Faronics Anti-Virus Enterprise User Manual

1
|
Faronics Anti-Virus User Guide
2|
Faronics Anti-Virus User Guide
Last modified: February, 2014
© 1999 - 2014 Faronics Corporation. All rights reserved. Faronics, Deep Freeze, Faronics Core Console, Faronics Anti-Executable, Faronics Anti-Virus, Faronics Device Filter, Faronics Data Igloo, Faronics Power Save, Faronics Insight, Faronics System Profiler, and WINSelect are trademarks and/or registered trademarks of Faronics Corporation. All other company and product names are trademarks of their respective owners.
Contents
Faronics Antivirus . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Important Information. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
About Faronics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Product Documentation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Technical Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Contact Information. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Definition of Terms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Faronics Anti-Virus Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
System Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Faronics Anti-Virus Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Faronics Core Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Deep Freeze Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Faronics Anti-Virus Licensing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
3
|
Installing Faronics Anti-Virus . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Installation Overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Installing Faronics Core . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Installing Faronics Anti-Virus Loadin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Installing or Upgrading Faronics Anti-Virus on a Workstation via Faronics Core . . . . . . . . . . . . . 20
Installing Faronics Anti-Virus on a Workstation Manually . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Using Faronics Anti-Virus . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Faronics Anti-Virus Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Managing Faronics Anti-Virus via Faronics Core Console. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Deploying Faronics Anti-Virus Client on the workstation(s) . . . . . . . . . . . . . . . . . . . . . . . . 27
Configuring Faronics Anti-Virus . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Refreshing Faronics Anti-Virus. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29
Faronics Anti-Virus Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
Creating Anti-Virus Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
Applying an Anti-Virus Policy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
Viewing or Modifying an Anti-Virus Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
Renaming an Anti-Virus Policy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
Copying a Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
Deleting an Anti-Virus Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
Importing an Anti-Virus Policy. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
Exporting an Anti-Virus Policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
Scanning via Faronics Core Console. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58
Viewing and Taking Action on Quarantined Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
Viewing Faronics Anti-Virus Log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61
Updating Faronics Anti-Virus via Faronics Core Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65
Schedule Action for Faronics Anti-Virus via Faronics Core Console . . . . . . . . . . . . . . . . . . . . . . 66
Generating Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
Global Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
Workstation-specific Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 67
Faronics Anti-Virus User Guide
4|Contents
Using Faronics Anti-Virus on the Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68
Launching Faronics Anti-Virus on the Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68
Scanning the Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 70
Scanning a File or a Folder via Right-Click . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
View Scanning History . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
View and take action on Quarintined Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Updating Anti-Virus Definitions on the Workstation . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75
Managing Faronics Anti-Virus on the Workstation via the System Tray . . . . . . . . . . . . . . . . . . 76
Command Line Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 77
Command Line Control. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78
Uninstalling Faronics Anti-Virus . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79
Uninstallation Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 80
Uninstalling Faronics Ant-Virus Client via Faronics Core Console . . . . . . . . . . . . . . . . . . . . . . 81
Uninstalling Faronics Anti-Virus Client on the Workstation via Add or Remove Programs . . . . . . 82
Uninstalling Faronics Anti-Virus Loadin with the Installer . . . . . . . . . . . . . . . . . . . . . . . . . . . 83
Uninstalling Faronics Anti-Virus Loadin via Add or Remove Programs . . . . . . . . . . . . . . . . . . . 86
Faronics Anti-Virus User Guide
Topics
Faronics Antivirus
This user guide explains how to install and use Faronics Anti-Virus.
Important Information
Technical Support
Definition of Terms
|
5
Faronics Anti-Virus User Guide
6| Faronics Antivirus
Important Information
About Faronics
Product Documentation
This section contains important information about your Faronics Product.
Faronics delivers market-leading solutions that help manage, simplify, and secure complex IT environments. Our products ensure 100% machine availability, and have dramatically impacted the day-to-day lives of thousands of information technology professionals. Fueled by a market-centric focus, Faronics’ technology innovations benefit educational institutions, health care facilities, libraries, government organizations, and corporations.
The following documents form the Faronics Anti-Virus documentation set:
Faronics Anti-Virus User Guide — This document guides you how to use the product.
Faronics Anti-Virus Release Notes — This document lists the new features, known issues, and closed issues.
Faronics Anti-Virus User Guide
Technical Support|7
Technical Support
Every effort has been made to design this software for ease of use and to be problem free. If problems are encountered, contact Technical Support.
Email: support@faronics.com
Phone: 1-800-943-6422 or 1-604-637-3333
Hours: Monday to Friday 7:00am to 5:00pm (Pacific Time)
Contact Information
Web: www.faronics.com
Email: sales@faronics.com
Phone: 1-800-943-6422 or 1-604-637-3333
Fax: 1-800-943-6488 or 1-604-637-8188
Hours: Monday to Friday 7:00am to 5:00pm (Pacific Time)
• Address: Faronics Technologies USA Inc.
100, W. San Fernando St. Suite 465
San Jose, CA, 95113
USA
Faronics Corporation
1400 - 609 Granville Street
PO Box 10362 Pacific Centre
Vancouver, BC V7Y 1G5
Canada
Faronics Pte Ltd
20 Cecil Street #104-01
Equity Way 049705,
Singapore
Faronics EMEA
Bracknell, England
8 The Courtyard, Eastern Road,
Bracknell, Berkshire
RG12 2XB, Europe
Faronics Anti-Virus User Guide
8| Faronics Antivirus
Definition of Terms
Term Definition
Active Protection Active Protection (AP) is a real-time method for detecting malware.
AP sits quietly in the background as you work or browse the Internet, constantly monitoring files that are executed (run) without causing noticeable strain to your system.
Adware Adware, also known as advertising software, is often contextually or
behaviorally based and tracks browsing habits in order to display third-party ads that are meant to be relevant to the user. The ads can take several forms, including pop-ups, pop-unders, banners, or links embedded within web pages or parts of the Windows interface. Some adware advertising might consist of text ads shown within the application itself or within side bars, search bars, and search results.
Email Protection Email Protection is a behind-the-scenes tool that protects your
computer from potentially harmful inbound and outbound email messages. As long as you have email protection enabled, your computer is protected with automatic email scanning of all attachments for malware and viruses without you having to do anything.
Firewall A Firewall provides bi-directional protection, protecting you from
both incoming and outgoing traffic. A Firewall protects your network from unauthorized intrusion.
Quarantine The Quarantine is a safe place on your computer that Faronics
Anti-Virus uses to store malware or infected files that could not be disinfected. If your computer or files on your computer are not acting normal after an item has been placed here, you have the opportunity to review the details of a risk and research it further and remove it from Quarantine, restoring it back to your computer in its original location. You can also permanently remove the risks from Quarantine.
Rogue security program
A rogue security program is software of unknown or questionable origin, or doubtful value. A rogue security program usually shows up on web sites or spam emails as intrusive warnings that claim that your computer is infected and offer to scan and clean it. These should never be trusted. Reputable antivirus or antispyware companies will never use this way of notifying you. A rogue security program may appear like an ordinary antivirus or antimalware program, but will instead attempt to dupe or badger you into purchasing the program. While some rogue security programs are the equivalent to snake oil salesman resulting in no good, others may actually result in harm by installing malware or even stealing the credit information that you enter and possibly resulting in identity theft. Further, you need to be cautious about closing or deleting these alerts, even when you know they're fake.
Faronics Anti-Virus User Guide
Definition of Terms|9
Term Definition
Rootkits A rootkit is software that cloaks the presence of files and data to evade
detection, while allowing an attacker to take control of the machine without the user's knowledge. Rootkits are typically used by malware including viruses, spyware, trojans, and backdoors, to conceal themselves from the user and malware detection software such as anti-virus and anti-spyware applications. Rootkits are also used by some adware applications and DRM (Digital Rights Management) programs to thwart the removal of that unwanted software by users.
Spyware Spyware is software that transmits information to a third party
without notifying you. It is also referred to as trackware, hijackware, scumware, snoopware, and thiefware. Some privacy advocates even call legitimate access control, filtering, Internet monitoring, password recovery, security, and surveillance software spyware because those could be used without notifying you.
Trojan A trojan is installed under false or deceptive pretenses and often
without the user's full knowledge and consent. In other words, what may appear to be completely harmless to a user is in fact harmful by containing malicious code. Most trojans exhibit some form of malicious, hostile, or harmful functionality or behavior.
Virus A computer virus is a piece of malicious code that has the ability to
replicate itself and invade other programs or files in order to spread within the infected machine. Viruses typically spread when users execute infected files or load infected media, especially removable media such as CD-ROMs or flash drives. Viruses can also spread via email through infected attachments and files. Most viruses include a payload that can be anywhere from annoying and disruptive to harmful and damaging; viruses can cause system damage, loss of valuable data, or can be used to install other malware.
Worm A worm is a malicious program that spreads itself without any user
intervention. Worms are similar to viruses in that they self-replicate. Unlike viruses, however, worms spread without attaching to or infecting other programs and files. A worm can spread across computer networks via security holes on vulnerable machines connected to the network. Worms can also spread through email by sending copies of itself to everyone in the user's address book. A worm may consume a large amount of system resources and cause the machine to become noticeably sluggish and unreliable. Some worms may be used to compromise infected machines and download additional malicious software.
Faronics Anti-Virus User Guide
10| Faronics Antivirus
Faronics Anti-Virus User Guide
Topics
Introduction
Faronics Anti-Virus provides protection from security threats without slowing down computers due to slow scan times and large footprints. Built with next-generation technology, Faronics Anti-Virus gives you powerful anti-virus, anti-rootkit and anti-spyware software in-one that protects you against today’s highly complex malware threats while providing seamless integration with Faronics Deep Freeze and Faronics Anti-Executable to form a complete layered security solution.
Faronics Anti-Virus Overview
11
|
System Requirements
Faronics Anti-Virus Licensing
Faronics Anti-Virus User Guide
12| Introduction
Faronics Anti-Virus Overview
Faronics Anti-Virus protects workstations from the following threats:
Adware
Rogue Security Programs
Rootkits
Spyware
Trojan
Worms
Faronics Anti-Virus can be deployed on multiple workstations via Faronics Core. For information on Faronics Core, refer to Faronics Core User Guide. The latest user guide is available at
http://www.faronics.com/library.
When installed with Deep Freeze, the Anti-Virus definitions can be updated on managed workstations without requiring to Reboot Thawed or rebooting in Maintenance Mode. For more information, refer to Deep Freeze Enterprise User Guide. The latest user guide is available at
http://www.faronics.com/library.
Faronics Anti-Virus User Guide
System Requirements|13
System Requirements
Faronics Anti-Virus Requirements
The Faronics Anti-Virus Loadin requires the following:
Faronics Core 3.7 or higher
Faronics Anti-Virus Client on the workstation requires any of the following operating systems:
Windows XP SP3 (32-bit) or Windows XP SP2 (64-bit)
Windows Vista SP2 (32-bit or 64 bit)
Windows 7 (32-bit or 64 bit)
Windows 8.1 (32-bit or 64 bit)
Windows Server 2003 (32-bit or 64-bit)
Windows Server 2008 R2 (64-bit)
Windows Server 2012 (64-bit)
It is highly recommended that all components be installed using a Windows Administrator account.
Faronics Core Requirements
Information on Faronics Core system requirements can be found in the Faronics Core User Guide. The latest user guide is available at http://www.faronics.com/library.
Deep Freeze Requirements
Information on Deep Freeze system requirements can be found in the Deep Freeze Enterprise User Guide. The latest user guide is available at http://www.faronics.com/library.
To run Faronics Anti-Virus on workstations managed by Deep Freeze, Deep Freeze Enterprise 7.0 or higher is required.
Faronics Anti-Virus User Guide
14| Introduction
Faronics Anti-Virus Licensing
Faronics Anti-Virus License can be applied via Faronics Core Console. Complete the following steps to apply Faronics Anti-Virus License:
1. Launch Faronics Core Console.
2. Right-click the Core Server and select Properties.
3. Click the Anti-Virus tab. The Anti-Virus tab displays the Version, License Key (if it is a Licensed Version), and License Expiry.
4. Click Edit and enter the License Key in the License Key field.
5. Click Apply. Click OK.
Faronics Anti-Virus Licensing works as follows:
The Core Server (a component of Faronics Core) automatically pushes the License Key to the workstations where Faronics Anti-Virus Client is installed (if the computers are offline, the License Key is applied once the computers are back online).
If the Faronics Anti-Virus License Key was entered while installing the Loadin, it is not necessary to enter it again in the Properties tab.
Virus definitions cannot be downloaded if Faronics Anti-Virus License Key has expired.
Faronics Anti-Virus User Guide
Topics
Installing Faronics Anti-Virus
This chapter describes how to install Faronics Anti-Virus.
Installation Overview
Installing Faronics Anti-Virus Loadin
Installing or Upgrading Faronics Anti-Virus on a Workstation via Faronics Core
Installing Faronics Anti-Virus on a Workstation Manually
15
|
Faronics Anti-Virus User Guide
16| Installing Faronics Anti-Virus
Installation Overview
Installing Faronics Core
Faronics Anti-Virus consists of two components:
Faronics Anti-Virus Loadin - to be installed on a computer that has Faronics Core.
Faronics Anti-Virus Client - to be deployed on workstation(s) that will be managed by the Faronics Anti-Virus Loadin.
Installation and configuration of Faronics Anti-Virus involves the following stages:
Installing Faronics Core and generating/deploying the Core Agent
Installing the Faronics Anti-Virus Loadin
Deploying Faronics Anti-Virus Client
For information on installing Faronics Core and generating and deploying the Core Agent, refer to the Faronics Core user guide. The latest user guide is available at
http://www.faronics.com/library.
Faronics Anti-Virus User Guide
Installing Faronics Anti-Virus Loadin|17
Installing Faronics Anti-Virus Loadin
Complete the following steps to install Faronics Anti-Virus Loadin:
The Anti-Virus Loadin cannot be installed on a computer that does not have Faronics Core Console (or Faronics Core Server) installed.
1. Double-click Anti-VirusLoadinInstaller.exe. Click Next.
2. Read and accept the License Agreement. Click Next.
Faronics Anti-Virus User Guide
18| Installing Faronics Anti-Virus
3. Enter the User Name, Organization and the License Key. Alternatively, select the Use Evaluation check box. Faronics Anti-Virus expires after 30 days of evaluation. Click Next.
4. The default location is C:\Program Files\Faronics\Faronics Core 3\Loadins\Anti-Virus.
Faronics Anti-Virus User Guide
5. Click Install to install Faronics Anti-Virus Loadin.
Installing Faronics Anti-Virus Loadin|19
6. The following message is displayed. Click Yes to restart the Faronics Core Server service. Click No to manually restart the Faronics Core Server service later.
7. Click Finish to complete installation.
Faronics Anti-Virus User Guide
20| Installing Faronics Anti-Virus
Installing or Upgrading Faronics Anti-Virus on a Workstation via
Faronics Core
The Core Agent, which is part of Faronics Core, must be installed on each workstation that will be managed by Faronics Anti-Virus. For more information on installing the Core Agent, refer to the Faronics Core user guide. The latest user guide is available at http://www.faronics.com/library.
Once the Core Agent is installed, the workstations are detected on the network and visible in Core Console.
To install or upgrade Faronics Anti-Virus, select a single workstation or multiple workstations:
1. Click Configure Workstations in the right pane and select Advanced > Install/Upgrade Faronics Anti-Virus Client.
2. Select the following options if you have another Anti-Virus program installed:
Remove any incompatible Anti-Virus products before installing Faronics Anti-Virus Enterprise Workstation.
Install Faronics Anti-Virus even if another Anti-Virus product is present or its removal failed.
The workstation reboots after a successful install or upgrade.
If there is more than one Loadin installed, the right-click contextual menu for Faronics Anti-Virus can be accessed by right-clicking a workstation, selecting Anti-Virus and then selecting the particular action.
Faronics Anti-Virus User Guide
Installing Faronics Anti-Virus on a Workstation Manually|21
Installing Faronics Anti-Virus on a Workstation Manually
Before installing Faronics Anti-Virus Client on a workstation, copy the appropriate .msi file from the path C:\Program Files\Faronics\Faronics Core 3\Loadins\Anti-Virus\Wks Installers on the computer where the Anti-Virus Loadin is installed to one or more workstations.
Repeat the process for each workstation that will be protected with Faronics Anti-Virus.
Complete the following steps to install Faronics Anti-Virus on the workstation:
1. Double-click AntiVirus_Ent_32-bit.msi on a 32-bit operating system and AntiVirus_Ent_64-bit.msi on a 64-bit operating system. Click Next.
2. Select the following options if you have another Anti-Virus program installed:
Remove any incompatible Anti-Virus products before installing Faronics Anti-Virus Enterprise Workstation.
Install Faronics Anti-Virus even if another Anti-Virus product is present or its removal failed.
3. Read and accept the License Agreement. Click Next.
Faronics Anti-Virus User Guide
22| Installing Faronics Anti-Virus
4. Enter the User Name and Organization. Click Next.
Faronics Anti-Virus User Guide
5. The default location is C:\Program Files\Faronics\Faronics Anti-Virus Enterprise. Click Change... to change the location where Faronics Anti-Virus is installed. Click Next.
Installing Faronics Anti-Virus on a Workstation Manually|23
6. Click Install to install Faronics Anti-Virus.
7. Click Finish to complete installation.
Faronics Anti-Virus User Guide
24| Installing Faronics Anti-Virus
An immediate restart is recommended after installing the Anti-Virus Client on the workstation.
Faronics Anti-Virus User Guide
Topics
Using Faronics Anti-Virus
This chapter explains how to use Faronics Anti-Virus.
Faronics Anti-Virus Overview
Managing Faronics Anti-Virus via Faronics Core Console
Faronics Anti-Virus Policy
25
|
Scanning via Faronics Core Console
Viewing and Taking Action on Quarantined Files
Viewing Faronics Anti-Virus Log
Updating Faronics Anti-Virus via Faronics Core Console
Generating Reports
Using Faronics Anti-Virus on the Workstation
Managing Faronics Anti-Virus on the Workstation via the System Tray
Faronics Anti-Virus User Guide
26| Using Faronics Anti-Virus
Faronics Anti-Virus Overview
Faronics Anti-Virus can be used in the following ways:
Managing Faronics Anti-Virus via Faronics Core Console:
Install Faronics Anti-Virus Loadin (for more information, refer to Installing Faronics
Anti-Virus Loadin)
Deploy Faronics Anti-Virus Client on the workstation(s)
Create, Edit, Delete and Apply an Anti-Virus Policy
Scan Workstation(s) via Faronics Core Console
Enable/Disable the Firewall
View Scanning History
Viewing and Taking Action on Quarantined Files
Updating Anti-Virus Definitions via Faronics Core Console
Generating Reports
Enable/Disable Active Protection
View Logs
Using Faronics Anti-Virus on the Workstation
Launching Faronics Anti-Virus on the workstation
Scanning the workstation
Updating Anti-Virus Definitions on the workstation
Enable/Disable Active Protection
Enable/Disable Firewall
View Scanning History
Quarantined
Faronics Anti-Virus User Guide
Loading...
+ 60 hidden pages