computers. For detailed instructions, follow the
the list of users on the left, select the users and Add
steps described in this Knowledgebase article. (The
them to the Privileged Users list. To display all system
article may not be available in your language.)
users, select Show all users. If you leave the Privileged
Users list empty, all users are considered privileged.
3.3.1 Creating a remote installation package
ESET Live Grid Program components
The ESET Live Grid Early Warning System helps ensure ESET Endpoint Antivirus allows you to install the
that ESET is immediately and continuously informed of product without some of its core components (for
new infiltrations in order to quickly protect our example, Web and Email protection). Deselect the
customers. The system allows new threats to be check box next to a product component to remove it
submitted to the ESET Threat Lab, where they are from installation.
analyzed, processed and added to the virus signature
database. Click Setup... to modify detailed settings for Proxy Server
the submission of suspicious files. For more If you are using a proxy server, you can define its
information see Live Grid 23 . parameters by selecting I use a proxy server. In the
next window, enter the IP address or URL of your proxy
Potentially Unwanted Applications server in the Address field. In the Port field, specify
The next step of the installation process is to configure the port where the proxy server accepts connections
detection of Potentially unwanted applications. Such (3128, by default). If the proxy server requires
programs are not necessarily malicious, but can often authentication, enter a valid Username and Password
negatively affect the behavior of your operating to grant access to the proxy server. If you do not use a
system. These applications are often bundled with proxy server, select I do not use a proxy server. If you
other programs and may be difficult to notice during are not sure whether you use a proxy server or not,
the installation process. Although these applications you can use your current system settings by selecting
usually display a notification during installation, they Use system settings (Recommended).
can easily be installed without your consent.
Privileges
After installing ESET Endpoint Antivirus, you should In the next step you can define privileged users who
perform a computer scan for malicious code. From the will be able to edit the program configuration. From
main program window click Computer scan and then the list of users on the left, select the users and Add
click Smart scan. For more information about On- them to the Privileged Users list. To display all system
demand computer scans, see On-demand computer users, select Show all users. If you leave the Privileged
scan 12 . Users list empty, all users are considered privileged.

7
ESET Live Grid
The ESET Live Grid Early Warning System helps ensure 3.3.3 Remote uninstallation
that ESET is immediately and continuously informed of To uninstall ESET Endpoint Antivirus from client
new infiltrations in order to quickly protect our computers:
customers. The system allows new threats to be
submitted to the ESET Threat Lab, where they are 1. Using the Copy Items command in Apple Remote
analyzed, processed and added to the virus signature Desktop, locate the uninstallation shell script (
database. Click Setup... to modify detailed settings for esets_rem ote_unInsta ll.sh – created along with the
the submission of suspicious files. For more installation package) and copy the shell script to the
information see Live Grid 23 . /tmp directory on target computers (for example, /
tm p/esets_rem ote_uninsta ll.sh).
Potentially Unwanted Applications 2. Select User under Run command as and then type
The next step of the installation process is to configure root into the User field.
detection of Potentially unwanted applications. Such 3. Click Send. After successful uninstallation, a console
programs are not necessarily malicious, but can often log will be shown.
negatively affect the behavior of your operating
system. These applications are often bundled with 3.3.4 Remote upgrade
other programs and may be difficult to notice during
Use the Install packages command in Apple Remote
the installation process. Although these applications
Desktop to install the latest version of ESET Endpoint
usually display a notification during installation, they
Antivirus when a new version becomes available.
can easily be installed without your consent.

Remote Installation Files 4. Product activation


In the last step of the installation wizard, select a
After installation is complete, you will be prompted to
destination folder for the installation package (
activate your product. There are multiple activation
esets_rem ote_Insta ll.pkg ), the setup shell script (
methods that can be used. The availability of a
esets_setup.sh) and the uninstallation shell script (
particular activation method may vary depending on
esets_rem ote_U nInsta ll.sh).
the country, as well as the means of distribution (CD/
DVD, ESET web page, etc.) for your product.
3.3.2 Remote installation on target computers
ESET Endpoint Antivirus can be installed on target To activate your copy of ESET Endpoint Antivirus
computers using Apple Remote Desktop or any other directly from the program, click the ESET Endpoint
tool that supports the installation of standard Mac
Antivirus icon located in the OS X menu bar (top of
packages ( .pkg), by copying the files and running shell
the screen) and click Product activation. You can also
scripts on target computers.
activate your product from the main menu under Help
> Manage license or Protection status > Activate
To install ESET Endpoint Antivirus using Apple Remote
product.
Desktop:

1. Click the Copy icon in Apple Remote Desktop.


2. Click +, navigate to the installation shell script
(esets_setup.sh) and select it.
3. Select /tmp from the Place items in drop-down
menu and click Copy.
4. Click Install to send the package to your target
computers.

For a detailed instructions on how to administer client


computers using ESET Remote Administrator please
refer to the ESET Remote Administrator online
documentation.

8
You can use any of the following methods to activate The following sections are accessible from the main
ESET Endpoint Antivirus: menu:

Activate with License Key – A unique string in the Protection status – provides information about the
format XXXX-XXXX-XXXX-XXXX-XXXX which is used protection status of your Computer, Web and Mail
for identification of the license owner and activation protection.
of the license. Computer scan – this section allows you to configure
Security Administrator – An account created on the and launch the On-demand computer scan 12 .
ESET License Administrator portal with credentials Update – displays information about virus signature
(email address + password). This method allows you database updates.
to manage multiple licenses from one location. Setup – select this section to adjust your computer’s
Offline license – An automatically generated file that security level.
will be transferred to the ESET product to provide Tools – provides access to Log files 20 , Scheduler 21 ,
license information. Your offline License file is Quarantine 22 , Running processes 23 and other
generated from the ESET License Administrator program features.
portal and is used in environments where the Help – displays access to help files, Internet
application cannot connect to the licensing Knowledgebase, support request form and
authority. additional program information.

Click Activate later with RA if your computer is a 6.1 Keyboard shortcuts


member of managed network and your administrator
plans to use ESET Remote Administrator to activate Keyboard shortcuts that can be used when working
your product. You can also use this option if you want with ESET Endpoint Antivirus:
to activate this client at a later time.
cm d+, – displays ESET Endpoint Antivirus
NOTE: ESET Remote Administrator is able to activate preferences,
client computers silently using licenses made available cm d+O – resizes the ESET Endpoint Antivirus main
by the administrator. GUI window to the default size and moves it to the
center of the screen,
5. Uninstallation cm d+Q – hides the ESET Endpoint Antivirus main GUI
window. You can open it by clicking the ESET
There are multiple ways to launch the ESET Endpoint Endpoint Antivirus icon in the OS X menu bar (top
Antivirus for Mac uninstaller: of the screen),
cm d+W – closes the ESET Endpoint Antivirus main
insert the ESET Endpoint Antivirus installation CD/ GUI window.
DVD into your computer, open it from your desktop
or Finder window and double-click Uninstall The following keyboard shortcuts work only if Use
open the ESET Endpoint Antivirus installation file ( . standard menu is enabled under Setup > Enter
dm g) and double-click Uninstall application preferences ... > Interface:
launch Finder, open the Applications folder on your
hard drive, CTRL+click the ESET Endpoint Antivirus cm d+a lt+L – opens the Log files section,
icon and select Show Package Contents. Open the cm d+a lt+S – opens the Scheduler section,
Resources folder and double-click the Uninstaller cm d+a lt+Q – opens the Quarantine section.
icon.

6. Basic overview
The main program window of ESET Endpoint Antivirus
is divided into two main sections. The primary window
on the right displays information that corresponds to
the option selected from the main menu on the left.

9
6.2 Checking operation of the system 7.1.1 General
In the General section (Setup > Enter application
To view your protection status click Protection status
preferences... > General), you can enable detection of
from the main menu. A status summary about the
the following types of applications:
operation of ESET Endpoint Antivirus modules will be
displayed in the primary window.
Potentially unwanted applications – These
applications are not necessarily intended to be
malicious, but may affect the performance of your
computer in a negative way. Such applications
usually require consent for installation. If they are
present on your computer, your system behaves
differently (compared to the way it behaved before
these applications were installed). The most
significant changes include unwanted pop-up
windows, activation and running of hidden
processes, increased usage of system resources,
changes in search results, and applications
communicating with remote servers.
Potentially unsafe applications – These applications
6.3 What to do if the program does not work properly are commercial, legitimate software that can be
abused by attackers if installed without user
When a module is functioning properly, a green check consent. This classification includes programs such as
mark icon is displayed. When a module is not remote access tools, for this reason this option is
functioning properly, a red exclamation point or an disabled by default.
orange notification icon is displayed. Additional Suspicious applications – These applications include
information about the module and a suggested programs compressed with packers or protectors.
solution for fixing the issue is displayed in the main These types of protectors are often exploited by
program window. To change the status of individual malware authors to evade detection. A Packer is a
modules, click the blue link below each notification runtime self-extracting executable that includes
message. several kinds of malware in a single package. The
most common packers are UPX, PE_Compact, PKLite
If you are unable to solve a problem using the and ASPack. The same malware may be detected
suggested solutions, you can search the ESET differently when compressed using a different
Knowledgebase for a solution or contact ESET packer. Packers also have the ability to make their
Customer Care. Customer Care will respond quickly to "signatures" mutate over time, making malware
your questions and help resolve any issues with ESET more difficult to detect and remove.
Endpoint Antivirus.
To set up File System or Web and Mail exclusions 11 ,
7. Computer protection click Setup.
Computer configuration can be found under Setup >
Computer. It displays the status of Real-time file
system protection and Removable media blocking. To
turn off individual modules, switch the desired
module to DISABLED. Note that this may decrease the
level of protection of your computer. To access
detailed settings for each module, click Setup.

7.1 Antivirus and antispyware protection

Antivirus protection guards against malicious system


attacks by modifying files that pose potential threats.
If a threat with malicious code is detected, the
Antivirus module can eliminate it by blocking it and
then cleaning it, deleting it or moving it to quarantine.

10
7.1.1.1 Exclusions To modify advanced settings for Real-time file system
In the Exclusions section you can exclude certain files/ protection, go to Setup > Enter application preferences
folders, applications or IP/IPv6 addresses from ... (or press cm d+,) > Real-Time Protection and click
scanning. Setup... next to Advanced Options (described in
Advanced scan options 11 ).
Files and folders listed in the File System tab will be
excluded from all scanners: Startup, Real-time and On- 7.1.3.1 Scan on (Event triggered scanning)
Demand (Computer scan). By default, all files are scanned upon file opening, file
creation or file execution. We recommend that you
Path – path to excluded files and folders keep these default settings, as they provide the
Threat – if there is a name of a threat next to an maximum level of Real-time protection for your
excluded file, it means that the file is only excluded computer.
for that threat, but not completely. If that file
becomes infected later with other malware, it will 7.1.3.2 Advanced scan options
be detected by the antivirus module.
In this window you can define object types to be
Add... – creates a new exclusion. Enter the path to an
scanned by the ThreatSense engine and enable/
object (you can also use the wild cards * and ?) or
disable Advanced heuristics as well as modify settings
select the folder or file from the tree structure.
for archives and file cache.
Edit... – enables you to edit selected entries
Delete – removes selected entries We do not recommend changing the default values in
Default – cancels all exclusions. the Default archives settings section unless needed to
resolve a specific issue, as higher archive nesting
In the Web and Mail tab, you can exclude certain values can impede system performance.
Applications or IP/IPv6 addresses from protocol
scanning. You can toggle ThreatSense Advanced heuristics
scanning for executed, created and modified files
7.1.2 Startup protection separately by selecting the Advanced heuristics check
Startup file check automatically scans files at system box in each of the respective ThreatSense parameters
startup. By default, this scan runs regularly as a sections.
scheduled task after a user logon or after a successful
virus database update. To modify ThreatSense engine To minimize system footprint when using Real-time
parameter settings applicable to the Startup scan, click protection, you can define the size of the optimization
Setup. You can learn more about ThreatSense engine cache. The optimization cache is used whenever
setup by reading this section 14 . Enable clean file cache is enabled. If this is disabled, all
files are scanned each time they are accessed. Files
7.1.3 Real-time file system protection will not be scanned repeatedly after being cached
(unless they have been modified), up to the defined
Real-time file system protection checks all types of
size of the cache. Files are scanned again immediately
media and triggers a scan based on various events.
after each virus signature database update.
Using ThreatSense technology (described in
ThreatSense engine parameter setup 14 ), Real-time
Click Enable clean file cache to enable/disable this
file system protection may vary for newly created files
function. To specify the size of the cache, enter the
and existing files. Newly created files can be more
desired value in the input field next to Cache size.
precisely controlled.
Additional scanning parameters can be set in the
By default, Real-time protection launches at system
ThreatSense Engine Setup window. You can define
startup and provides uninterrupted scanning. In special
what type of Objects should be scanned using which
cases (for example, if there is a conflict with another
Options and Cleaning level, and define Extensions and
Real-time scanner), Real-time protection can be
file-size Limits for Real-time file system protection.
terminated by clicking the ESET Endpoint Antivirus
You can enter the ThreatSense engine setup window
icon located in your menu bar (top of the screen)
by clicking Setup next to ThreatSense Engine in the
and selecting Disable Real-time File System Protection
Advanced setup window. For more detailed
. Real-time file system protection can also be disabled
information about ThreatSense engine parameters
from the main program window (click Setup >
see ThreatSense engine parameter setup 14 .
Computer and switch Real-time file system protection
to DISABLED).
11
If Real-time protection is inadvertently disabled by a
7.1.3.3 When to modify Real-time protection user, it will need to be reactivated. To reactivate Real-
configuration time protection, from the main menu click Setup >
Real-time protection is the most essential component Computer and switch Real-time file system protection
of maintaining a secure system. Use caution when to ENABLED. Alternatively, you can enable Real-time
modifying the Real-time protection parameters. We file system protection in the application preferences
recommend that you only modify these parameters in window under Real-Time Protection by selecting
specific cases. For example, a situation in which there Enable real-time file system protection.
is a conflict with a certain application or Real-time
scanner of another antivirus program. Real-time protection does not detect and clean
infiltrations
After installing ESET Endpoint Antivirus, all settings are Make sure that no other antivirus programs are
optimized to provide the maximum level of system installed on your computer. If two real-time protection
security for users. To restore the default settings, click shields are enabled at the same time, they may
the Default button located at the bottom-left of the conflict with each other. We recommend that you
Real-Time Protection window (Setup > Enter uninstall any other antivirus programs that may be on
application preferences ... > Real-Time Protection). your system.

7.1.3.4 Checking Real-time protection Real-time protection does not start


If Real-time protection is not initiated at system
To verify that Real-time protection is working and
startup, it may be due to conflicts with other programs.
detecting viruses, use the eicar.com test file. This test
If you experience this issue, contact ESET Customer
file is a special, harmless file detectable by all antivirus
Care.
programs. The file was created by the EICAR institute
(European Institute for Computer Antivirus Research)
7.1.4 On-demand computer scan
to test the functionality of antivirus programs.
If you suspect that your computer is infected (it
To check the status of Real-time protection without behaves abnormally), run a Smart scan to examine
using ESET Remote Administrator, connect to the client your computer for infiltrations. For maximum
computer remotely using Terminal and issue the protection, computer scans should be run regularly as
following command: part of routine security measures, not just when an
/Applications/.esets/Contents/MacOS/esets_daemon infection is suspected. Regular scanning can detect
--status infiltrations that were not detected by the Real-time
scanner when they were saved to the disk. This can
The status of the Real-time scanner will be displayed happen if the Real-time scanner was disabled at the
as either RTPStatus=Enabled or RTPStatus=Disabled. time of infection, or if the virus signature database is
not up-to-date.
The output of the Terminal bash includes the following
statuses:

the version of ESET Endpoint Antivirus installed on


the client computer
date and version of the virus signature database
path to the update server

NOTE: Use of the Terminal utility is recommended for


advanced users only.

7.1.3.5 What to do if Real-time protection does not


work
In this chapter we describe problem situations that
may arise when using Real-time protection, and how
to troubleshoot them.

Real-time protection is disabled

12
We recommend that you run an On-demand computer
scan at least once a month. Scanning can be configured 7.1.4.2 Scan targets
as a scheduled task from Tools > Scheduler. The Scan targets tree structure allows you to select
files and folders to be scanned for viruses. Folders may
You can also drag and drop selected files and folders also be selected according to a profile's settings.
from your Desktop or Finder window to the ESET
Endpoint Antivirus main screen, dock icon, menu bar A scan target can be more precisely defined by
icon (top of the screen) or the application icon entering the path to the folder or file(s) you want to
(located in the /A pplica tions folder). include in scanning. Select targets from the tree
structure that lists all available folders on the
7.1.4.1 Type of scan computer by selecting the check box that corresponds
Two types of On-demand computer scans are to a given file or folder.
available. Smart scan quickly scans the system with no
need for further configuration of the scan parameters. 7.1.4.3 Scan profiles
Custom scan allows you to select any of the predefined Your preferred scan settings can be saved for future
scan profiles, as well as choose specific scan targets. scanning. We recommend that you create a different
profile (with various scan targets, scan methods and
7.1.4.1.1 Smart scan other parameters) for each regularly used scan.
Smart scan allows you to quickly launch a computer
scan and clean infected files with no need for user To create a new profile, from the main menu click
intervention. Its main advantage is easy operation with Setup > Enter application preferences ... (or press
no detailed scanning configuration. Smart scan checks cm d+,) > Computer Scan and click Edit next to the list of
all files in all folders and automatically cleans or current profiles.
deletes detected infiltrations. The cleaning level is
automatically set to the default value. For more
detailed information on types of cleaning, see
Cleaning 15 .

7.1.4.1.2 Custom scan


Custom scan allows you to specify scanning parameters
such as scan targets and scanning methods. The
advantage of running a Custom scan is the ability to
configure scan parameters in detail. Different
configurations can be saved as user-defined scan
profiles, which can be useful if scanning is repeatedly
performed using the same parameters. To help you create a scan profile to fit your needs, see
the ThreatSense engine parameters setup 14 section
To select scan targets, select Computer scan > Custom for a description of each parameter of the scan setup.
scan and then select specific Scan Targets from the tree
structure. A scan target can also be more precisely Example: Suppose that you want to create your own
specified by entering the path to the folder or file(s) scan profile and the Smart scan configuration is
you want to include. If you are only interested in partially suitable, but you do not want to scan runtime
scanning the system without additional cleaning packers or potentially unsafe applications and you also
actions, select Scan without cleaning. Furthermore, want to apply Strict cleaning. In the On-demand
you can choose from three cleaning levels by clicking Scanner Profiles List window, type the profile name,
Setup... > Cleaning. click Add and then confirm by clicking OK. Adjust the
parameters to meet your requirements using the
NOTE: Performing computer scans with Custom scan is ThreatSense Engine and Scan Targets settings.
only recommended for advanced users with previous
experience using antivirus programs. If you want to turn off the operating system and shut
down the computer after the On-demand scan is
finished, use the Shutdown computer after scan
option.

13
7.1.5 ThreatSense engine parameters setup 7.1.5.1 Objects
ThreatSense is a proprietary ESET technology The Objects section allows you to define which files
comprised of several complex threat detection will be scanned for infiltrations.
methods. This technology is proactive, which means it
also provides protection during the early hours of the Files – scans all common file types (programs,
spread of a new threat. It uses a combination of pictures, audio, video files, database files, etc.).
several methods (code analysis, code emulation, Symbolic links – (Computer scan only) scans files that
generic signatures, virus signatures) that work in contain a text string that is interpreted as a path to a
concert to significantly enhance system security. The file or directory.
scanning engine is capable of controlling several data Email files – (not available in Real-time Protection)
streams simultaneously, maximizing efficiency and scans email files.
detection rate. ThreatSense technology also Mailboxes – (not available in Real-time Protection)
successfully prevents rootkits. scans user mailboxes in the system. Incorrect use of
this option may result in a conflict with your email
The ThreatSense technology setup options allow you client. To learn more about advantages and
to specify several scan parameters: disadvantages of this option, read the following
knowledgebase article.
File types and extensions that are to be scanned Archives – (not available in Real-time Protection)
The combination of various detection methods scans files compressed in archives (.rar, .zip, .arj, .tar,
Levels of cleaning, etc. etc.).
Self-extracting archives – (not available in Real-time
To configure ThreatSense engine parameters for the Protection) scans files which are contained in self-
different product modules, click Setup > Enter extracting archive files.
application preferences and then click Startup Runtime packers – unlike standard archive types,
Protection, Real-Time Protection or Computer Scan runtime packers decompress in memory. When this
depending on which module you want to edit settings is selected, standard static packers (e.g. UPX, yoda,
for. Click Setup next to ThreatSense Engine to make ASPack, FGS) are also scanned.
configuration changes specific to that product module.
ThreatSense configuration settings are divided into 7.1.5.2 Options
five tabs where you can configure object types to scan,
scanning methods, cleaning settings, file extensions to In the Options section, you can select the methods
exclude, file size limits when scanning, and use of used during a scan of the system. The following
Smart optimization. Settings contained in each tab are options are available:
described in the following sections. Click OK when you
are finished making changes to apply settings for the Heuristics – Heuristics use an algorithm that analyzes
selected product module. the (malicious) activity of programs. The main
advantage of heuristic detection is the ability to
Startup Protection – Automatic startup file check detect new malicious software which did not
previously exist, or was not included in the list of
Real-Time Protection – Real-time file system
known viruses (virus signatures database).
protection
Advanced heuristics – Advanced heuristics is
Computer Scan – On-demand computer scan.
comprised of a unique heuristic algorithm,
developed by ESET, optimized for detecting
The ThreatSense parameters are specifically optimized
computer worms and trojan horses written in high-
for each module, and their modification can
level programming languages. The program's
significantly influence system operation. For example,
detection ability is significantly higher as a result of
changing settings to always scan runtime packers, or
advanced heuristics.
enabling advanced heuristics in the Real-time file
system protection module could result in a slower ESET Live Grid – The Live Grid Early Warning System
system. Therefore, we recommend that you leave the helps ensure that ESET is immediately and
default ThreatSense parameters unchanged for all continuously informed of new infiltrations in order
modules except Computer scan. to quickly protect our customers. To read more, see
the Live Grid 23 section.

14
7.1.5.3 Cleaning 7.1.5.5 Limits
Cleaning settings determine the manner in which the The Limits section allows you to specify the maximum
scanner cleans infected files. There are 3 levels of size of objects and levels of nested archives to be
cleaning: scanned:

No cleaning – Infected files are not cleaned Maximum Size: Defines the maximum size of objects
automatically. The program will display a warning to be scanned. The antivirus module will only scan
window and allow you to choose an action. objects smaller than the size specified. We do not
Standard cleaning – The program will attempt to recommend changing the default value, as there is
automatically clean or delete an infected file. If it is usually no reason to modify it. This option should
not possible to select the correct action only be changed by advanced users who have
automatically, the program will offer a choice of specific reasons for excluding larger objects from
follow-up actions. The choice of follow-up actions scanning.
will also be displayed if a predefined action cannot Maximum Scan Time: Defines the maximum time
be completed. allotted to scan an object. If a user-defined value has
Strict cleaning – The program will clean or delete all been entered here, the antivirus module will stop
infected files (including archives). The only scanning an object when that time has elapsed,
exceptions are system files. If it is not possible to whether or not the scan has finished.
clean a file, you will receive a notification and be Maximum Nesting Level: Specifies the maximum
asked to select the type of action to take. depth of archive scanning. We do not recommend
changing the default value of 10; under normal
W a rning : In the default Standard cleaning mode, circumstances, there should be no reason to modify
entire archive files are deleted only if all files in the it. If scanning is prematurely terminated due to the
archive are infected. If an archive contains legitimate number of nested archives, the archive will remain
files as well as infected files, it will not be deleted. If unchecked.
an infected archive file is detected in Strict cleaning Maximum File Size: This option allows you to specify
mode, the entire archive will be deleted even if clean the maximum file size for files contained in archives
files are present. (when they are extracted) that are to be scanned. If
scanning is prematurely terminated as a result of this
7.1.5.4 Extensions limit, the archive will remain unchecked.
An extension is the part of a file name delimited by a
period. The extension defines the type and content of 7.1.5.6 Others
a file. This section of the ThreatSense parameter setup Enable Smart optimization
lets you define the types of files to be excluded from With Smart Optimization enabled, settings are
scanning. optimized to ensure the most efficient level of
scanning without compromising scanning speed. The
By default, all files are scanned regardless of their various protection modules scan intelligently, making
extension. Any extension can be added to the list of use of different scanning methods. Smart Optimization
files excluded from scanning. Using the Add and is not rigidly defined within the product. The ESET
Remove buttons, you can enable or prohibit the Development Team is continuously implementing new
scanning of specific extensions. changes which are then integrated into ESET Endpoint
Antivirus through regular updates. If Smart
Excluding files from scanning is sometimes necessary if Optimization is disabled, only the user-defined
scanning certain file types prevents the program from settings in the ThreatSense core of the particular
functioning properly. For example, it may be advisable module are applied when performing a scan.
to exclude log, cfg and tm p files. The correct format for
entering file extensions is: * .log, * .cfg , *.tm p. Scan alternative data stream (On-demand scanner
only)
Alternate data streams (resource/data forks) used by
the file system are file and folder associations which
are invisible to ordinary scanning techniques. Many
infiltrations try to avoid detection by disguising
themselves as alternative data streams.

15
7.1.6 An infiltration is detected 7.2 Removable media blocking
Infiltrations can reach the system from various entry
ESET Endpoint Antivirus can run an on-demand scan of
points: webpages, shared folders, email or removable
inserted removable media devices (CD, DVD, USB, iOS
computer devices (USB, external disks, CDs, DVDs,
devices etc.).
etc.).

If your computer is showing signs of malware


infection, for example it runs slower, often freezes,
etc., we recommend that you take the following steps:

1. Click Computer scan.


2. Click Smart scan (for more information, see the
Smart scan 13 section).
3. After the scan has finished, review the log for the
number of scanned, infected and cleaned files.

If you only want to scan a certain part of your disk click Removable media may contain malicious code and put
Custom scan and select targets to scan for malware. your computer at risk. To block removable media, click
Media blocking setup (see the picture above) or from
As a general example of how infiltrations are handled the main menu click Setup > Enter application
by ESET Endpoint Antivirus, suppose that an infiltration preferences ... > Media from the main program
is detected by the Real-time file system monitor using window and select Enable removable media blocking.
the default cleaning level. Real-time protection will To allow access to certain types of media, deselect
attempt to clean or delete the file. If there is no your desired media volumes.
predefined action available for the Real-time
protection module, you will be asked to select an NOTE: To allow access to an external CD-ROM drive
option in an alert window. Usually, the options Clean, connected to your computer via USB cable, deselect
Delete and No action are available. Selecting No action the CD-ROM option.
is not recommended, since the infected file(s) is left in
its infected state. This option is intended for situations 8. Anti-Phishing
when you are sure that the file is harmless and has
been detected by mistake. The term phishing defines a criminal activity that uses
social engineering (the manipulation of users in order
Cleaning and deleting – Apply cleaning if a file has to obtain confidential information). Phishing is often
been attacked by a virus that has attached malicious used to gain access to sensitive data such as bank
code to it. If this is the case, first attempt to clean the account numbers, credit card numbers, PIN numbers or
infected file in order to restore it to its original state. If usernames and passwords.
the file consists exclusively of malicious code, it will
be deleted. We recommend that you keep Anti-Phishing enabled (
Setup > Enter application preferences ... > Anti-
Deleting files in archives – In the default cleaning Phishing Protection). All potential phishing attacks
mode, the entire archive will be deleted only if it coming from websites or domains listed in the ESET
contains infected files and no clean files. In other malware database will be blocked and a warning
words, archives are not deleted if they also contain notification will be displayed informing you of the
harmless clean files. Use caution when performing a attack.
Strict cleaning scan – with Strict cleaning the archive
will be deleted if it contains at least one infected file, 9. Web and email protection
regardless of the status of other files in the archive.
To access Web and Mail protection from the main
menu, click Setup > Web and Mail. From here you can
also access detailed settings for each module by
clicking Setup.

16
Web access protection – monitors HTTP/HTTPS
communication between web browsers and remote To only allow access to URLs listed in the Allowed URL
servers. list, select Restrict URL addresses.

Email client protection – provides control of email To activate a list, select Enabled next to the list name.
communication received through POP3 and IMAP If you want to be notified when entering an address
protocols. from the current list, select Notified.

Anti-Phishing protection – blocks potential phishing The special symbols * (asterisk) and ? (question mark)
attacks coming from websites or domains listed in the can be used when building URL lists. The asterisk
ESET malware database. substitutes any character string and the question mark
substitutes any symbol. Particular care should be taken
9.1 Web access protection when specifying excluded addresses, because the list
should only contain trusted and safe addresses.
Web access protection monitors communication Similarly, it is necessary to ensure that the symbols *
between web browsers and remote servers for and ? are used correctly in this list.
compliance with HTTP (Hypertext Transfer Protocol) or
HTTPS rules. 9.2 Email protection

9.1.1 Ports Email protection provides control of email


In the Ports tab you can define the port numbers used communication received through the POP3 and IMAP
for HTTP communication. By default the port numbers protocols. When examining incoming messages, the
80, 8080 and 3128 are predefined. program uses all the advanced scanning methods
included in the ThreatSense scanning engine. This
9.1.2 Active mode means that detection of malicious programs takes
place even before being matched against the virus
ESET Endpoint Antivirus also contains the Active Mode signature database. Scanning of the POP3 and IMAP
submenu, which defines the checking mode for web protocol communications is independent of the email
browsers. Active mode examines data transferred client used.
from applications accessing the Internet, regardless of
whether they are web browsers. If it is not enabled, ThreatSense Engine – advanced virus scanner setup
communications from applications are monitored enables you to configure scan targets, detection
gradually in batches. This decreases the effectiveness methods, etc. Click Setup to display the detailed
of the data verification process, but increases scanner setup window.
compatibility for listed applications. If no problems
occur while using it, we recommend that you enable After an email has been scanned, a notification
active checking by selecting the check box next to the containing scan results can be appended to the
desired application. message. You can select Append tag messages to email
subject. Tag messages cannot be relied on without
When a controlled application downloads data, the question, since they may be omitted in problematic
data is saved to a temporary file created by ESET HTML messages and can be forged by some viruses.
Endpoint Antivirus. Data is not available for the given The following options are available:
application at that time. Once downloading is
complete, it is checked for malicious code. If no Never – no tag messages will be added at all,
infiltration is found, data is sent to the original To infected email only – only messages containing
application. This process provides complete control of malicious software will be marked as checked,
the communications made by a controlled application. To all scanned email – the program will append
If passive mode is activated, data is trickle-fed to the messages to all scanned email.
original application to avoid timeouts.
Template added to the subject of infected email – edit
9.1.3 URL lists this template to modify the subject prefix format of an
The URL Lists section enables you to specify HTTP infected email.
addresses to block, allow or exclude from checking.
Websites in the list of blocked addresses will not be
accessible. Websites in the list of excluded addresses
are accessed without being scanned for malicious
code.
17
Append tag message to the email footnote – select this
check box if you want email protection to include a 10. Update
virus warning in the infected email. This feature allows
for simple filtering of infected emails. It also increases Regularly updating ESET Endpoint Antivirus is
the level of credibility for the recipient and, if an necessary to maintain the maximum level of security.
infiltration is detected, it provides valuable The Update module ensures that the program is always
information about the threat level of a given email or up to date by downloading the most recent virus
sender. signature database.

9.2.1 POP3 protocol checking Click Update from the main menu to view your current
update status including the date and time of the last
The POP3 protocol is the most widespread protocol successful update and check to see if an update is
used to receive email communication in an email needed. To begin the update process manually, click
client application. ESET Endpoint Antivirus provides Update virus signature database.
protection for this protocol regardless of the email
client used. Under normal circumstances, when updates are
downloaded properly, the message U pda te is not
The protection module providing this control is necessa ry – the insta lled virus sig na ture da ta ba se is
automatically initiated at system startup and is then current will appear in the Update window if you have
active in memory. Make sure the module is enabled the latest virus signature database. If the virus
for protocol filtering to work correctly, POP3 protocol signature database cannot be updated, we recommend
checking is performed automatically with no need to that you check your update settings 18 – the most
reconfigure your email client. By default, all common reason for this error is incorrectly entered
communication on port 110 is scanned, but other license data 8 or incorrectly configured connection
communication ports can be added if necessary. Port settings 26 .
numbers must be delimited by a comma.
The Update window also contains information about
If Enable POP3 protocol checking is selected, all POP3 the virus signature database version. This numeric
traffic is monitored for malicious software. indicator is an active link to the ESET website where all
virus signatures added in a given update are displayed.
9.2.2 IMAP protocol checking
The Internet Message Access Protocol (IMAP) is 10.1 Update setup
another Internet protocol for e-mail retrieval. IMAP
has some advantages over POP3, for example multiple The update setup section specifies update source
clients can simultaneously connect to the same information such as update servers and authentication
mailbox and maintain message state information such data for these servers. By default, the Update Server
as whether or not the message has been read, replied drop-down menu is set to Choose automatically to
to or deleted. ESET Endpoint Antivirus provides ensure that update files will automatically download
protection for this protocol, regardless of the email from the ESET server with the least network traffic.
client used.

The protection module providing this control is


automatically initiated at system startup and is then
active in memory. Make sure that IMAP protocol
checking is enabled for the module to work correctly;
IMAP protocol control is performed automatically with
no need to reconfigure your email client. By default,
all communication on port 143 is scanned, but other
communication ports can be added if necessary. Port
numbers must be delimited by a comma.

If Enable IMAP protocol checking is selected, all IMAP


traffic is monitored for malicious software.
The list of available update servers is accessible via
the Update Server drop-down menu. To add a new
update server, click Edit, enter the address of the new
server in the Update Server input field and click Add.

18
ESET Endpoint Antivirus allows you to set an 10.2 How to create update tasks
alternative or failover update server. Your Primary
server could be your mirror server and your Secondary Click Update > Update virus signature database to
server the standard ESET update server. The secondary manually trigger a virus signature database update.
server must differ from the primary one, otherwise it
will not be used. If you do not specify a Secondary Updates can also be run as scheduled tasks. To
Update Server, Username and Password, the failover configure a scheduled task, click Tools > Scheduler. By
update functionality will not work. You can also select default, the following tasks are activated in ESET
Choose automatically to and enter your Username and Endpoint Antivirus:
Password in the appropriate fields to have ESET
Endpoint Antivirus automatically select the best Regular automatic update
update server to use. Automatic update after user logon

If you are experiencing difficulty when attempting to Each of the update tasks can be modified to meet your
download virus signature database updates, click Clear needs. In addition to the default update tasks, you can
Update Cache to delete temporary update files. create new update tasks with a user-defined
configuration. For more details about creating and
10.1.1 Advanced Setup configuring update tasks, see Scheduler 21 .
To disable notifications displayed after each successful
10.3 Upgrading to a new build
update, select Do not display notification about
successful update. For maximum protection, it is important to use the
latest build of ESET Endpoint Antivirus. To check for a
Enable Pre-release Updates to download development new version, click Update from the main menu on the
modules still in testing, this can be useful to resolve left. If a new build is available, a notification will be
product issues. Enable Delayed (Deferred) Updates to displayed at the bottom of the window. Click Learn
download updates a few hours after they are released. more to display a new window containing the version
number of the new build and the changelog.
ESET Endpoint Antivirus records snapshots of virus
signature database and program modules for use with Click Download to download the latest build. Click
the Update Rollback feature. Leave Create snapshots Close to close the window and download the upgrade
of update files enabled to have ESET Endpoint later.
Antivirus record these snapshots automatically. If you
suspect that a new update of the virus database and/or If you clicked Download, the file will be downloaded
program modules may be unstable or corrupt, you can to your downloads folder (or the default folder set by
roll back to the previous version and disable updates your browser). When the file has finished
for a set period of time. Alternatively, you can enable downloading, launch the file and follow the
previously disabled updates if you had postponed installation directions. Your license information will
them indefinitely. When rolling back to a previous automatically be transferred to the new installation.
update, use the Set suspend period to drop-down
menu to specify the time period for which you want to We recommend that you check for upgrades regularly,
suspend updates. If you select until revoked normal especially when installing ESET Endpoint Antivirus via
updates will not resume until you restore them CD/DVD.
manually, use caution when selecting this setting.
10.4 System updates

The Mac OS X system updates feature is an important


component designed to protect users from malicious
software. For maximum security, we recommend that
you install these updates as soon as they become
available. ESET Endpoint Antivirus will notify you about
missing updates according to level of importance. You
can adjust the level of update importance for which
notifications are displayed in Setup > Enter application
preferences > Alerts and notifications > Setup using
the Display Conditions drop-down menu next to

19
Operating system updates.
11.1 Log files
Show all updates – a notification will be displayed
any time that a system update is missing The Log files contain information about all important
program events that have occurred and provide an
Show only recommended – you will be notified
overview of detected threats. Logging acts as an
about recommended updates only
essential tool in system analysis, threat detection and
troubleshooting. Logging is performed actively in the
If you do not want to be notified about missing
background with no user interaction. Information is
updates, deselect the check box next to Operating
recorded based on the current log verbosity settings. It
system updates.
is possible to view text messages and logs directly
from the ESET Endpoint Antivirus environment, as well
The notification window provides an overview of the
as to archive logs.
updates available for the OS X operating system and
the applications updated through the OS X native tool
Log files are accessible from the ESET Endpoint
– Software updates. You can run the update directly
Antivirus main menu by clicking Tools > Log files.
from the notification window or from the Home
Select the desired log type using the Log drop-down
section of ESET Endpoint Antivirus by clicking Install
menu at the top of the window. The following logs are
the missing update.
available:
The notification window contains the application
1. Detected threats – Use this option to view all
name, version, size, properties (flags) and additional
information about events related to the detection
information about available updates. The Flags column
of infiltrations.
contains the following information:
2. Events – This option is designed for system
administrators and users to solve problems. All
[recommended] – the operating system
important actions performed by ESET Endpoint
manufacturer recommends that you install this
Antivirus are recorded in the Event logs.
update to increase the security and stability of the
3. Computer scan – Results of all completed scans are
system
displayed in this window. Double-click any entry to
[restart] – a computer restart is required on
view details of the respective computer scan.
following installation
[shutdown] – the computer must be shut down and Right-click any log file and click Copy to copy the
then powered back on following installation contents of that log file to the clipboard.
The notification window shows the updates retrieved 11.1.1 Log maintenance
by the command line tool called 'softwareupdate'.
Updates retrieved by this tool can vary from the The logging configuration for ESET Endpoint Antivirus is
updates displayed by the 'Software updates' accessible from the main program window. Click Setup
application. If you want to install all available updates > Enter application preferences ... > Tools > Log Files.
displayed in the 'Missing system updates' window and You can specify the following options for log files:
also those not displayed by the 'Software updates'
application, you have to use the 'softwareupdate' Delete old log records automatically – log entries
command line tool. To learn more about this tool, read older than the specified number of days are
the 'softwareupdate' manual by typing man automatically deleted.
softwareupdate into a Terminal window. This is Optimize log files automatically – enables automatic
recommended for advanced users only. defragmentation of log files if the specified
percentage of unused records has been exceeded.
11. Tools
All the relevant information displayed in the graphic
The Tools menu includes modules that help simplify user interface, threat and event messages can be
program administration and offer additional options stored in human readable text formats such as plain
for advanced users. text or CSV (Comma-separated values). If you want to
make these files available for processing using third-
party tools, select the check box next to Enable logging
to text files.

To define the target folder to which the log files will


be saved, click Setup next to Advanced setup.
20
The Scheduler manages and launches scheduled tasks
Based on the options selected under Text Log Files: with predefined configurations and properties. The
Edit, you can save logs with the following information configuration and properties contain information such
written: as the date and time as well as specified profiles to be
used during execution of the task.
Events such as Inva lid userna m e a nd pa ssw ord, V irus
sig na ture da ta ba se ca n not be upda ted etc. are By default, the following scheduled tasks are displayed
written to the eventslog .txt file. in the Scheduler:
Threats detected by the Startup scanner, Real-Time
Protection or Computer Scan are stored in the file Log maintenance (after enabling Show system tasks
named threa tslog .txt. in scheduler setup)
The results of all completed scans are saved in the Startup file check after user logon
format sca nlog .N U M BER.txt. Startup file check after successful update of the virus
signature database
To configure the filters for Default Computer Scan Log Regular automatic update
Records, click Edit and select/deselect log types as Automatic update after user logon
required. Further explanation to these log types can be
found in Log Filtering 21 . To edit the configuration of an existing scheduled task
(both default and user-defined), CTRL+click the task
11.1.2 Log filtering you want to modify and select Edit or select the task
Logs store information about important system events. and click Edit task.
The log filtering feature allows you to display records
about specific events. 11.2.1 Creating new tasks
To create a new task in Scheduler, click Add task or
The most frequently used log types are listed below: CTRL+click in the blank field and select Add from the
context menu. Five types of scheduled tasks are
Critical warnings – critical system errors (for available:
example, Antivirus protection failed to start)
Errors – error messages such as " Error dow nloa ding Run application
file" and critical errors Update
Warnings – warning messages Log maintenance
Informative records – informative messages On-demand computer scan
including successful updates, alerts, etc. System startup file check
Diagnostic records – information needed to fine-
tune the program as well as all records described NOTE: By choosing Run application, you can run
above. programs as a system user called "nobody".
Permissions for running applications through the
11.2 Scheduler Scheduler are defined by Mac OS X.

The Scheduler can be found in the ESET Endpoint In the example below, we will use the Scheduler to
Antivirus main menu under Tools. The Scheduler add a new update task, since update is one of the most
contains a list of all scheduled tasks and configuration frequently used scheduled tasks:
properties such as the predefined date, time, and
scanning profile used. 1. Select Update from the Scheduled task drop-down
menu.

2. Type a name for the task in the Task name field.

3. Select the frequency of the task from the Run task


drop-down menu. Based on the frequency selected,
you will be prompted to specify different update
parameters. If you select User-defined, you will be
prompted to specify date/time in the cron format
(see the Creating user-defined task 22 section for
more details).

21
4. In the next step, define what action to take if the You can choose to quarantine any file. This is advisable
task cannot be performed or completed at the if a file behaves suspiciously but is not detected by the
scheduled time. antivirus scanner. Quarantined files can be submitted
to the ESET Threat Lab for analysis.
5. Click Finish. The new scheduled task will be added
to the list of currently scheduled tasks. Files stored in the quarantine folder can be viewed in a
table which displays the date and time of quarantine,
By default ESET Endpoint Antivirus contains pre- the path to the original location of the infected file, its
defined scheduled tasks to ensure correct product size in bytes, the reason it was quarantined (for
functionality. These should not be altered, and are example, added by user) and the number of threats
hidden by default. To make these tasks visible, from detected. The quarantine folder ( /Libra ry/A pplica tion
the main menu click Setup > Enter application Support/Eset/esets/ca che/qua ra ntine) remains in the
preferences > Scheduler and select Show system tasks. system even after uninstalling ESET Endpoint Antivirus.
Quarantined files are stored in a safe encrypted form
11.2.2 Creating a user-defined task and can be restored again after installing ESET
There are a few special parameters that must be Endpoint Antivirus.
defined when you select User-defined as the task type
from the Run task drop-down menu. 11.3.1 Quarantining files
ESET Endpoint Antivirus automatically quarantines
The date and time of a User-defined task has to be deleted files (if you have not deselected this option in
entered in year-extended cron format (a string the alert window). From the Quarantine window, you
comprising 6 fields separated by white space): can click Quarantine to manually add any file to the
minute(0-59) hour(0-23) day of month(1-31) month quarantine. You can also ctrl-click a file at any time and
(1-12) year(1970-2099) day of week(0-7)(Sunday =
0 or 7)
select Services > ESET Endpoint Antivirus - Add files to
Quarantine from the context menu to send the file to
For example: the quarantine.
30 6 22 3 2012 4
11.3.2 Restoring a quarantined file
The following special characters are supported in cron Quarantined files can also be restored to their original
expressions: location, to do so, select a quarantined file and click
asterisk ( *) – expression will match for all values of Restore. Restore is also available from the context
the field; e.g. asterisk in the 3rd field (day of month) menu, CTRL+click a given file in the Quarantine
means every day window and click Restore. You can use Restore to to
hyphen ( -) – defines ranges; e.g. 3-9 restore a file to a location other than the one from
comma ( ,) – separates items of a list; e.g. 1,3,7,8 which it was quarantined.
slash ( /) – defines increments of ranges; e.g. 3-28/5
in the 3rd field (day of month) means 3rd day of the 11.3.3 Submitting a file from Quarantine
month and then every 5 days.
If you have quarantined a suspicious file that was not
detected by the program, or if a file was incorrectly
Day names (Monday-Sunday) and month names (
evaluated as infected (for example, by heuristic
January-December) are not supported.
analysis of the code) and subsequently quarantined,
please send the file to the ESET Threat Lab. To submit a
NOTE: If you define both a day of the month and day of
file from quarantine, CTRL+click the file and select
the week, the command will only be executed when
Submit file for analysis from the context menu.
both fields match.

11.3 Quarantine

The main purpose of the quarantine is to safely store


infected files. Files should be quarantined if they
cannot be cleaned, if it is not safe or advisable to
delete them, or if they are being falsely detected by
ESET Endpoint Antivirus.

22
11.4 Running processes 11.5 Live Grid

The list of Running processes displays the processes The Live Grid Early Warning System keeps ESET
running on your computer. ESET Endpoint Antivirus immediately and continuously informed about new
provides detailed information on running processes to infiltrations. The bidirectional Live Grid Early Warning
protect users using ESET Live Grid technology. System has a single purpose – to improve the
protection that we can offer you. The best way to
Process – name of the process that is currently ensure that we see new threats as soon as they appear
running on your computer. You can also use Activity is to “link“ to as many of our customers as possible and
monitor (found in /A pplica tions/U tilities) to view all use the information they collect to keep our virus
processes running on your computer. signature information constantly up-to-date. Select
Risk level – in most cases, ESET Endpoint Antivirus one of two options for Live Grid:
and ESET Live Grid technology assign risk levels to
objects (files, processes, etc.) using a series of 1. You can choose not to enable the Live Grid Early
heuristic rules that examine the characteristics of Warning System. You will not lose any functionality
each object and then weigh their potential for in the software, but, in some cases, ESET Endpoint
malicious activity. Based on these heuristics, objects Antivirus may respond faster to new threats than
are assigned a risk level. Known applications marked virus signature database update.
green are definitely clean (whitelisted) and will be 2. You can configure the Live Grid Early Warning
excluded from scanning. This improves the speed of System to submit anonymous information about
both the On-demand and Real-time scans. When an new threats and where new threatening code is
application is marked as unknown (yellow), it is not contained. This information can be sent to ESET for
necessarily malicious software. Usually it is just a detailed analysis. Studying these threats will help
newer application. If you are not sure about a file, ESET update its database of threats and improve our
you can submit it to the ESET Threat Lab for analysis. threat detection ability.
If the file turns out to be a malicious application, its
signature will be added to an upcoming update. The Live Grid Early Warning System will collect
Number of Users – the number of users that use a information about your computer related to newly-
given application. This information is gathered by detected threats. This information may include a
ESET Live Grid technology. sample or copy of the file in which the threat
Time of discovery – period of time since the appeared, the path to that file, the filename, the date
application was discovered by ESET Live Grid and time, the process by which the threat appeared on
technology. your computer and information about your computer‘s
Application Bundle ID – name of the vendor or operating system.
application process.
While there is a chance this may occasionally disclose
By clicking a given process, the following information some information about you or your computer
will appear at the bottom of the window: (usernames in a directory path, etc.) to the ESET Threat
Lab, this information will not be used for ANY purpose
File – location of an application on your computer other than to help us respond immediately to new
File Size – physical size of the file on the disk threats.
File Description – file characteristics based on the
To access Live Grid setup from the main menu, click
description from the operating system
Setup > Enter application preferences > Live Grid.
Application Bundle ID – name of the vendor or
Select Enable Live Grid Early Warning System to
application process
activate Live Grid and then click Setup next to
File Version – information from the application
Advanced Options.
publisher
Product name – application name and/or business 11.5.1 Suspicious files
name
By default, ESET Endpoint Antivirus is configured to
submit suspicious files to the ESET Threat Lab for
detailed analysis. If you do not wish to submit these
files automatically, deselect Submission of Suspicious
Files (Setup > Enter application preferences > Live Grid
> Setup).

23
If you find a suspicious file, you can submit it to our Use standard menu allows you to use certain
Threat Lab for analysis. To do so, click Tools > Submit keyboard shortcuts (see Keyboard shortcuts 9 ) and
file for analysis from the main program window. If it is see standard menu items (User interface, Setup and
a malicious application, its signature will be added to Tools) on the Mac OS menu bar (top of the screen).
the next virus signature database update. Enable Show tooltips to display tooltips when the
cursor is placed over certain options in ESET Endpoint
Submission of Anonymous Statistical Information – The Antivirus.
ESET Live Grid Early Warning System collects Show hidden files allows you to see and select
anonymous information about your computer related hidden files in Scan Targets setup for a Computer
to newly detected threats. This information includes scan.
the name of the infiltration, the date and time it was
detected, the ESET security product version, your 12.1 Alerts and notifications
operating system version and the location setting.
These statistics are typically delivered to ESET servers The Alerts and notifications section allows you to
once or twice daily. configure how threat alerts and system notifications
are handled by ESET Endpoint Antivirus.
Below is an example of a statistical package submitted:
Disabling Display alerts will disable all alert windows
# utc_time=2005-04-14 07:21:28 and is only recommended in specific situations. For
# country=“Slovakia“
# language=“ENGLISH“
most users, we recommend that this option be left on
# osver=9.5.0 its default setting (enabled).
# engine=5417
# components=2.50.2
Selecting Display notifications on desktop will cause
# moduleid=0x4e4f4d41
# filesize=28368 alert windows that do not require user interaction to
# filename=Users/UserOne/Documents/Incoming/ display on the desktop (in the upper-right corner of
rdgFR1463[1].zip your screen by default). You can define the period for
which a notification will be displayed by adjusting the
Exclusion Filter – This option allows you to exclude Close notifications automatically after X seconds value.
certain file types from submission. For example, it may
be useful to exclude files that may carry confidential 12.1.1 Alerts and notifications advanced setup
information, such as documents or spreadsheets. The
most common file types are excluded by default (. ESET Endpoint Antivirus displays alert dialog windows
doc, .rtf etc.). You can add file types to the list of informing you of new program versions, operating
excluded files. system updates, the disabling of certain program
components, the deletion of logs etc. You can suppress
Contact Email (optional) – Your email address will be each notification individually by selecting Do not show
used if further information is required for analysis. this dialog again.
Please note that you will not receive a response from
ESET unless more information is needed. List of Dialogs (Setup > Enter application preferences ...
> Alerts and notifications > Setup) shows the list of all
alert dialogs triggered by ESET Endpoint Antivirus. To
12. User interface enable or suppress each notification, select the check
The user interface configuration options allow you to box left of the Dialog Name. Additionally, you can
adjust the working environment to fit your needs. define Display Conditions under which notifications
These options are accessible from the main menu by about new program versions and operating system
clicking Setup > Enter application preferences > updates will be displayed.
Interface.
12.2 Privileges
To display the ESET Endpoint Antivirus splash screen
at system startup, select Show splash-screen at ESET Endpoint Antivirus settings can be very important
startup. to your organization’s security policy. Unauthorized
Present application in Dock allows you to display the modifications may endanger the stability and
ESET Endpoint Antivirus icon in the Mac OS Dock protection of your system. Consequently, you can
and switch between ESET Endpoint Antivirus and choose which users will have permission to edit the
other running applications by pressing cm d-ta b. program configuration.
Changes take effect after you restart ESET Endpoint
Antivirus (usually triggered by computer restart). You can configure privileged users under Setup > Enter
application preferences > User > Privileges.
24
To provide maximum security for your system, it is 12.4 Context menu
essential that the program be configured correctly.
Unauthorized modifications can result in the loss of To make ESET Endpoint Antivirus features available
important data. To set a list of privileged users, select from the context menu, click Setup > Enter application
them from the Users list on the left side and click Add. preferences > Context Menu and select the check box
To remove a user, select their name from the next to Integrate into the context menu. Changes will
Privileged Users list on the right side and click Remove take effect after you log out or restart your computer.
. To display all system users, select Show all users. Context menu options will be available on the desktop
and in the Finder window when you CTRL+click on any
NOTE: If the list of privileged users is empty, all users file or folder.
of the system will have permission to edit the program
settings. 13. Miscellaneous
12.3 Presentation mode 13.1 Import and export settings
Presentation mode is a feature for users that demand To import an existing configuration or export your ESET
uninterrupted usage of their software, do not want to Endpoint Antivirus configuration, click Setup > Import
be disturbed by pop-up windows and want to and export settings.
minimize CPU usage. Presentation mode can also be
used during presentations that cannot be interrupted Import and export are useful if you need to backup
by antivirus activity. When enabled, all pop-up your current configuration of ESET Endpoint Antivirus
windows are disabled and scheduled tasks are not run. for use at a later date. Export settings is also
System protection still runs in the background, but convenient for users who want to use their preferred
does not require any user interaction. configuration of ESET Endpoint Antivirus on multiple
systems. You can easily import a configuration file to
To enable Presentation mode manually, click Setup > transfer your desired settings.
Enter application preferences... > Presentation mode >
Enable Presentation mode.

Select the check box next to Auto-enable Presentation


mode in fullscreen to trigger Presentation mode
automatically when applications are run in fullscreen
mode. When this feature is enabled, Presentation
mode will start whenever you initiate a fullscreen
application and will automatically stop after you exit
the application. This is especially useful for starting a
presentation.

You can also select Disable Presentation mode 13.1.1 Import settings
automatically after to define the amount of time in To import a configuration click Setup > Import and
minutes after which Presentation mode will export settings from the main menu and then select
automatically be disabled. Import settings. Click Browse to navigate to the
configuration file you want to import.
Enabling Presentation mode is a potential security risk,
so the ESET Endpoint Antivirus protection status icon 13.1.2 Export settings
will turn orange and display a warning.
To export a configuration, click Setup > Import and
export settings from the main menu and select Export
settings. Use the browser to select a location on your
computer to save the configuration file.

25
13.2 Proxy server setup

To configure Proxy server settings, click Setup > Enter


application preferences > Proxy Server. Specifying the
proxy server at this level defines global proxy server
settings for all ESET Endpoint Antivirus functions.
Parameters defined here will be used by all modules
that require a connection to the Internet. ESET
Endpoint Antivirus supports Basic Access and NTLM (NT
LAN Manager) authentication.

To specify proxy server settings for this level select


Use proxy server and enter the IP address or URL of
your proxy server in the Proxy Server field. In the Port
field, specify the port where the proxy server accepts
connections (3128 by default).

If communication with the proxy server requires


authentication, enter a valid Username and Password
into the respective fields.

13.3 Shared Local Cache

To enable the use of the Shared Local Cache, click


Setup > Enter application preferences > Shared Local
Cache and select the check box next to Enable caching
using ESET Shared Local Cache. Use of this feature
boosts performance in virtualized environments by
eliminating duplicate scanning in the network. This
ensures that each file will be scanned only once and
stored in the shared cache. When enabled,
information about scans of files and folders on your
network is saved to the local cache. If you perform a
new scan, ESET Endpoint Antivirus will search for
scanned files in the cache. If files match, they will be
excluded from scanning.

Shared Local Cache settings contain the following:

Server address – name or IP address of the computer


where the cache is located
Port – port number used for communication (3537 by
default)
Password – The Shared Local Cache password
(optional)

26

Вам также может понравиться