2. Product Information .............................................................................. 5
2.1 Features ............................................................................................................................................ 6
6.1 Internet Updates ............................................................................................................................ 44
7. The Dazuko Kernel Module ...................................................................46
7.1 Compiling Dazuko on your own .................................................................................................... 46
7.2 Known Issues with dazukofs ......................................................................................................... 47
8. Service .................................................................................................49
8.1 Support ........................................................................................................................................... 49
9.2 Further Information ...................................................................................................................... 52
9.3 Golden Rules for Protection Against Viruses ............................................................................... 53
Avira GmbHAvira AntiVir Server/ Professional (UNIX)2
1About this Manual
In this Chapter you can find an overview of the structure and contents of this manual.
After a short introduction, you can read information about the following issues:
•The Structure of the Manual – Page 3
•Signs and Symbols – Page 4
1.1Introduction
We have included in this manual all the information you need about Avira AntiVir Server/
Professional and it will guide you step by step through installation, configuration and
operation of the software.
The appendix contains a Glossary which explains the basic terms.
For further information and assistance, please refer to our website, to the Hotline of our
Technical Support and to our regular Newsletter (see Service – Page 49).
Your Avira Team
1.2The Structure of the Manual
The manual of your AntiVir software consists of a number of Chapters, providing you
with the following information:
ChapterContents
1 About this ManualThe structure of the manual, signs and symbols
2 Product InformationGeneral information about Avira AntiVir Server/
3 InstallationInstructions to install AntiVir on your system –
4 ConfigurationDirections for optimum settings of AntiVir
5 OperationWorking with AntiVir, after installation; targeted
6 UpdatesCarrying out automatic or manual Internet updates.
7 The Dazuko Kernel ModuleInformation about compiling and using dazuko.
8 ServiceSupport and Service.
Professional, its modules, features, system
requirements and licensing.
using the installation script.
components on your system.
scanning for viruses and unwanted programs;
reactions when viruses and unwanted programs are
detected.
9 AppendixGlossary of technical terms and abbreviations,
Golden Rules for Protection against Viruses.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)3
1.3Signs and Symbols
The manual uses the following signs and symbols:
SymbolMeaning
3... shown before a condition that must be met prior to
... shown before a step you have to perform.
... shown before the result that directly follows the preceding
For improved legibility and clear marking, the following types of emphasis are also used
in the text:
Emphasis in textExplanation
performing an action.
action.
... shown before a warning if there is a danger of critical data loss
or hardware damage.
... shown before a note containing particularly important
information, e.g. on the steps to be followed.
... shown before a tip that makes it easier to understand and use
AntiVir.
Ctrl+AltKey or key combination
/usr/lib/AntiVir/guard/avscanPath and filename
ls /usr/lib/AntiVir/guardUser entries
http://www.avira.comURLs
Signs and Symbols – Page 4Cross-reference within the document
1.4Abbreviations
The manual uses the following abbreviations:
AbbreviationMeaning
CLSCommand Line Scanner
FAQFrequently Asked Question
GUIGraphical User Interface
SMTPSimple Mail Transfer Protocol
SNMPSimple Network Management Protocol
VDFVirus Definition File
Avira GmbHAvira AntiVir Server/ Professional (UNIX)4
2Product Information
You are responsible for numerous workstations and servers in your network but you are
only human. The servers are the heart of the network. So if viruses can freely penetrate
and spread on your servers, your network is only a step away from breakdown. This is
where AntiVir products for servers come in.
UNIX computers are more often used as file servers or email gateway servers. Thus they
transfer and store files that have no connection to UNIX, e.g. Office documents and email
attachments. So, viruses can access a server through a Windows Client and freely cause
damage.
Avira AntiVir Server/ Professional is a comprehensive and flexible tool for confronting
viruses and unwanted programs and for reliable protection of your systems.
Losing valuable files usually has dramatic consequences. Not even the
best antivirus software can fully protect you against data loss.
Ensure that you make regular backups of your files.
An antivirus program can be reliable and effective only if kept up to
date.
Ensure that you keep your AntiVir programs up to date using
automatic updates as described in this user guide.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)5
2.1Features
AntiVir Server/ Professional offers you extensive configuration possibilities to keep
control of your network.
The current features of AntiVir Server/ Professional are:
•Easy installation, using the installation script.
•Command Line Scanner (on demand):
•Resident guard (on-access):
•Heuristic detection of macroviruses.
•Detection of all common archive types with certain recursion level in the case of
•Simple integration with automatic jobs, such as scanning at a set time.
•Automatic Internet Updates for product, scan engine and VDF.
•Comprehensive functions for logging, warnings and messages for the administrator;
•Self-Integrity Program Check, which ensures the antivirus system is operating
Configurable on-demand search for all known malware types (viruses, Trojans,
backdoor programs, hoaxes, worms etc.)
Configurable reactions when detecting viruses or unwanted programs: repair, move,
rename programs or files; automatically remove viruses or unwanted programs.
nested archives.
sending email warnings (SMTP).
correctly at all times.
2.2Licensing Concept
You must have a license to use AntiVir Server/ Professional. You have to accept the
license terms
(see http://www.avira.com/documents/general/pdf/en/avira_eula_en.pdf).
There are two license modes for using AntiVir Server/ Professional:
•Test version
•Full version
The license depends on the number of users in the network who are to be protected by
AntiVir and on the license period.
The license is given in a license file named hbedv.key . You will receive it by email from
Avira GmbH. It contains certain data, such as the programs you will use and the period of
your license. The same license file may refer to more AntiVir products.
Test Version
Full Version
Details about the 30-days Test License can be found on our Website:
http://www.avira.com.
The range of full version features includes:
•Download of AntiVir versions from the Internet
•License file by email, for converting the test version to a full version
•Complete installation instructions (digital)
•PDF manuals available for Internet download
•Four weeks installation support, starting from acquisition date
•Newsletter service (by email)
•Internet update service for program files and VDF
Avira GmbHAvira AntiVir Server/ Professional (UNIX)6
Self-Integrity Check
Each AntiVir executable binary is signed and performs a self-integrity check during
startup.
The self-integrity check cannot protect against forgery (e.g. to check if
the complete package is faked) or crafted attacks (e.g. the function
call that performs the self-integrity check is bypassed). Such a
verification has to be performed from outside the package.
2.3Modules and Operating Mode
The Avira security software consists of the following program components:
•AntiVir Engine
•AntiVir Guard
•AntiVir Command Line Scanner
•Avira Updater
AntiVir Engine
AntiVir Engine essentially represents the scanning and repairing modules of Avira
software. These are also used by the other AntiVir products.
AntiVir Guard
AntiVir Guard runs as a daemon process. It permanently monitors all user access in the
network (on access) and it protects the files against viruses and unwanted programs. It
immediately blocks access to infected files which can be automatically renamed, repaired
or moved.
AntiVir Command Line Scanner
AntiVir CLS can always be launched from the command prompt (on-demand). Infected
files and suspicious macros can be isolated, cleaned or deleted using a number of options.
It can be integrated and used within scripts.
Avira Updater
Avira Updater downloads current updates from the AntiVir web servers and installs them
at regular intervals, manually or automatically. It can also send update notifications by
email. You can update Avira AntiVir entirely or only the scanner.
2.4System Requirements
Avira AntiVir Server asks for the following minimum system requirements on your
server:
•i386 (Linux) or Sparc (SunOS) processor;
•200 MB free hard disk space;
•40 MB temporary disk space;
•256 MB (512 MB on SunOS) free memory space;
•Linux with glibc; SunOS.
Officially supported distributions for Avira AntiVir Server:
Avira GmbHAvira AntiVir Server/ Professional (UNIX)7
- Red Hat Enterprise Linux 5 Server
- Red Hat Enterprise Linux 4 Server
- Novell SUSE Linux Enterprise Server 10 - 10.2
- Novell SUSE Linux Enterprise Server 9
- Debian GNU/Linux 4 (stable), Debian etch
- Ubuntu Server Edition 8
- Sun Solaris 9 (SPARC)
- Sun Solaris 10 (SPARC)
- Novell Open Enterprise Server
Avira AntiVir Professional asks for the following minimum system requirements on
your server:
•i386 (Linux) or Sparc (SunOS) processor;
•100 MB free hard disk space;
•20 MB temporary disk space
•192 MB (512 MB on SunOS) free memory space;
•Linux with glibc; SunOS.
You need sufficient disk space on your hard drive to save the
temporary guard files. We therefore recommend that there are at
least 4GB available for the temporary directory.
Officially supported distributions for Avira AntiVir Professional:
- Red Hat Enterprise Linux 5 Desktop
- Red Hat Enterprise Linux 4 Desktop
- Novell SUSE Linux Enterprise Desktop 10 - 10.2
- Novell SUSE Linux Enterprise Desktop 9
- Debian GNU/Linux 4 (stable)
- Ubuntu Desktop Edition 8
- Sun Solaris 9 (SPARC)
- Sun Solaris 10 (SPARC)
2.5Technical Information
AntiVir Guard is based on DazukoFS (http://www.dazuko.org), an open source software
project. DazukoFS is a kernel module which allows the AntiVir Guard daemon to access
the files.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)8
3Installation
You can find the current version of Avira AntiVir Server/ Professional on our website
www.avira.com.
AntiVir is supplied as a packed archive. It contains AntiVir Engine, Guard, Command Line
Scanner and the Avira Updater.
You will be guided step by step throughout the installation procedure. This Chapter is
divided into the following sections:
•Getting the Installation Files – Page 9
•Licensing – Page 9
•Installing AntiVir – Page 10
•Reinstalling and Uninstalling AntiVir – Page 14
•Integration in AMaViS – Page 16
3.1Getting the Installation Files
Downloading the Installation Files from the Internet
Download the current version of Avira AntiVir Server/ Professional from our website
http://www.avira.com to your local computer.
Save the file in the temporary folder (/tmp) on the computer on which you want to
run Avira AntiVir Server/ Professional. The file name is
antivir-server-prof-<version>.tar.gz
or:
antivir-workstation-prof-<version>.tar.gz
Unpacking Program Files
Go to the temporary directory:
cd /tmp
Unpack the archive containing the AntiVir kit:
tar -xzvf antivir-server-prof-<version>.tar.gz
or:
tar -xzvf antivir-workstation-prof-<version>.tar.gz
In the temporary directory will then appear:
3.2Licensing
You must have an AntiVir license in order to use the product (see Licensing Concept –
Page 6). The license comes in a file named hbedv.key.
This license file contains information regarding the scope and period of the license.
Purchasing the License
You may contact us by telephone or by email (sales@avira.com) to acquire a license
file for Avira AntiVir Server/ Professional.
You will receive the license file by email.
antivir-server-prof-<version> or antivir-workstation-prof-<version>
Avira GmbHAvira AntiVir Server/ Professional (UNIX)9
You can easily acquire Avira AntiVir Server/ Professional using our Online Shop (for
details, visit http://www.avira.com).
Copying the License File
Copy the license file hbedv.key to the installation directory on your system
./tmp/antivir-server-prof-<version>
or in ./tmp/antivir-workstation-prof-<version>.
3.3Installing AntiVir
AntiVir is automatically installed using a script. This script performs the following tasks:
•Checks integrity of the installation files.
•Checks for the required permissions for the installation.
•Checks for an existing version of AntiVir on the computer.
•Copies the program files. Overwrites existing obsolete files.
•Copies AntiVir configuration files. Existing AntiVir configuration files are inherited.
•Optional: it creates a link in /usr/bin, so that AntiVir can be called from any folder
without needing a given path.
•Optional: it installs the resident scanner AntiVir Guard and the dazuko module.
•Optional: it installs a Gnome plug-in.
•Optional: it installs Avira Updater.
•Optional: it configures an automatic start for Avira Updater and AntiVir Guard on
system start-up.
•Optional: it installs the plug-in for Avira Security Management Center.
You can also perform the installation without having a license key from the
beginning. You can copy the license file at any time to the AntiVir program
directory /usr/lib/AntiVir/guard.
Preparing Installation
Login as root. Otherwise you do not have the required authorization for installation
and the script returns an error message.
Go to the directory in which you unpacked AntiVir:
cd /tmp/antivir-server-prof-<version>
or
cd /tmp/antivir-workstation-prof-<version>
Installing AntiVir (example for AntiVir Server)
For using Avira AntiVir Server/ Professional v.3 with AntiVir Guard, we
recommend and support dazuko3/dazukofs.
The installation script will also install dazuko3, if it detects the
needed build components on your system. If the installation script
cannot detect a supported linux kernel version, you can only install Avira
AntiVir without AntiVir Guard. AntiVir Guard can be easily installed
later. For more details, see The Dazuko Kernel Module – Page 46.
Type the command:
./install
Avira GmbHAvira AntiVir Server/ Professional (UNIX)10
Please note the dot and slash in the command syntax. Typing the command without
this path specification, leads to another command, which is not related to AntiVir
installation process and this would result in error messages and unwanted actions.
Press q to close the license text view.
The installation script starts. After you agree with the license terms, it will copy
the program files. The Installer can read an existing license key:
Do you agree to the license terms? [n] y
creating /usr/lib/AntiVir/guard ... done
copying AV_SRV_PROF to /usr/lib/AntiVir/guard ... done
copying LICENSE to /usr/lib/AntiVir/LICENSE-server ... done
1) installing AntiVir Core Components (Engine, Savapi and Avupdate)
copying uninstall to /usr/lib/AntiVir/guard ... done
copying etc/file_list to /usr/lib/AntiVir/guard ... done
.....
Enter the path to your key file: [HBEDV.KEY]
copying HBEDV.KEY to /usr/lib/AntiVir/guard/avira.key ... done
installation of AntiVir Core Components (Engine, Savapi and Avupdate) complete
After you type the path to the key file, the installer continues with updates’
configuration:
2) Configuring updates
An internet updater is available...
...
Would you like to create a link in /usr/sbin for avupdate-guard? [y]
Type y and confirm with Enter.
Then the script can create a cron task for automatic updates:
linking /usr/sbin/avupdate-guard ... done
Would you like to setup Scanner update as cron task ? [y]
The update cron job uses the minute when the product was installed. If you
want another update time, you can change the entries later, in
/etc/cron.d/avira_updater
Press Enter. You can change this setting later.
Then select the update interval (daily - d; every two hours - 2):
Please specify the interval to check.
Recommended values are daily or 2 hours.
available options: d [2]
Enter d or 2.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)11
If you selected daily updates, you can specify the time of the day when the updates
should start:
The AntiVir Updater can be set to always check for updates at a particular time of
day. This is specified in a HH:MM format (where HH is the hour and MM is the
minutes). If you do not have a permanent connection, you may set it to a time
when you are usually online.
available option: HH:MM
What time should updates be done [00:15]?
Press Enter or set another time first.
Then the installer asks if you want to check for Product updates every week:
Would you like to check for Guard updates once a week ? [n]
Press y, if you want to create this task, or just press Enter, if you don’t.
The next step of the installation process is installing the main program.
If no dazuko device is detected on your system, the script tries to install
dazuko:
3) installing main program
copying doc/avserver_en.pdf to /usr/lib/AntiVir/guard ... done
copying bin/linux_glibc22/libdazuko3compat2.so to /usr/lib/AntiVir/guard...
done
...
No Dazuko device found on your system
Would you like to install dazuko now ? [y]
Press y, if you want to install dazuko and use AntiVir Guard, then press Enter.
Dazuko3 package is installed.
installing dazuko ... Available Dazuko3-Package: '3.0.0-rc4'
checking for needed build components:
checking for C compiler cc ... found
checking for C compiler gcc ... found
checking for kernel sources ... found
linking /usr/lib/AntiVir/guard/libdazuko.so to /usr/lib/AntiVir/guard/
libdazuko3compat2.so...
If the attempt to install dazuko fails, you have to compile the module yourself.
For more details, see The Dazuko Kernel Module – Page 46.
AntiVir can be installed even without dazuko, but in this case it will run
without AntiVir Guard.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)12
The installer then reads /etc/fstab, to check the directories to be mounted as
dazukofs. If no entry is found, it asks you to enter one directory to be scanned by
the Guard:
Guard will automatically protect all directories
which are mounted upon dazukofs filesystem.
Please specify at least one directory to be protected
by Guard to add in /etc/fstab: [/home]
There are some file systems that should not be overlayed by dazukofs, since
no security gain would be achieved, but on the contrary, it could lead to
system malfunction. Examples of these file systems are
procfs (/proc), usbfs
. These file systems do not allow the creation
sysfs (/sys),
of files anyway, so they do not need to be protected against malware.
The special directory "/" (
root) should not be mounted with dazukofs,
because it may also be the root for other file systems, which likewise should
not be mounted with dazukofs.
Mounting "/" could also be dangerous due to the fact that there will very
likely be processes already working on files under/ before dazukofs is
mounted. This might result in undefined file states, if those files are later
accessed through the dazukofs layer.
Type one directory, which you want to be protected on-access (for example, /home)
and press Enter.
If you want to modify the list of protected directories, you can add or remove entries
later, by editing /etc/fstab file and remounting dazukofs.
Then the installer checks if the default quarantine directory exists:
/home/quarantine, the AVIRA Guard default quarantine directory, does not exist.
INFO: You can change the quarantine directory in /etc/avira/avguard.conf.
and /etc/avira/avscan.conf after the installation.
Would you like to create /home/quarantine ? [y]
Type Enter, to create the directory, if necessary. You can change it later in the
configuration files.
Then the script can install a GNOME plug-in, which would allow you to add the
status icon for AntiVir Guard to the panel ( - Guard is active; - Guard is
inactive):
Would you like to install the AVIRA Guard GNOME plugin? [n]
Type y and press Enter, if you want to install the plug-in,
or just press Enter, if you don’t.
Then you are asked if you want to create a link to avguard and if the Updater should
be automatically activated at system start:
Would you like to create a link in /usr/sbin for avguard ?[y]
linking /usr/sbin/avguard to /usr/lib/AntiVir/guard/avguard ... done
Please specify if boot scripts should be set up.
Set up boot scripts [y]:
Confirm with Enter.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)13
The automatic system start is configured:
setting up boot script ... done
installation of AVIRA Guard complete
Then the script can install the optional plug-in for Avira Security Management
Center:
4) activate SMC support
The AntiVir Security Management Center (SMC) requires this feature.
Would you like to activate the SMC support? [y]
If you are using Avira SMC, type y or confirm with Enter.
The plug-in is installed and the installation process is complete. You can start
AntiVir Guard, if dazuko is correctly compiled:
Would you like to start AVIRA Guard now? [y]
Starting Avira AntiVir Server...
Starting: avguard.bin
You will see a report that indicates the completion of the installation:
Installation of the following features complete:
AntiVir Core Components (Engine, Savapi and Avupdate)
AVIRA Internet Updater
AVIRA Guard
AntiVir SMC plugin
Finally, you can start AntiVir:
/usr/lib/AntiVir/guard/avguard start
Modified binaries will not run.
For example, if binaries are prelinked: Either disable prelinking or add
/usr/lib/AntiVir/guard as an excluded prelink path in
/etc/prelink.conf
3.4Reinstalling and Uninstalling AntiVir
You can launch the installation script at any time. There are several possible situations,
such as:
•Later installation of some components, e.g. AntiVir Guard or Avira Updater.
•Activating or deactivating the automatic start of Avira Updater or AntiVir Guard.
Reinstalling AntiVir
The procedure applies to all above mentioned cases:
3 First of all, you have to make sure that AntiVir Guard is stopped:
/usr/lib/AntiVir/guard/avguard stop
Open the temporary directory where you unpacked AntiVir Server:
cd /tmp/antivir-server-prof-<version>
Avira GmbHAvira AntiVir Server/ Professional (UNIX)14
or, for AntiVir Professional:
cd /tmp/antivir-workstation-prof-<version>
Type:
./install
The installation script performs as described in Installing AntiVir – Page 10).
Make the changes you need during installation procedure.
AntiVir is installed with the required features.
Uninstalling AntiVir
You can use the uninstall script, located in the temporary AntiVir directory, to remove
Avira AntiVir Server/ Professional. The syntax is:
where productname is Guard. Open the AntiVir directory:
cd /usr/lib/AntiVir/guard
Type:
./uninstall --product=Guard
The script starts uninstalling the product, asking you step by step, if you want to
keep backups for the license file, for the configuration files and logfiles; it can also
remove the cronjobs you made for Guard and Scanner.
Answer the questions with y or n and press Enter.
Avira AntiVir Server/ Professional is removed from your system.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)15
3.5Integration in AMaViS
"A Mail Virus Scanner (AMaViS)" project (http://www.amavis.org/) is already prepared
for integration with the AntiVir Scanner. You can either install AMaViS after installing
AntiVir, for automatic detection, or explicitly activate AntiVir support during AMaViS
installation using the option --enable-all or --enable-hbedv for the command
./configure.
Please note that AMaViS uses the Command Line Scanner and runs it as a
separate process for every message. Unfortunately, this method is not as
efficient as a dedicated email scanner. For an environment with higher
throughput requirements, you should consider integrating Avira AntiVir
MailGate or SAVAPI-based products.
You need a license to integrate the Command Line Scanner with AMaViS.
This allows you to generate antivirus scan services for other computers.
Avira GmbHAvira AntiVir Server/ Professional (UNIX)16
4Configuration
You can adjust AntiVir Server/ Professional for optimum performance. You can make the
main adjustments immediately after installation. The most common settings are
suggested. You can modify these settings anytime, to adjust the product to your
requirements.
After a short overview, you will be guided step by step through the configuration process:
•Description of the configuration files:
- Configuration of AntiVir Guard in avguard.conf – Page 17
- Configuration of the Command Line Scanner in avscan.conf – Page 25
- Scanner specific configuration in avguard-scanner.conf – Page 30
- Configuration of Avira Updater in avupdate-guard.conf – Page 31
•Testing AntiVir Server/Professional - Page 33, after completing the configuration.
4.1Configuration Files
The configuration is defined in four files:
•/etc/avira/avguard.conf configures the on-access scanner.
•/etc/avira/avscan.conf configures the on-demand scanner.
•/etc/avira/avupdate-guard.conf defines the automatic updates.
The settings can be made directly in the configuration files or as
parameters when using the Command Line Scanner.
The parameters given in command lines take precedence of those
saved in configuration files.
This part describes the structure of AntiVir Server/ Professional configuration files.
AntiVir Server/ Professional reads these files on program start-up. It ignores empty lines
and commented lines beginning with #.
The program is provided with default values, which are important for many procedures.
Some options can be deactivated with a # at the beginning of the line (commented) or can
be set with default values. These can be activated by removing the # character or by
changing the values.
You must restart the AntiVir Guard if you modify any values
manually in the configuration files. The changes only take effect after
a restart.
Type:
/usr/lib/AntiVir/guard/avguard restart
4.1.1Configuration of AntiVir Guard in avguard.conf
This section provides a short description of the entries in avguard.conf . The settings
affect only the behavior of AntiVir Server/ Professional and no other AntiVir programs.
OnAccess
Management
Avira GmbHAvira AntiVir Server/ Professional (UNIX)17
Enable/ Disable on-access protection:
This option allows you to explicitly enable/ disable on-access protection of specified
directories provided by Guard using dazukofs/dazuko kernel module.
Loading...
+ 37 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.