KASPERSKY Anti-Virus for Novell NetWare 5.7 User Manual

Page 1
KASPERSKY LAB
Kaspersky Anti-Virus 5.7 for Novell NetWare
ADMINISTRATOR’S GUIDE
Page 2
KASPERSKY ANTI-VIRUS 5.7 FOR NOVELL NETWARE
Administrator’s Guide
http://www.kaspersky.com/
Revision date: October, 2006
Page 3
Contents
CHAPTER 1. INTRODUCTION............................................................................ 7
1.1. What’s new in version 5.7?.................................................................................. 8
1.2. Hardware and software requirements................................................................. 8
1.3. Distribution kit....................................................................................................... 8
1.4. Help Desk for Registered Users.......................................................................... 9
1.5. Conventions ....................................................................................................... 10
CHAPTER 2. KASPERSKY ANTI-VIRUS 5.7 FOR NOVELL NETWARE
BASICS 11
2.1. Deploying protection on servers........................................................................ 11
2.2. Basic concepts and operation scheme of the application ................................ 12
2.3. Maintaining the antiviral protection system ....................................................... 13
CHAPTER 3. INSTALLING, UPDATING, AND UNINSTALLING THE
APPLICATION 14
3.1. Installation from the distribution package.......................................................... 14
3.1.1. Installing Kaspersky Anti-Virus for Novell NetWare..................................... 16
3.1.2. Installing Snapin for Console One................................................................ 19
3.1.3. Installing Web management module............................................................ 19
3.1.4. Installing Kaspersky Administration Kit Network Agent............................... 20
3.2. Deploying the application across the network .................................................. 21
3.3. Installing application on cluster volume............................................................. 23
3.4. Uninstalling the application ................................................................................ 24
3.5. Updating the application version ....................................................................... 24
CHAPTER 4. SETTING UP THE APPLICATION.............................................. 26
4.1. Starting the application ...................................................................................... 26
4.2. Application interface........................................................................................... 26
4.3. Default protection of the server ......................................................................... 29
4.4. Starting/stopping the application on the server................................................. 30
4.5. Setting up the application .................................................................................. 33
CHAPTER 5. UPDATING THE ANTI-VIRUS DATABASE ...............................36
Page 4
4 Kaspersky Anti-Virus for Novell NetWare
5.1.
Creating an update task..................................................................................... 37
5.2. Setting up the task ............................................................................................. 38
5.3. Batch task setup................................................................................................. 43
5.4. Starting/stopping a task ..................................................................................... 46
5.5. Deleting a task ................................................................................................... 46
CHAPTER 6. SCANNING THE SERVER FOR VIRUSES ............................... 48
6.1. Creating tasks for Real-Time Protection and On-Demand Scan..................... 49
6.2. Setting up a task ................................................................................................ 51
6.3. Batch task setup................................................................................................. 55
6.4. Starting/stopping a task ..................................................................................... 57
6.5. Deleting a task ................................................................................................... 58
CHAPTER 7. GENERATING AND VIEWING LOGS, RECEIVING
NOTIFICATIONS 60
7.1. Viewing the anti-virus database updating results ............................................. 61
7.2. Viewing the server scanning results.................................................................. 65
7.3. Summarized results of the task execution ........................................................ 70
7.4. Notification regarding detected viruses ............................................................. 72
CHAPTER 8. LICENSE MANAGEMENT .......................................................... 73
8.1. Licensing policy.................................................................................................. 73
8.2. Installing the license key.................................................................................... 76
CHAPTER 9. MANAGING KASPERSKY ANTI-VIRUS USING
KASPERSKY ADMINISTRATION KIT...................................................................... 78
9.1. Managing policies .............................................................................................. 79
9.1.1. Creating a policy ...........................................................................................79
9.1.2. Viewing and editing policy settings............................................................... 86
9.1.2.1. Viewing information about the application .............................................87
9.1.2.2. Viewing policy enforcement results........................................................ 88
9.1.2.3. Configuring event logging settings ......................................................... 89
9.1.2.4. Specifying CPU usage during scans ..................................................... 90
9.1.2.5. Selecting the updating source for the anti-virus database .................... 90
9.1.2.6. Configuring settings for the on-demand scan task................................ 91
9.1.2.7. Selecting actions for the on-demand scan task..................................... 92
9.1.2.8. Configuring settings for the real-time protection task ............................94
9.1.2.9. Selecting actions for the real-time protection task................................. 95
Page 5
Contents 5
9.2.
Managing application settings ........................................................................... 96
9.2.1.1. Viewing the information about the application ....................................... 98
9.2.1.2. Viewing the information about the location of objects ........................... 98
9.2.1.3. Viewing connection settings and CPU usage........................................ 99
9.2.1.4. Viewing information about license keys............................................... 100
9.2.1.5. Viewing information about events ........................................................ 101
9.3. Managing tasks................................................................................................ 102
9.3.1. Configuring specific task settings ............................................................... 104
9.3.1.1. Specifying the settings specific to updating the anti-virus database... 104
9.3.1.2. Configuring specific settings for the on-demand scan and real-time
protection tasks..................................................................................... 106
9.3.1.3. Configuring specific settings for the license key installation task........ 109
9.3.2. Starting and stopping tasks ........................................................................ 110
APPENDIX B. APPLICATION SETTINGS................................................................. 112
B.1. The General Tab............................................................................................... 112
B.2. The Folders Tab................................................................................................ 113
B.3. The Advanced Tab ........................................................................................... 115
B.4. The E-mail Notification tab................................................................................ 116
B.5. The Schedule Tab............................................................................................. 117
B.6. The Task Tab.................................................................................................... 120
APPENDIX C. TASK SETTINGS................................................................................ 122
C.1. The Update Task ..............................................................................................122
C.1.1. The Recipients Tab.................................................................................... 122
C.1.2. The Updating source Tab .......................................................................... 124
C.1.3. The Event log Tab...................................................................................... 129
C.1.4. The Proxy Tab............................................................................................ 131
C.1.5. The Schedule Tab...................................................................................... 133
C.1.6. The E-mail notification tab ......................................................................... 137
C.2. The On-Demand Scan and Real-Time Protection Tasks ...............................139
C.2.1. The Scan settings Tab............................................................................... 139
C.2.1.1. Code analyzer .....................................................................................142
C.2.1.2. Extracting Engine ................................................................................ 142
C.2.1.3. Executable Module Extracting Engine ............................................... 143
C.2.2. The Actions Tab ......................................................................................... 144
Page 6
6 Kaspersky Anti-Virus for Novell NetWare
C.2.3. The Event log Tab...................................................................................... 146
C.2.3.1. Messages regarding infected files ...................................................... 148
C.2.3.2. Messages Regarding Suspicious Files .............................................. 149
C.2.3.3. Warnings ............................................................................................. 150
C.2.3.4. Messages Regarding Packed Executable Files ................................150
C.2.3.5. Messages Regarding Archive Files.................................................... 151
C.2.3.6. Messages Regarding Uninfected Files .............................................. 151
C.2.4. The NW-Notification Tab ........................................................................... 151
C.2.5. The E-mail Notification Tab ....................................................................... 153
C.2.6. The Schedule Tab...................................................................................... 155
APPENDIX D. KASPERSKY LAB............................................................................... 160
Other Kaspersky Lab Products................................................................................ 161
Contact Us ................................................................................................................ 169
Page 7

CHAPTER 1. INTRODUCTION

Kaspersky Anti-Virus 5.7 for Novell NetWare (hereafter, referred to as Kaspersky Anti-Virus) is an anti-virus application designed to protect LAN file servers running the Novell NetWare operating system.
Kaspersky Anti-Virus has the following functions:
Real-time server protection – scans all started or modified files, then disinfects and/or deletes infected objects.
On-demand server scan – successively scans the files on the server on administrator’s demand or according to a schedule with user-specified frequency. The anti-virus application can disinfect and/or delete infected objects.
Anti-virus database updating – updates the anti-virus database used to search for viruses, and distributes the downloaded updates to other servers on the Novell NetWare network. The database can be scheduled for automatic updating. The application will download the latest updates via the Internet or the LAN and distribute these among the specified servers. Prior to updating the anti-virus database on a server the program will back up all the files being modified, thus making it possible to revert to the latest update if necessary.
Quarantine – moves infected or suspicious files to a special storage location called ‘quarantine’. Quarantined files can be analyzed by the administrator or sent to the Kaspersky Lab for examination.
Event log keeping – creates detailed logs and writes the results of the on-demand server scanning, real-time protection and anti-virus database updating. The logs can be viewed and printed.
Backup – saves backup copies of any suspicious or infected files prior to disinfecting or deleting them. This makes it possible to restore the data in the event of disinfection, deletion failure or error.
Notification – notifies users and administrators of finished scans, warns about found dangerous objects using Novell NetWare network and by email.
Kaspersky Anti-Virus is based on the client-server architecture. Its server part consists of two modules: Kaspersky Anti-Virus, dealing with anti-virus functionality, and Anti-virus database updating, responsible for updating the anti-virus database and application modules. The client part consists of Snapin for ConsoleOne, a web module, and a module for managing the application using Kaspersky Administration Kit that provide the user interface for the
Page 8
8 Kaspersky Anti-Virus for Novell NetWare
application administrative services and enable the user to install the application, set it up, and manage the server part.
1.1. What’s new in version 5.7?
Version 5.7 of Kaspersky Anti-Virus for Novell NetWare has the following main difference from the previous version: now Kaspersky Anti-Virus can be managed from a remote location using Kaspersky Administration Kit.
1.2. Hardware and software requirements
Software requirements:
A server with installed Novell NetWare ver. 5.x or 6.0, 6.5.
Installed servlet container (for installing and using the web management
interface).
Viewing the task performance log within a web interface requires the
presence of an installed Novell NetWare client on the computer.
Installed Support Packs:
For Novell NetWare 5.x – Support Pack 6 or higher
For Novell NetWare 6.0.x – Support Pack 3 or higher
Microsoft Internet Explorer 6.0 or higher.
Hardware requirements:
An Intel Pentium processor or higher.
About 12 MB of available (free) RAM.
About 8 MB of free hard-disk space on the server’s volumes.
1.3. Distribution kit
You can purchase Kaspersky Anti-Virus 5.7 for Novell NetWare either from our distributors (retail box) or online at one of our Internet shops (for example,
www.kaspersky.com
The retail box includes:
– select the E-Store link).
Page 9
Introduction 9
A sealed envelope with an installation CD containing files for the software product
User Guide
A license key written on the installation CD
License agreement
Before you unseal the envelope containing the CD, be sure to thoroughly review the license agreement.
If you buy Kaspersky Anti-Virus for Novell NetWare online, you download the installation file of the product from the Kaspersky Lab website. This installation file includes this User Guide and the license key. The license key can also be sent to you by e-mail after receiving your payment.
The License Agreement (LA) is a legal agreement between you and the manufacturer (Kaspersky Lab Ltd.) describing the terms on which you may use the anti-virus product which you have purchased.
Make sure you read the License Agreement!
If you do not agree to the terms of this LA you can return the unused product to your Kaspersky Anti-Virus dealer for a full refund, making sure the envelope containing the CD is sealed.
By unsealing the envelope or installing the program, you agree to all the terms of the LA.
1.4. Help Desk for Registered Users
Kaspersky Lab offers a large service package enabling its registered customers to enjoy all available features of Kaspersky Anti-Virus.
If you register and purchase a subscription you will be provided with the following services for the period of your subscription:
New versions of this anti-virus software product provided free of charge.
Phone or e-mail advice on matters related to the installation,
configuration, and operation of this anti-virus product.
Information about new Kaspersky Lab products and about new computer viruses (for those who subscribe to the Kaspersky Lab newsletter).
Kaspersky Lab does not provide information related to operation and use of your operating system or various other technologies.
Page 10
10 Kaspersky Anti-Virus for Novell NetWare
1.5. Conventions
In this book we use various conventions to emphasize different meaningful parts of the documentation. The table below lists the conventions used in this Guide.
Convention Meaning Bold font
Attention Additional information, notes
Warning!
To perform action:
1. Step 1.
2. …
Task, Example
Menu titles, commands, window titles, dia­log elements, etc.
Critical information
Actions that must be taken
Formulation of the problem or an example of how to use the product.
Page 11
CHAPTER 2. KASPERSKY
ANTI-VIRUS 5.7 FOR NOVELL NETWARE BASICS
2.1. Deploying protection on servers
Building of the file server antiviral protection system using Kaspersky Anti-Virus must begin with installation of Snapin for Novell ConsoleOne and/or the web management module1.
Snapin for ConsoleOne is installed from the distribution package on one of the workstations running Windows or on a NetWare server, where the Novell ConsoleOne network administration utility is installed.
The Web management module is also installed from the distribution package on a Windows workstation or on a NetWare server with the installed Tomcat servlet container.
Snapin for ConsoleOne and the Web module can be installed on only one of the computers as they provide centralized access to all network resources from a single administrator workbench. However, if in the event that several administrators are working jointly, the management modules can be installed on each of their computers.
If none of the modules is installed, the anti-virus functionality of the application will be limited to real-time server protection mode with default settings. Scanning will be launched automatically when starting the server and will be stopped when the server is shut down. Stopping or starting the scanning forcibly will only be possible from the command line by closing or starting the application.
The next step is installation of the server side application on all the NetWare file servers across the network. Kaspersky Anti-Virus and Anti-virus database updating modules can be installed on the server either using the distribution package or without it, by using the Snapin for ConsoleOne or web interface.
1 Hereinafter in this Administrator’s Guide we shall demonstrate the interface of
the Snapin for Novell ConsoleOne. All peculiarities of the web-based interface will be mentioned individually.
Page 12
12 Kaspersky Anti-Virus for Novell NetWare
2.2. Basic concepts and operation scheme of the application
The antiviral protection system is based on creation of tasks, which maximize the
basic functionality of the application.
A task is a specific action performed by the application. Tasks are divided into several types according to their function. Kaspersky Anti-Virus uses three types of task:
Real-time protection
Scan on-demand
Anti-virus database updating
The tasks can be started according to a schedule, manually, or upon an application event. Each task has a corresponding set of parameters that specify how the application will work when running this task.
The set of application parameters common for all its task types makes up the application settings. The application parameters specific to each type of task make up task settings.
Because of the distributed architecture of Kaspersky Anti-Virus, obtaining access to its anti-virus functionality requires starting its server part – Kaspersky Anti- Virus or Anti-virus database updating module – to carry out the update. Updating can be started using the Snapin for Novell ConsoleOne, the web module (see section 4.4 on page 30), or the Kaspersky Administration Kit management module.
In order to initiate execution of the required function, the user must set the application parameters (see section 4.5 on page 33), create the respective task (see section 5.1 on page 37 and section 6.1 on page 49), set its generic parameters (see section 5.2 on page 38 and section 6.2 on page 51) and run this task (see section 5.4 on page 46 and section 6.4 on page 57). If the scheduled start mode or start on event mode is selected, the task is launched automatically.
Access to the application administrative functions, and creation and running of the tasks is granted to the users2 who possess administrator rights. The user rights are checked based on their authentication in the Novell Netware network.
2 In this document, users with administrator rights are referred to as users.
Page 13
Kaspersky Anti-Virus 5.7 for Novell NetWare basics 13
2.3. Maintaining the antiviral protection system
Maintenance of the server antiviral protection system involves the following processes:
Reception and processing of virus detection messages
Regular checking of anti-virus database update reception and distribution
reports
An important factor that determines the quality of infected object detection by anti-virus programs is completeness of their anti-virus database. The procedure of searching and removing viruses is based on the records of the anti-virus database, which stores descriptions of every virus known at the time along with methods of cleaning objects infected by them.
Kaspersky Lab adds descriptions of new viruses to the anti-virus database daily and places the updates on the Internet for downloading. It is recommended to download these updates daily.
The anti-virus database versions must be the same on all the protected servers. In order to save traffic, the update process can be set up in such a way that the anti-virus database updates will be downloaded from the Internet by the “main" server. All the other servers will receive the updates from the shared folder located on the “main” server.
A server can receive updates only from the server located in the same NDS tree. Therefore, it is necessary to create at least one server responsible for updating the anti-virus database in every NDS tree whose servers are to be protected from viruses.
Page 14
CHAPTER 3. INSTALLING,
UPDATING, AND UNINSTALLING THE APPLICATION
Prior to installing Kaspersky Anti-Virus for Novell NetWare please make sure that hardware and software of the server/workstation meets the program’s require­ments. The minimal possible requirements are specified in section 1.1 on page 8.
3.1. Installation from the distribution package
Kaspersky Anti-Virus is installed from a computer running Windows 9x/NT/2000/Me/XP.
To install Kaspersky Anti-Virus,
run the installer (setup.exe) from the CD with the application distribution package.
This will start the installation wizard. Follow its directions. Most of the settings required for installation will be made by default or will be based on the choice you make. Please read carefully the text in each window of the wizard. Make any desired changes if necessary.
A detailed description of the installation steps is provided below.
1. First of all, the license agreement will be displayed. You must accept it in order to proceed with the installation.
2. After that you should select the application components to install (see Figure 1). You can install both the server-side application and the client application simultaneously (full installation) or install the Snapin for ConsoleOne first and then deploy the application via Novell ConsoleOne. To install the server-side application select
Kaspersky Anti-Virus; for the client application select Snapin for ConsoleOne, the Web management module, and / or Kaspersky Network Agent.
Page 15
Installing, updating, and uninstalling the application 15
Figure 1. Selecting the components to install
3. Further installation process depends on the component you want to install.
Kaspersky Anti-Virus for Novell NetWare ( see 3.1.1 on page
16)
Snapin for ConsoleOne
Web management module
Kaspersky Network Agent
4. Next, the files will be copied to the server and the settings will be stored in the NDS.
5. After the wizard successfully completes its work, in the final window (see Figure 2) you will be offered the opportunity to modify the AUTOEXEC.NCF file so as to start the server-side application whenever the server is started. In addition, you will be offered the
Page 16
16 Kaspersky Anti-Virus for Novell NetWare
possibility of loading the server-side application immediately after the application is installed on the server. Enable the necessary checkboxes.
The AUTOEXEC.NCF is modified automatically and does not require additional settings to be made.
Figure 2. The final window of the setup wizard
3.1.1. Installing Kaspersky Anti-Virus for Novell NetWare
To install Kaspersky Anti-Virus for Novell NetWare:
1. Specify servers for the installation (Figure 3). Select the required servers from the list of those currently connected.
Page 17
Installing, updating, and uninstalling the application 17
Figure 3. Selecting servers for the Kaspersky Anti-Virus installation
2. Specify the directories in which to install the components of Kaspersky Anti-Virus 5.6 for Novell NetWare. The server-side application is installed in the SYS/KAV folder. If you are installing the product on only one server, you can specify another destination folder in the volume structure of the server. The group of elements of the component is only displayed if it was selected for installation.
3. In the license key installation window please specify the license key file (*.keys), using which Kaspersky Anti-Virus will check the validity of the license agreement and its deadline (see Figure 5).
Page 18
18 Kaspersky Anti-Virus for Novell NetWare
Figure 4. Installation folders selection
Figure 5. The License Key installation window
Page 19
Installing, updating, and uninstalling the application 19
The license key is your personal “key”, which stores the information required for full-featured operation of the application and some reference information. This information includes:
Support information (who provides it and where it can by ob­tained).
Name, number and the expiration date of the license.
Your license key can be enclosed with the distribution package or sent to you by e-mail after the product is purchased. The program will not run without the key file.
3.1.2. Installing Snapin for Console One
To install Snapin for ConsoleOne,
Select the install folder. The installation directory for Novell ConsoleOne should be Novell ConsoleOne Install folder on the computer from which the application control utility will be started. By default this field contains the server’s directory
SYS\Public\mgmt\ConsoleOne\1.2 of the workstation’s directory \Novell\ConsoleOne\1.2. You can change it.
3.1.3. Installing Web management module
To install the Web management module (iKAV)
1. Specify servers for the installation (Figure 3). Select the required servers from the list of those currently connected.
2. Select the destination folder. By default, the Web management
module (iKAV) is installed in the <server_name >\\SYS\Tomcat\4
directory.
This path is correct if you are running a server version 6.0 or higher.
For a server version 5.x, check the version of Tomcat launched at
startup and specify the path <server_name >\SYS\Tomcat\< Tomcat_version>. The default Tomcat version is 33. The path for this version should be changed to <server_name >\SYS\Tomcat\33.
If you want to install only the web management module, the default
installation directory is C:\Tomcat\4. You can change the path by
Page 20
20 Kaspersky Anti-Virus for Novell NetWare
specifying the Tomcat directory on your local drive or simply copy the module files to the Tomcat directory after the installation.
After installing web management module to Tomcat you need to restart Tomcat
3.1.4. Installing Kaspersky Administration Kit Network Agent
To install Kaspersky Administration Kit Network Agent
1. Specify servers for the installation (Figure 3). Select the required servers from the list of those currently connected.
2. Specify address and port number of the administration server, which works as a central storage for information about Kaspersky Lab applications installed in the network.
Figure 6. Specify address and port number of the administration server
Page 21
Installing, updating, and uninstalling the application 21
3.2. Deploying the application across the network
If the Snapin for Novell ConsoleOne and/or the Web management module are already installed on a computer (server or workstation), then the server-side application can be installed on other servers without using the distribution package. This is done via Novell ConsoleOne or the web module using the Install Kaspersky Anti-Virus shortcut menu command of the NDS console tree.
You can install the server-side application of Kaspersky Anti-Virus on both a server selected in the console tree and several servers at the same time.
To install Kaspersky Anti-Virus on a group of servers:
Select a node in the console tree that contains the required servers and right click your mouse button to open the shortcut menu. In the shortcut menu, select the Install Kaspersky Anti-Virus option. If this option is unavailable in the shortcut menu, Kaspersky Anti-Virus is already installed on all the servers of this node.
During installation, the program will ask you to select the servers on which you want to install Kaspersky Anti-Virus and specify the path to the license key file (see Figure 7). The list of servers available for installation includes only those servers on which Kaspersky Anti-Virus has not been installed. The license key file is selected in the same manner as installation from the distribution package (see section 3.1 on page. 14).
Page 22
22 Kaspersky Anti-Virus for Novell NetWare
Figure 7. Installing the application on a group of servers via Novell ConsoleOne
In order to make the server-side part of the application launch automatically at the server start, update the AUTOEXEC.NCF file by checking the Modify the autoexec.ncf file automatically box.
To install Kaspersky Anti-Virus on one server:
Select a node in the console tree that contains the required servers, open the shortcut menu, and select the Install Kaspersky Anti-Virus option. During installation the program will ask you to specify the directory in which to install the server-side application and the path to the license key file. You will also be prompted to update the AUTOEXEC.NCF configuration file to make the server-side part of the application launch at the server’s start (similarly to These operations are the same as those described above (see section 3.1 on page. 14).
Page 23
Installing, updating, and uninstalling the application 23
3.3. Installing application on cluster volume
If the Snapin for Novell ConsoleOne and/or the Web management module are already installed on a computer (server or workstation), then Kaspersky Anti ­virus can be installed on cluster volume without using the distribution package.
To install Kaspersky Anti-Virus on cluster volume:
1. Run the Web management module or Snapin for Novell Con-
soleOne.
2. Select a node in the console tree that contains the required cluster volume, open the shortcut menu, and select the Install Kaspersky Anti-Virus option.
3. During installation the program will ask you to specify the directory in which to install the server-side application (SYS/KLAB by default ) and the path to the license key file. You can install the license key via ConsoleOne after the application is installed.
After installing the application on cluster volume you are not recommended to modify AUTOEXEC.NCF. This can lead to application failure!
Click Install button to install the application.
The install process will start, it is similar to one described in 3.1.1 on page. 16
To enable automatic load of server scripts, add the following lines to the beginning of startup scripts:
SEARCH ADD SYS:/KLAB LOAD KLABAV.NLM KAVSCH5.NCF
To enable automatic shut down of server scripts on system shut down, add the following lines to the ending of shutdown scripts:
UNLOAD KLABAV.NLM UKAVSCH5.NCF
Page 24
24 Kaspersky Anti-Virus for Novell NetWare
3.4. Uninstalling the application
Uninstalling Kaspersky Anti-Virus means removing the application’s server part from the file servers and removing its client part from the computers on which it was installed (see section 3.1 on page. 14).
The application’s server part can be uninstalled from the file server selected in the NDS structure via Novell ConsoleOne using the Remove Kaspersky Anti- Virus command in the shortcut menu of the console tree. You will be asked to confirm that you really want to uninstall the application. After the last installed server part is removed, the NDS structure will be cleared – the Kaspersky Anti- Virus 5 class and all its attributes will be deleted.
To uninstall the client part, Snapin for ConsoleOne and/or Web management module, it must be removed from the computer on which it is installed (see section 3.1 on page 14) using the available file manager. The following files and directories must be removed from the Novell ConsoleOne installation directory:
For the Snapin for ConsoleOne:
kav500.jar file from the snapins\mach directory;
kavResource500.jar file from the resources\mach directory;
InstallAVP subdirectory from the jre directory;
KasperskyAV subdirectory from the help directory
For the Web management module:
For version tomcat 33: the tomcat\33\webapps\ikav directory
and the ikav.war file, the tomcat\33\work\default directory;
For version tomcat 4:
the tomcat\4\work\standalone\localhost\iKAV directory.
3.5. Updating the application version
In order to upgrade Kaspersky Anti-Virus from version 4.0 to 5.7, you must first uninstall version 4.0 and install the new version, according to the instructions contained in this document (see section 3.1 on page 14).
To update the application from version 5.х to version 5.7, do the following:
1. Install one of the management modules, either for ConsoleOne or the web module;
2. In the Kaspersky Anti-Virus 5 namespace, select a server on which you want to upgrade the application version;
Page 25
Installing, updating, and uninstalling the application 25
3. Open the shortcut menu and select the Update Kaspersky Anti­Virus option.
After this, all previous settings will be saved and the current license key will be applied to the new version of Kaspersky Anti-Virus.
Kaspersky Anti-Virus for Novell NetWare supports the anti-virus database formats used in the previous versions of the program.
After software update from version 5.х to 5.7 on the server, you will have to update the program on all servers included into the list for distribution of updates. Otherwise updating of the anti-virus databases on those computers will become impossible.
Page 26
CHAPTER 4. SETTING UP THE
APPLICATION
4.1. Starting the application
The application is launched, set up, and controlled using Novell ConsoleOne, the web interface, or Kaspersky Administration Kit.
To start the application from ConsoleOne
Run this utility on your computer.
1. To launch the application from the web interface:
2. Open your web browser.
3. In the address bar, enter the following address:
http://Server IP Address/iKAV
where:
Server IP address is the address of the server on which the Web
management module is installed;
port is the port on the server (default port is 8080).
Attention! Commands in tomcat version 4 are case sensitive.
4. On the authorization page that opens, enter the required data.
To launch the application using Kaspersky Administration Kit
Start Kaspersky Administration Kit on your computer.
4.2. Application interface
Hereinafter, all instructions and explanations are based on the interface of Snapin for ConsoleOne. All differences between the Snapin for ConsoleOne and Web module will be discussed separately. See Chapter 9 on page 78 about managing Kaspersky Anti-Virus using Kaspersky Administration Kit.
Page 27
Setting up the application 27
The main window of Novell ConsoleOne contains the menu, the control panel, the review panel and the results panel (see Figure 8). The menu provides the functions for controlling files and windows, and provides access to the help system. The set of buttons on the tools panel provides direct access to some of the most frequently used main menu items. The review panel displays, in a console tree form, the name spaces installed in Novell ConsoleOne. The result panel displays the list of elements of the object selected in the tree.
After installing the Snapin for Novell ConsoleOne, a Kaspersky Anti-Virus 5
name space is created in the console tree. It is marked by the
icon.
Figure 8. Novell ConsoleOne window after installation of the Snapin
This space contains the list of NDS trees with which connection is established.
Each tree is marked with the
icon and displays the hierarchy of its servers
with an indication of their context. The servers that have no server part installed
are marked with the icon.
The servers on which the Kaspersky Anti-Virus module is installed are marked
with the
symbol and contain the list of task types of Kaspersky Anti-Virus:
Real-Time Protection
On-Demand Scan
Page 28
28 Kaspersky Anti-Virus for Novell NetWare
Anti-Virus Database Updating
In turn, for each task type a list of created tasks is provided. If the task is being executed its icon is colored, otherwise it is black and white.
The umbrella icon becomes gray if Kaspersky Anti-Virus module is not running on the server. When the module is started, this icon becomes green.
Each object category in the Kaspersky Anti-Virus 5 name space has its own shortcut menu. In addition to Novell ConsoleOne standard menu commands, it contains several others that can be used for setting up and controlling the application. The list of objects and their respective shortcut menu commands are shown in the table below.
Object Command Function
Load/Unload Kaspersky Anti-Virus
Starts / Stops Kaspersky Anti­Virus module on the server.
Server
Container
Task type
Task
Install Kaspersky Anti­Virus / Uninstall Kasper­sky Anti-Virus
View Event Log
View statistics
Properties
Register license key
Install/Uninstall Kasper­sky Anti-Virus Create task
Delete all tasks Start task / Stop task
Delete task
Installs the program on the server / Removes the program from the server.
Displays the event log that keeps data on the tasks per­formed on the server.
Displays the general statistics on the tasks performed on the server.
Opens the application set-up window.
Installs the license key for the application (only for the web interface). Installs / Uninstalls Kaspersky Anti-Virus module on the server Creates a task.
Deletes all the tasks of this type. Starts the task / Stops the task.
Deletes the task.
Page 29
Setting up the application 29
Object Command Function
View log
Opens the report window with the data regarding the object and the actions taken with it.
Properties
Load/Unload anti-virus database updating mod­ule
Opens the task set-up window.
Start/stop the Anti-Virus data- base updating module on the server.
4.3. Default protection of the server
Antiviral protection of the server begins immediately after installing Kaspersky Anti-Virus, upon launching the program on the server for the first time.
As a result of the installation, two tasks are created on the server: a real-time protection task named Real-Time Protection, and an on-demand scan task named On Demand Scan.
The Real-Time Protection task starts automatically together with the server part of the program. For a more detailed check of the server the administrator can run the On-Demand Scan task.
The Real-Time Protection and On-Demand Scan tasks are created automatically with the optimal default settings recommended by Kaspersky Lab’s experts.
The Real-Time Protection task runs with the following settings:
Start at the Kaspersky Anti-Virus start.
Scan all the volumes of the server.
All the files that can potentially be infected are to be analyzed when
they are opened for reading, writing, and execution.
Use heuristic code analyzer.
Do not scan:
The directory containing application event log files.
Archives and mail format files.
Upon detection of an infected object the application attempts to disinfect
it. If disinfection is impossible it outputs an appropriate message to the report.
Page 30
30 Kaspersky Anti-Virus for Novell NetWare
If a suspicious object is detected, the application places it under quarantine.
The On-demand Scan task can be started with the following settings:
Scan all volumes of the server.
Scan all files.
Scan archives and packed files, mail files in text format, and mail
databases.
Use the heuristic code analyzer.
Upon detection of an infected object the application attempts to disinfect
it. If disinfection is impossible it outputs an appropriate message to the report.
If a suspicious object is detected, the application places it under quarantine.
Use heuristic code analyzer.
The above settings are also applied when the administrator creates a task using the Default template.
4.4. Starting/stopping the application on the server
The server part of Kaspersky Anti-Virus and Anti-virus database updating modules is started and stopped on the server from a workstation or a server on which the Snapin for Novell ConsoleOne or the web management module is installed.
The user can start/stop the modules using the shortcut menu in the left panel of Novell ConsoleOne window.
In order to start the Kaspersky Anti-Virus module on the server,
select the required server in Kaspersky Anti-Virus 5 name space in the console tree. Open the shortcut menu and select the Load Kaspersky Anti-Virus option.
This will initiate checking of whether the number of running modules of Kaspersky Anti-Virus matches the number of registered license agreements. If the user attempts to run a module in excess of the number allowed by the registered license agreements or such an agreement is not registered at all, a warning will by displayed on the respective server and the module will not start.
Page 31
Setting up the application 31
If the numbers match, the application kernel – the KAV.NLM module, the antiviral engine – KAVSCAN.NLM and the anti-virus database will be loaded to the server’s memory. The program kernel controls the antiviral functions of the application, while the antiviral engine scans files for viruses. The antiviral engine is loaded to the protected address space. More than one antiviral engine may be running at the same time. The number of concurrently executed file scan requests depends upon the number of simultaneously running copies of the antiviral engine. By default, there are two copies running at the same time. The user can change this value in the application settings on the Advanced tab (see section A.3 on page 115), or load additional antiviral engine copies manually from the server command line (see below).
As a result, Kaspersky Anti-Virus module will be started on the server selected in the console tree. After the module starts, the real-time scanning and scan on demand tasks will be started if they are configured to run at application startup on the server.
After the Kaspersky Anti-Virus module is started on the server, separate screens display general statistical information on the module operation and individual information on every active task. The first screen is created when the module is started; it contains information about the application and statistical information regarding the module execution (see Figure 9). When a server scanning task is launched, a new screen is created. The screen name matches that of the task and it displays the task settings and its execution statistics (see Figure 10). After the task is completed the screen is removed.
Figure 9. Server screen when the Kaspersky Anti-Virus module is started
Page 32
32 Kaspersky Anti-Virus for Novell NetWare
Figure 10. Server screen during execution of the real-time protection task
Similar information is represented in the results pane when the user selects the server running the Kaspersky Anti-Virus module in the console tree (see Figure 8).
To stop the Kaspersky Anti-Virus module on the server:
Select the required server in Kaspersky Anti-Virus 5 name space in the console tree. Open the shortcut menu and select the Unload Kaspersky Anti-Virus command.
Moreover, you can start / stop the Kaspersky Anti-Virus module on the General tab in the application parameters setup window using the Load Kaspersky Anti- Virus / Unload Kaspersky Anti-Virus buttons (see section A.1 on page 112).
The web interface has no General tab. To start / stop the application through the web interface, select the Load / Unload Kaspersky Anti-Virus options in the shortcut menu. To open the shortcut menu, click your right mouse button on the server name in the NDS tree.
To start/stop the Anti-virus database updating module on the server:
Select the required server in the Kaspersky Anti-Virus 5 name space in the console tree. Select the Anti-Virus Database Updates task type. Call the shortcut menu and run the Load / Unload anti-virus database updating module command.
As a result, the Anti-virus database updating module will be started / stopped on the server selected in the console tree.
Page 33

Setting up the application 33

You can start / stop the Kaspersky Anti-Virus and Anti-virus database updating modules, and load / unload additional antiviral engines directly from
the server command line using the following commands:
LOAD SYS:\KAV\KAV.NLM – start Kaspersky Anti-Virus module
KAVSCH5/.NCF – start Anti-virus database updating module
UNLOAD KAV.NLM – stop Kaspersky Anti-Virus module
UKAVSCH5.NCF – stop Anti-virus database updating module
LOAD ADDRESS SPASE=KAV(N) RESTART
SYS:\KAV\KAVSCAN.NLM – load additional N
UNLOAD ADDRESS SPASE=KAV(N) – unload additional N
th
antiviral engine
th
anti-
viral engine.
4.5. Setting up the application
After installation, Kaspersky Anti-Virus begins working with the minimal number of settings, most of which are set by default.
We recommend that after starting the application you familiarize yourself with its options and, if necessary, change the settings as required. These parameters are common for all the task types of this server and cannot be changed at the moment of creating a task.
The application is set up from a workstation or a server on which the Snapin for Novell ConsoleOne or the Web management module is installed. Individual windows are used for each server. This operation can be carried out regardless of whether the application is running on the server or not.
To open the application setup window,
select the required server in Kaspersky Anti-Virus 5 name space in the console tree. Open the shortcut menu and select the Properties… item.
The Kaspersky Anti-Virus 5.7 on <server name> window will be displayed (see Figure 11). The tabs are described in detail in Appendix A on p.112.
Page 34
34 Kaspersky Anti-Virus for Novell NetWare
Figure 11. The Kaspersky Anti-Virus 5.6 on <Server name> window.
The General tab
On the General tab (see Figure 11) you can view general information about the Kaspersky Anti-Virus module, start/stop the program on the server, or renew the license agreement (for more details please refer to section A.1 on page 112).
This tab is unavailable in the Web management module. You can view this information (except for registering the license key and unloading Kaspersky Anti­Virus) on the server information page displayed in the left pane when a specific server is selected in the console tree.
The Folders tab displays information regarding the location of the following directories used by the application (for more details please refer to section A.2 on page 113):
The directory in which the current and the previous versions of the anti­virus database are stored.
Quarantine directories for infected files and suspicious objects.
Work directory for storing temporary files.
The directory for storing anti-virus database updates.
Page 35
Setting up the application 35
On the Advanced tab the user can specify the parameters of connection between the Snapin for ConsoleOne and the server on which the module of Kaspersky Anti-Virus being set up is installed, the parameters of connection with the anti-virus database update server, allowable server’s resources usage for the Kaspersky Anti-Virus module, and the number of file scan requests simultaneously processed by the server (the number of concurrently scanned connections) (for more details please refer to section A.3 on page 115).
On the E-mail notification tab you must specify the parameters of connection between the Snapin for ConsoleOne and the mail server. These parameters will be used for sending e-mail notifications and providing sender address. As a sender address, use an email address registered on your mail server (for more details, refer to section A.4 on page 116).
The Schedule tab displays a complete schedule of unattended startups for all the tasks created for the server. The tasks are viewed by their type. The user can choose to view either the server scanning tasks startup schedule (both scan by demand and real-time protection), or the update tasks. The user can change any of the elements of the schedule (for more details please refer to section A.4 on page 116).
The Task tab displays a full list of the tasks created for the server. The tasks are viewed by their type. The user can choose to review either the server scanning tasks (both scan by demand and Real-Time Protection), or the updating tasks. You can change the settings for any task, delete tasks, create new ones, and review the log with the results of any task execution. In addition you can carry out batch setup of the task parameters (for more details please refer to section A.6 on page 120).
Page 36
CHAPTER 5. UPDATING THE
ANTI-VIRUS DATABASE
The procedure of searching out and removing viruses is based on the records of the anti-virus database, which contains descriptions of every virus known at the time, along with methods of cleaning the files infected by them.
Keeping the database up-to-date is of the utmost importance since new viruses appear every day. We recommend that you update the anti-virus database immediately after installing the application since the database included in the distribution package will be outdated from the moment you install the program. In Kaspersky Anti-Virus 5.6 for Novell NetWare, the anti-virus database is updated by creating and running the update tasks.
The Anti-virus database updating module deals with database updating. It is included in the application’s server part. When executing the update task the server connects to the Internet or to a shared directory at the scheduled time, downloads the anti-virus database updates, and saves them in a special directory. Then the updates are distributed to the servers included in the mailing list and saved in the directories for storing the used anti-virus database. Backup copies of all the updated objects are created.
Prior to updating the anti-virus database, the updater automatically creates a backup copy of all data from the directory containing received updates. The copy will be placed in the special Backup directory so that the last update can be rolled back, if necessary.
To do this, the user must copy the anti-virus database from the back-up directory (the default location is SYS:\KAV\BASES\BACKUP) to the current database location (the default directory is SYS:\KAV\BASES)
To ensure that the server that executes the update task updates its own anti­virus database it must be included in the mailing list along with the other servers.
To ensure the server is able to save the anti-virus database in the directories of the servers it updates, it must have access rights for the file systems of these servers.
All the tasks can be started either manually at the user's (administrator’s) request, or using the scheduler. The task scheduler allows tasks to be started at any desired time and also allows the duration of the task execution to be specified. Executing the tasks requires Kaspersky Anti-Virus or Anti-virus database updating module to be running on the server.
Page 37
Updating the anti-virus database 37
After the tasks are completed, the user can review the anti-virus database update log.
5.1. Creating an update task
To create a new task for updating the anti-virus database on the server, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server which will execute the anti-virus database update.
2. Expand the task types list and select Anti-virus Database Updates.
3. Open the shortcut menu and select the Create the task item.
4. The Create Task dialog window (see Figure 12) will display the following information about the task to be created:
Task name – the name of the task, which will be used to represent it in the list of created tasks of this type. If necessary, enter the name manually. It must be unique within this server.
Task type – the type of task. The set value is Anti-Virus Database Updates, and it is detected automatically depending
on your selection.
Template – the template for creating the task. You can create tasks by example, selecting a previously created task from the list as a template. In this case, the parameter values set for the new task will be exactly the same as those set in the template task. To create a task with the default parameters use the Default template.
5. When you have finished making changes, click on the ОК button.
As a result, the Anti-Virus Database Updates task will be assigned to the selected server. The name of this new task specified in the Task name field will appear in the list of tasks assigned to this server. After this, you must set the task parameters.
The task can be created regardless of whether the Anti-virus database updating module is running on the server or not.
Page 38
38 Kaspersky Anti-Virus for Novell NetWare
Figure 12. Creating the anti-virus database update task
A task can also be created using the application setup window Kaspersky Anti- Virus on <Server name>.
To create a new update task in the application setup window, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server which will execute the anti-virus database update. Open the shortcut menu and select the Properties item.
2. In the next window Kaspersky Anti-Virus on <Server name> select the Task tab (see Figure 14).
3. Select Anti-virus database updating task as the tasks view mode.
4. Click on the Create button located in the group of buttons on the right.
5. Make the desired settings (as described above) in the dialog window Create Task (see Figure 12) that will open, and click on the ОК button.
As a result, a new element will appear in the tasks list with the name specified in the Task name field. After you close the application setup window this task will appear in the Anti-Virus Database Updates task list in the console tree. Now you need to set up the task.
5.2. Setting up the task
The parameters that the application will use when executing a task depend on the task settings. The task settings can be changed regardless of whether the Anti-virus database updating module is running on the server or not.
Page 39
Updating the anti-virus database 39
To set up the update task parameters, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server which will execute the anti-virus database update.
2. Open the task types list and select Anti-Virus Database Updates. Open the list of created update tasks and select the one for which you want to set up parameters.
3. Open the shortcut menu and select the Properties item.
This will open the task properties window Anti-virus database updating (<Server name>):<Task name> (see Figure 13). Please familiarize yourself with the information provided on the tabs and change or add to it if necessary.
Figure 13. Setting up the Anti-virus database updating task.
The Recipients tab
First of all you need to create a list of servers to which the notifications will be sent during execution of the task. The list is created on the Recipients tab using the buttons Add and Delete (see Figure 13). After that, you should check if the server you create the task for has the rights to access the file systems of the servers you have specified. If there is a ‘no’ value in the Rights column in the
Page 40
40 Kaspersky Anti-Virus for Novell NetWare
mailing list table, it means there are no rights for the respective server. The rights can be granted using the Add rights button (for more details please refer to section B.1.1 on page 122).
After that switch to the Updating source tab and set the update receiving parameters: (for more details please refer to section B.1.2 on page 124):
Updating source – from the Internet, LAN resources, or using
Kaspersky Administration Kit. If you update the database via the Internet, the dialog box will display a list of HTTP and FTP servers of Kaspersky Lab. If you push updates from a network resource, a list of shared directories will be displayed. If you select Kaspersky Administration Kit as an updating source, the anti-virus database will be updated from the Administration Server of Kaspersky Administration Kit.
In case of disconnection from the main source of updates, three more attempts will be made within the 15-minute interval (the next attempt is made in the event that the previous connection fails). Using the Schedule tab you can change the number of repeated attempts to connect with the source, and the interval. During each attempt to connect, the list of update source addresses is used from the beginning (the main address). The addresses are tried in sequence until the connection is established or the list of addresses is exhausted.
Updates copying mode – specifies what files will be downloaded from
the update source; all the anti-virus databases available from the source or only the new and changed ones.
If you have selected an Internet server as a source of the updates and plan to use a proxy server to connect to the ISP, you will have to set up its parameters on the Proxy tab (for more details please refer to section B.1.4 on page 131).
Then go to the Schedule tab and schedule the unattended start of the task and set the reconnection parameters in the event of disconnection during the updates downloading (for more details please refer to section B.1.5 on page 133).
On the Event log tab you can specify the name and the location of the log file, which will contain detailed information about the results of the task execution. In addition, you can set the log file size and specify the events to be logged (for more details please refer to section B.1.3 on page 129).
On the E-mail notification tab, you can enable notifications about task completion for a specified group of users. The program uses the mail system installed in the network to deliver its notifications.
To make your settings come into effect, use the Apply button located in the lower part of the dialog window Anti-virus database updating (<Server
Page 41
Updating the anti-virus database 41
name>):<Task name> or click OK to save changes and close the dialog box. To close the dialog box without saving recent changes, click Cancel.
The task settings can also be changed in the application setup window Kaspersky Anti-Virus on <Server name>.
To set up the task in the application setup window, do the following:
1. Select the required server in the Kaspersky Anti-Virus 5 name space in the console tree. Open the shortcut menu and select the Properties item.
2. In the next window, Kaspersky Anti-Virus on <Server name> select the Task tab (see Figure 14).
Figure 14. The Kaspersky Anti-Virus on <Server name> window.
The Task tab
3. Select Anti-virus database updating task as the tasks view mode.
4. In the task list, select the task you wish to set up. Click Edit in the group of buttons on the right.
Page 42
42 Kaspersky Anti-Virus for Novell NetWare
5. This will open the Change task settings window (see Figure 15) with the tabs: Recipients, Updating source, Proxy, Event log and E-mail notification. These tabs are exactly the same as those in the task setup window Anti-virus database updating (<Server
name>): <Task name>. Make all the desired changes and click on Apply or OK to save the settings.
Figure 15. The Change task settings window. Event log tab
6. Now it is necessary to schedule the task start. In the window,
Kaspersky Anti-Virus 5.7 on <Server name> select the Schedule tab.
7. Select Anti-virus database updating task schedule as the tasks view mode. Click on the Add button at the right side of the schedule.
8. In the Create new schedule for the task dialog box (see Figure 16) select the task you want to schedule and specify the parameters of its start (for more details please refer to section A.4 on page 116). The task is selected from the list in the left part of the
Page 43
Updating the anti-virus database 43
window. The schedule parameter setting procedure is exactly the same as the one described above. After finishing, click OK.
Figure 16. The Create new schedule for the task dialog box
5.3. Batch task setup
You can make identical settings for a group of tasks using the batch setup option. In this case, one of the tasks serves as a basis. If necessary, its settings can be modified.
To carry out batch setting of update tasks, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server whose tasks you wish to set up. Open the shortcut menu and select the Properties item.
2. In the next window, Kaspersky Anti-Virus on <Server name> select the Task tab.
3. Select Anti-virus database updating task as the tasks view mode.
Page 44
44 Kaspersky Anti-Virus for Novell NetWare
4. In the task list select the group of tasks you wish to set up (see Figure 17). Click on the Edit button located in the group of buttons on the right.
Figure 17. Selecting a group of tasks to set up
5. In Select task template window that will open (see Figure 18) select the task to use as a basis from the list of tasks you have included in the batch. Click OK.
Page 45
Updating the anti-virus database 45
Figure 18. The Select task template window
6. This will open the Edit window (see Figure 19). Using the tabs in this window, you can customize settings for the task selected in the previous window. To apply these settings to the whole batch of tasks check the Save group settings checkbox in the lower part of the window on each of the tabs.
In Web management module to perform group settings you need to check the box on settings tab header.
After this, those fields on the tabs become available for editing, and their values can be set the same for the whole batch of tasks. Make the desired changes and click on Apply or OK to save the settings.
As a result, the settings you have made will be saved for the whole batch of tasks. A common log will be shared by these tasks. You can change the tasks schedule on the Schedule tab individually for each task.
Figure 19. The Change task settings window. Batch task setup
Page 46
46 Kaspersky Anti-Virus for Novell NetWare
5.4. Starting/stopping a task
Tasks can be started and stopped automatically according to the scheduler settings, or manually, using the Snapin for Novell ConsoleOne, the Web management module, or Kaspersky Administration Kit.
The update tasks can only be started when the Anti-virus database updating module is running on the server. If the module is stopped, all the running update tasks are cancelled.
To start an update task manually, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server that you wish to scan.
2. Open the task types list and select Anti-Virus Database Updates.
3. Expand the list of the created tasks and select the task to start.
4. Open the shortcut menu and select the Start task item.
If the Start task item is not available check that the Anti-virus database updating module is running on the server.
The tasks are completed automatically after the updates are sent to the specified servers or after executing the preset number of attempts to reconnect to the anti­virus database source.
In addition you can stop the task manually before its execution is complete.
To stop a task manually, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server you wish to stop scanning.
2. Expand the task types list and select Anti-Virus Database Updates.
3. Expand the list of the created tasks and select the task to stop.
4. Open the shortcut menu and select the Stop task item.
5.5. Deleting a task
To delete a task, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server to which the task you wish to delete relates.
Page 47
Updating the anti-virus database 47
2. Expand the task types list and select Anti-Virus Database Updates.
3. Expand the list of the created tasks and select the task to delete.
4. Open the shortcut menu and select the Delete task item.
You can delete a task regardless of whether the Anti-virus database updating module is running on the server or not and whether the task is being executed or not.
It is also possible to delete a batch of tasks.
To delete all the update tasks, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server to which the task you wish to delete relates.
2. Expand the task types list and select Anti-Virus Database Updates.
3. Open the shortcut menu and select the Delete all tasks item.
A task can also be deleted using the application setup window Kaspersky Anti- Virus on <Server name>.
To delete an update task from the application setup window, do the following:
1. Select the required server in the Kaspersky Anti-Virus 5 name space in the console tree. Call the shortcut menu and select the Properties item.
2. In the next window, Kaspersky Anti-Virus on <Server name> select the Task tab.
3. Select Anti-virus database updating task as the tasks view mode.
4. In the task list select the task you wish to delete. Click Delete in the group of buttons on the right. Click Yes in the next window to confirm deletion.
As a result, the task is removed from the list. After the window is closed with the OK button, the task is deleted from the update task list in the console tree.
Page 48
CHAPTER 6. SCANNING THE
SERVER FOR VIRUSES
The server can be scanned for viruses by creating and running two types of task:
Real-Time Protection
On-Demand Scan
The Real-Time Protection task is unattended real-time scanning (‘on-the-fly’ scanning) of all the files on the server accessed by other workstations and servers. The files are scanned prior to their opening/starting, thus preventing infected files from being started or copied. In addition, the files are scanned immediately after they are modified. Only one task of the server’s Real-Time Protection can be executed at a time. simultaneously with Kaspersky Anti-Virus module startup and shut down on the server.
A Real-Time Protection task running on the server slows down its performance slightly. Therefore, it is not recommended to enable archive unpacking mechanism for this type of task.
During scanning on demand, the program scans the directory tree of the selected volumes on the server and virus checks the files specified in the settings. This type of task is intended for scheduled inspections of the server. More than one scanning task with different settings can be executed at the same time.
All the tasks can be started either manually or automatically, using the scheduler. The scheduler allows tasks to be started either according to the schedule or upon an event (e.g. after an application start). You can also set the duration of task execution.
If, during scanning the server (as part of Real-Time Protection or on demand), the program detects infected or suspicious files (detected using the heuristic code analyzer) it will undertake actions specified by the administrator in the task settings.
After the tasks are completed, the user can review the server scanning log.
It can be set up to be started and stopped
Page 49
Scanning the server for viruses 49
6.1. Creating tasks for R eal-Time Protection and On-Demand Scan
In order to create a new Real-Time Protection / On-demand Scan task for the server, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server you wish to scan.
2. Expand the task types list and select On-Demand Scan / Real- Time Protection.
3. Open the shortcut menu and select the Create task item.
4. The Create Task dialog box (see Figure 20) displays the following information about the task to be created:
Task name – the name of the task. This name will be used to represent the task in the list of created tasks of this type. If necessary, enter the name manually. It must be unique within this server.
Task type – the type of the task. The set value is Real-Time Protection / On-Demand Scan. It is detected automatically
based on your selection.
Template – the template for task creation. You can create tasks by example, by selecting a previously created task from the list as a template. In this case the parameter values set for the new task will be exactly the same as those set in the template task. To create a task with the default parameters use the Default template.
5. When you have finished making changes, click the ОК button.
As a result, the list of tasks of the server you have selected will have a new element. Its name is the one you have specified in the Task name field. Now you must set the task parameters.
A task can be created regardless of whether the program is running on the server or not.
Page 50
50 Kaspersky Anti-Virus for Novell NetWare
Figure 20. Creating a Real-Time Protection Task
A task can also be created using the Kaspersky Anti-Virus on <Server name> application setup window.
1. In order to create a new Real-Time Protection / On-Demand Scan task for the server in the application setup window, do the following:
2. Select the required server in the Kaspersky Anti-Virus 5 name space in the console tree. Open the shortcut menu and select the Properties item.
3. In the next window, Kaspersky Anti-Virus on <Server name>, select the Task tab.
4. Select the mode for reviewing the Real-Time Protection and On­demand Scan tasks – On-demand scan and real-time protection tasks.
5. Click on the Create button located in the group of buttons on the right.
6. Make the desired settings (as described above) in the dialog window Create Task (see Figure 20) that opens and then click on the ОК button.
As a result, a new element will appear in the tasks list with the name specified in the Task name field. After the application setup window is closed with the OK button, the newly created task will appear in the re­spective task type list in the console tree. Now you need to set up the task.
Page 51
Scanning the server for viruses 51
6.2. Setting up a task
The parameters that the application will use when executing a task depend on the task settings. Task parameters can be set up regardless of whether the program is running on the server or not.
To set up the update task parameters, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server that you wish to scan.
2. Expand the task types list and select On-demand Scan/ Real- Time Protection.
3. Open the list of the created tasks of the desired type and select the one for which you want to set up parameters.
4. Open the shortcut menu and select the Properties item.
This will open the task properties window On-Demand Scan (<Server name>): <Task name> / Real-Time Protection (<Server name>): <Task name>. This window has several tabs (see Figure 21), each containing parameters related to a certain part of the application’s functions. The values of most of the parameters are set automatically or depending on the values stored in the template task. Please familiarize yourself with the information provided on the tabs and change or add to it if necessary.
You can take the following actions:
Specify regions for scanning, file types to be scanned, regions to be excluded from scanning, and activate advanced scanning modes, namely: scan by wildcard, archive scanning, packed executables scanning and use of heuristic code analyzer. This can be done on the Scan settings tab (see Figure 21) (for more details please refer to section B.2.1below
139).
Specify actions to be applied to infected or suspicious files if these detected, as well as actions to be applied to a workstation that attempts to store an infected object on the server. This can be done on the Actions tab (for more details please refer to section B.2.2below 144).
Specify the location of the log file that will contain detailed information about the results of the task execution, set the log file size and specify the events to be logged. This can be done on the Event log tab (for more details please refer to section B.2.3 on page 146).
Page 52
52 Kaspersky Anti-Virus for Novell NetWare
Figure 21. Setting up the Real-Time Protection task.
The Scan settings tab
Set the notification mode to alert the administrator and network users about detected viruses and specify the messages to be sent out. Use the NW-Notification tab to configure notifications sent using the Novell NetWare messaging tools (for more details please refer to section B.2.4 on page 151). Use the E-mail notification tab to configure settings for sending notifications using your mail system (for more details, see section B.2.5 on page 153).
Schedule unattended starts of the task and specify how long they will run. This can be done on the Schedule tab (for more details please refer to section B.2.6 on page 155).
To make your settings come into force, click the Apply button or save changes and close the window using the OK button. To close the window without saving changes, click Cancel.
The task settings can also be made in the application setup window Kaspersky Anti-Virus on <Server name>.
Page 53
Scanning the server for viruses 53
To set up the task in the application setup window, do the following:
1. Select the required server in the Kaspersky Anti-Virus 5 name space in the console tree. Open the shortcut menu and select the Properties item.
2. In the new window, Kaspersky Anti-Virus on <Server name>, select the Task tab (see Figure 14).
3. Select the mode for reviewing the Real-Time Protection and On­demand Scan tasks – On-demand scan and real-time protection tasks.
4. In the list of tasks created for the server select the one you wish to set up. Click on the Edit button located in the group of buttons on the right.
5. This will open the Edit window (see Figure 22), with the tabs: Scan
settings, Actions, Event log, NW-notification and E-mail notification. These tabs are exactly the same as those in the task
setup window On-Demand Scan (<Server name>):<Task name> / Real-Time Protection (<Server name>):<Task name>. Make all the desired changes and click on Apply or OK to save the settings.
6. Now it is necessary to schedule the task start. In the window
Kaspersky Anti-Virus 5.6 on <Server name> select the Schedule tab.
7. Select the mode for reviewing the Real-Time Protection and On­demand Scan tasks – On-demand scan and real-time protection task schedule.
8. Click on the Add button at the right side of the schedule.
9. In the Create new schedule for the task (see Figure 23) dialog box select the task you want to schedule and specify the parameters of its start (see section A.4 on page 116). The task is selected from the list in the left part of the window. The start parameters setting procedure is exactly the same as the one described above. After finishing, click OK.
Page 54
54 Kaspersky Anti-Virus for Novell NetWare
Figure 22. The Scan settings tab of the Change task settings window
Page 55
Scanning the server for viruses 55
Figure 23. The Create new schedule for the task window. Scheduling the task to run
every week
6.3. Batch task setup
You can make identical settings for a group of tasks using the batch setup option. In this case, one of the tasks serves as a basis. If necessary, its settings can be modified.
To carry out batch task setting, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server whose tasks you wish to set up. Open the shortcut menu and select the Properties item.
2. In the next window, Kaspersky Anti-Virus on <Server name>, select the Task tab (see Figure 14).
3. Select the mode for reviewing the Real-Time Protection and On­demand Scan tasks – On-demand scan and real-time protection tasks.
4. In the list of tasks created for the server select the group of tasks you wish to set up. The selection is made in a standard way, by
Page 56
56 Kaspersky Anti-Virus for Novell NetWare
pressing the <S
HIFT+CTRL> keys. Click Edit in the group of buttons
on the right.
5. In Select task template window that will open (see Figure 24) select the task to use as a basis from the list of tasks you have included in the batch. Click OK.
Figure 24. The Select task template window
6. This will open the Change task settings window (see Figure 25), the tabs of which contain the settings of the task selected in the previous window. To apply these settings to the whole batch of tasks from the Snapin for ConsoleOne, check the Save checkbox in the lower part of window on each of the tabs. If you are using the web management interface, check the box located near the name of the relevant tab.
After this, the fields on the tabs become available for editing and their values can be set the same for this batch of tasks. Make the desired changes and click on Apply or OK to save the settings.
Page 57
Scanning the server for viruses 57
Figure 25. The Change task settings window. Batch task setting
As a result, the settings you have made will be saved for the whole batch of tasks. A common log will be shared by these tasks. You can change the tasks schedule on the Schedule tab individually for each task (see section A.4 on page 116).
6.4. Starting/stopping a task
Tasks can be started and stopped automatically according to the scheduler settings, or manually, using the Snapin for Novell ConsoleOne, web interface, or Kaspersky Administration Kit.
A task can be started only if the application is running on the server. If the server is stopped, all the tasks are cancelled.
In order to start scanning the server for viruses manually, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server that you wish to scan.
Page 58
58 Kaspersky Anti-Virus for Novell NetWare
2. Expand the task types list and select On-Demand Scan/ Real­Time Protection.
3. Expand the list of the created tasks of the type you need and select the task to start.
4. Open the shortcut menu and select the Start task item.
If the Start task item is not available, make sure that the application is running on the server.
Several on-demand Scan tasks with different settings can be running simultaneously with one Real-Time Protection task.
The tasks are completed after scanning all the specified files and directories, or terminate after the preset time elapses.
You can stop the task before its execution is complete.
To stop the task manually, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server you wish to stop scanning.
2. Expand the task types list and select On-demand Scan/ Real- Time Protection.
3. Expand the list of the created tasks of the type you need and select the task to stop.
4. Open the shortcut menu and select the Stop task item.
6.5. Deleting a task
To delete a task, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server whose task you wish to delete.
2. Expand the task types list and select On-Demand Scan/ Real- Time Protection.
3. Expand the list of the created tasks of the type you need and select the task to delete.
4. Open the shortcut menu and select the Delete task item.
You can delete a task regardless of whether the program is running on the server or not and whether the task is being executed or not.
It is also possible to delete a batch of tasks.
Page 59
Scanning the server for viruses 59
To delete all the tasks of the same type, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server, you wish to delete the tasks for.
2. Expand the list of task types and select the type of tasks you wish to delete.
3. Open the shortcut menu and select the Delete all tasks item.
A task can also be deleted using the application setup window Kaspersky Anti- Virus 5.7 on <Server name>.
In order to delete a Real-Time Protection / On-demand Scan task in the application setup window, do the following,
1. Select the required server in the Kaspersky Anti-Virus 5 name space in the console tree. Open the shortcut menu and select the Properties item.
2. In the next window, Kaspersky Anti-Virus 5.7 on <Server name>, select the Task tab.
3. Select the mode for reviewing the Real-Time Protection and On­demand Scan tasks – On-demand scan and real-time protection tasks (see Figure 14).
4. In the task list, select the task you wish to delete. Click Delete in the group of buttons on the left. Click OK in the next window to confirm deletion.
As a result, the task is removed from the list. After the window is closed with the OK button, the task is deleted from the respective task type list in the console tree.
Page 60
CHAPTER 7. GENERATING
AND VIEWING LOGS, RECEIVING NOTIFICATIONS
All the events that take place during execution of the tasks are logged and the information about them is saved in the log file. This version of Kaspersky Anti­Virus is capable of working with two log formats: text and XML.
Text format is the traditional type, providing the opportunity to record and view task execution results.
The XML format, apart from having the features of the text format, has a number of extra capabilities. The information recorded in XML logs can be filtered and sorted using various criteria. In addition, it is possible to merge different task logs and obtain summarized results. The above mentioned functions are provided by a number of auxiliary files located in the View directory nested in the Log.
In the event that the View directory is deleted or moved, the functions of filtering, sorting, searching or merging the log data become unavailable.
To view any journals, use the Microsoft Internet Explorer 6.0.
Viewing the xml format log is only possible if Microsoft Internet Explorer 6.0 is installed on your computer.
By default a separate log file is created for each task. The log file is located in the Log directory, which is created during the installation of the application in the
installation directory of the server along with other auxiliary directories. txt-files are saved in the root of this directory, while xml log files are saved in the nested
XML directory. To assist in viewing the XML logs auxiliary htm-files are created, which are also stored in the root of the Log directory.
The user can view the log via the computer file system or using the Snapin for ConsoleOne or the web module (if the Novell NetWare client is installed on the local computer).
The log can only be deleted by means of removing the respective files from the XML and Log directories.
The log keeping parameters and the information to be recorded can be set during adjustment of the respective task using the Event log tab (for more details please refer to section B.1.3 on page 129 and section B.2.3 on page146).
Page 61
Generating and viewing logs, receiving notifications 61
The log keeping system provides the administrator with quick, convenient and unified access to the task execution results.
7.1. Viewing the anti-virus database updating results
In order to view the updating task results log, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server on which the desired task was executed.
2. Expand the task types list and select Anti-Virus Database Updates. Open the list of created update tasks and select the one for which you want to view parameters.
3. Open the shortcut menu and select the View log item.
The updating task results log will be displayed in the Microsoft Internet Explorer window. The view of the results log is displayed in the format defined by the task settings
If you are using the Snapin for Novell ConsoleOne, the task execution results log can also be viewed from the Anti-Virus Database Updates (<Server
name>): <Task name> task window (see section B.1.3 on page 129) or the Kaspersky Anti-Virus on <Server name> application setting window (see
section A.6 on page 120). If you are using the web management interface, the task results log can be ac­cessed from the shortcut menu for the target task. Select the task, open the shortcut menu for this task, and click the View log option.
(see section B.1.3 on page 129).
The XML log file structure and its use are more complicated, therefore we provide a detailed description below.
The left pane of the log contains the list of all the task launch sessions in the form of hyperlinks (see Figure 26). This information includes the time and the date.
The right pane displays the task name, full path to the report file, and a table with information about the task session selected in the left pane. The session date and time are displayed in the header of the right pane. Below is the group of checkboxes used to set up the filter, and a set of buttons that can be used for:
Refreshing the table contents and applying the filter settings – Apply
Checking all the filter setting boxes at the same time – Select All
Page 62
62 Kaspersky Anti-Virus for Novell NetWare
Unchecking all the filter setting boxes at the same time – Clear
Figure 26. Viewing the XML log of the update results
In order to view the parameters used with the updating session and view the updating results, do the following:
Select the desired session in the left pane. This will display the required information in the right pane.
The table displays the updating session results: the Object column shows the list of events, and the Result column shows the results of these events. The displayed information depends on the settings made on the Event log tab (see
Page 63
Generating and viewing logs, receiving notifications 63
section B.2.3 on page 146) and the activated filter. By default, the information about the anti-virus database updating results is displayed.
The information is output at 100 lines per page, and the lines are numbered. The Total Records field displays the total number of records. To navigate through the log records you can use the navigation buttons located above and below the table.
To facilitate viewing and searching the information, the program offers the opportunity to set up user filters. The filters allow searching and discarding of currently unnecessary information when it complicates viewing. After the filter is applied, only that information that meets the requirements of the filter is displayed. This has great importance since the log stores large volumes of information.
To set up the filter for the information displayed in the table, do the following:
1. Check the boxes corresponding to the information to be displayed in the table:
Updating results – information regarding the results of the server anti-virus database update download (this box is checked by default).
Updating source – information regarding the results of connection to the update source.
Backup before updating – whether the backup copy of the previous version of the anti-virus database was created before updating.
Not changed files – information regarding the anti-virus database files that were not modified.
Successfully downloaded files – information regarding successfully updated anti-virus database.
Deleted files – information regarding the deleted files.
Errors – information about errors in the event that the update
fails.
You can check all the boxes using the Select All button, or uncheck all the boxes using the Clear button.
2. In order to refresh the information in the table click on the Apply button.
Using the Parameters hyperlink you can view the task settings that were to be used during this session. This will open the task settings window (see Figure 27), which displays the following information:
Page 64
64 Kaspersky Anti-Virus for Novell NetWare
To – a list of servers on which anti-virus database must be updated as a result of executing the task.
Backup before updating – status of the backup mode set for the anti- virus database prior to updating.
Copying mode – the mode used to copy the anti-virus database from the update source.
Updating source – the method used to download the updates (via the Internet or LAN).
List – a list of update sources.
Proxy – parameters of the proxy server used for connecting to the update
source.
Schedule – task starting mode (Daily, Weekly, Monthly).
Figure 27. Update task parameters window
Page 65
Generating and viewing logs, receiving notifications 65
7.2. Viewing the server scanning results
In order to view the scan on demand / real-time protection task execution log, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server on which the desired task was executed.
2. Expand the task types list and select On-Demand Scan / Real- Time Protection. Open the list of the respective tasks and select the one for which you want to view parameters.
3. Open the shortcut menu and select the View log item.
The task results log will be displayed in the Microsoft Internet Explorer window. The view of the results log is displayed in the format defined by the task settings
If you are using the Snapin for Novell ConsoleOne, the task execution results log file can also be viewed from the On-Demand Scan (<Server name>): <Task name> / Real-Time Protection (<Server name>): <Task name> task adjustment window (for more details refer to section B.2.3 on page 146. or the Kaspersky Anti-Virus on <Server name> application setting window (for more details refer to section A.6 on page 120).
If you are using the web management interface, the task results log can be ac­cessed from the shortcut menu for the target task. Select the task, open the shortcut menu for this task, and click the View log option.
(see section B.2.3 on page 146).
The text format log contains detailed information and overall statistics on the results of all the task execution sessions that have taken place (see Figure 28).
Page 66
66 Kaspersky Anti-Virus for Novell NetWare
Figure 28. Viewing the real-time server protection task log in the text format
The XML log file structure and its use are more complicated, therefore we provide a detailed description below.
The displayed information depends on the settings made on the Event log tab (see section B.2.3 on page 146) and the activated filter. By default, the information regarding the infected files detected is displayed.
The left pane of the log contains a list of all the task launch sessions in the form of hyperlinks. The information on the task start includes the date and the time.
The right pane displays the task name, full path to the report file, and a table with information about the session selected in the left pane. The session date and time are displayed in the header of the right pane. Below is the group of checkboxes used to set up the filter, and a set of buttons that can be used for:
Refreshing the table contents and applying the filter settings – Apply
Checking all the filter setting boxes at the same time – Select All
Unchecking all the filter setting boxes at the same time – Clear
Page 67
Generating and viewing logs, receiving notifications 67
Figure 29. Viewing the real-time server protection task log in the XML format
In order to view the parameters of the server scanning task and its results, do the following:
Highlight the desired line in the list in the left pane. This will display the required information in the right pane.
The table displays the following information regarding the task execution results:
Date – the date and the time of the event.
Object – the event registered.
Result – the result of the event.
Virus name – the name of the detected virus or the archive name.
User– the name of the user who was accessing the infected object.
The displayed information depends on the settings specified on the Event log tab (see section B.2.3 on page 146) and the activated filter. By default, the information regarding the infected files detected is displayed.
The information is output by 100 lines per page and the lines are numbered. The Total Records field displays the total number of records. To navigate through the log records you can use the navigation buttons located above and below the table.
Page 68
68 Kaspersky Anti-Virus for Novell NetWare
The records in the table can be arranged by the contents of one of the columns. To the left of the name of the column by which the records are sorted there is a symbol showing whether they are arranged in ascending or descending order. To sort the table records by a column left-click on the desired column header.
To facilitate viewing and searching the information, the program offers the opportunity to set up user filters. The filters allow searching and discarding of currently unnecessary information when it complicates viewing. After the filter is applied, only that information that meets the requirements of the filter is displayed. This has great importance since the log stores large volumes of information.
To set up the filter for the information displayed in the table, do the following:
1. Check the boxes corresponding to the information to be displayed in the table:
Infected files – messages regarding infected files.
Suspicious files – messages regarding suspicious files.
Warnings – alerts regarding detection of a modified or a
damaged virus in a file.
Compressed executables – information regarding compressed executable files.
Archives – information regarding archive files.
Virus-free files – information regarding uninfected files.
Errors – information regarding the application errors during
execution of the task.
Disinfected files – information regarding disinfected files.
Deleted – information regarding deleted files.
Quarantine – information regarding the files moved to the
quarantine directory.
Renamed – information regarding renamed files.
You can check all the boxes using the Select all button or uncheck all the boxes using the Clear button.
2. In order to refresh the information in the table click on the Apply button.
Using the Statistics hyperlink you can view the statistical information on the results of the last task execution (either real-time protection or on-demand scanning task). A click on this hyperlink will open the window (see Figure 30) with the following information:
Page 69
Generating and viewing logs, receiving notifications 69
Scanned files – the number of files scanned.
Scanned folders – the number of directories scanned.
Archives scanned – the number of archive files scanned.
Compressed executables – the number of packed files scanned.
Errors – the number of errors when attempting to access files.
Infected files – the number of infected files detected.
Suspicious files– messages regarding suspicious files and alerts about
detection of a modified or a dam-aged virus in a file.
Disinfected files – information regarding disinfected files.
Deleted files – information regarding deleted files.
Quarantine – information regarding the files moved to the quarantine
directory.
Renamed files – information regarding renamed files.
Scan time – scanning duration.
Page 70
70 Kaspersky Anti-Virus for Novell NetWare
Figure 30. The server scanning statistics window
7.3. Summarized results of the task execution
With the XML logs you can create and view composite logs with information about the results of several tasks. Different logs are created for the server updating and scanning tasks.
In order to create a composite log with the results of several server updating/scanning tasks, do the following:
1. In the Kaspersky Anti-Virus 5 name space in the console tree select the server for which tasks are to be set up. Open the shortcut menu and select the Properties item.
2. In the next window, Kaspersky Anti-Virus on <Server name>, select the Task tab (see Figure 14).
3. Select the viewing mode corresponding to the desired task type:
Anti-Virus Database Updating Tasks.
On Demand Scanning and Real-Time Protection Tasks.
4. In the list of tasks created for the server select the group of tasks for which you wish to create a composite log. The selection is made in a standard way, using the Shift and Ctrl keys. Click on the View log button.
If only one task is selected, a click on the View log button will display the log of this task.
5. In the View log window (see Figure 31 and Figure 32) that will open set up the parameters of the composite log:
Specify the amount of information you need by means of checking the desired box in the Period field group. You can select all the information logged for every task – All records, or the information regarding the events logged during the specified time interval – Period.
Adjust the filters using the Filter group of check boxes. Check the boxes corresponding to the information to be output to the composite log. The structure of the check boxes depends on the task type. Match the log filter settings for this type of task.
Page 71
Generating and viewing logs, receiving notifications 71
After you finish configuring settings, click Save to create, save, and view the composite log. In the standard Save dialog box, specify the file name and location of the log. This opens a Microsoft Internet Explorer window, in which you can view the composite log.
Figure 31. Setting up the parameters of the composite log with the update tasks results
Figure 32. Setting up the parameters of the composite log with the server scanning tasks
results
Page 72
72 Kaspersky Anti-Virus for Novell NetWare
To create, save and view the composite log after the parameters are set, click on the Save button. In the standard file save dialog window specify the name and the path to save the file. This will create the composite log file at the specified address and start the Microsoft Internet Explorer application. The composite log of the tasks execution will be opened in the Explorer window.
The left pane of the log contains the task type and the list of selected tasks launch sessions (see Figure 27). This information includes the time, the date and the name of the task.
Except for this, the composite log is similar to the logs created for this type of task and can be used in the same way.
If you only wish to view the composite log, without saving it to a separate file, click the View log button in the View log window. This will launch Microsoft Internet Explorer and display the log in its window.
7.4. Notification regarding detected viruses
Kaspersky Anti-Virus can alert network users about any infected or suspicious objects detected, thus allowing the infection to be contained and preventing its further spread. The information can be sent via the Novell NetWare network or by e-mail.
The user notification procedure, information sending method, and the text of the messages to be sent are set during adjustment of the real-time server protection and on-demand scanning tasks on the E-mail notification (see section B.2.5 on page 153) and NW-Notification (see section B.2.4 on page 151) tabs.
Page 73
CHAPTER 8. LICENSE
MANAGEMENT
8.1. Licensing policy
When purchasing Kaspersky Anti-Virus for Novell NetWare you conclude a license agreement with Kaspersky Lab, based on which you are granted the right to use this software on one or more computers for one year after installing it.
During the license period you are provided with the following opportunities:
To use the anti-virus functionality of the application.
To update the anti-virus database.
To update the versions of the application.
To seek consultations on questions concerning the installation, setting up
and operation of the application. The consultations can be provided on the telephone or by e-mail.
To send any infected and suspicious objects detected to Kaspersky Lab for analysis.
The application detects the availability of the license agreement and ascertains its validity period using the license key – an integral part of any product produced by Kaspersky Lab. The application may have only one valid license key. It contains the limitations set for the operation of Kaspersky Anti-Virus. These limitations can be checked by special procedures built into the application. You can install the application and the license key on as many Novell-servers in the network as you wish, but copies above the number allowed by the license key will be inoperative.
In the event of violation of the limitations set by the license agreement, Kaspersky Lab may cancel the agreement unilaterally. In such a case, the license key number is included in the cancelled keys list, the so-called "black list". Having detected its key in the "black list", the application terminates the license key and notifies the user that the license agreement has been cancelled by Kaspersky Lab.
Page 74
74 Kaspersky Anti-Virus for Novell NetWare
In the event that the user attempts to interfere in the license canceling procedure (e.g. removes the "black list" file) the application notifies the user that the license agreement has been violated and switches to the ‘No features’ mode until the interference effects are eliminated.
Kaspersky Anti-Virus will notify you about the license expiration two weeks prior to the expiration date. A reminder message will contain information about the expiration date of the current license key (see Figure 33).
Figure 33. The server screen with a reminder message about the license expiration date
To find out the license expiration date, do the following:
Select the desired server in the Kaspersky Anti-Virus 5 name space in the console tree, open the shortcut menu and select the Properties item. The license expiration date is shown in the License expiration date field on the General tab of the Kaspersky Anti-Virus on <Server name> window.
After the license expires, Kaspersky Anti-Virus retains its functionality except for the anti-virus database and application module update services and technical support provided by the company. During execution of the application, the screen displaying the module information will contain the message regarding the license key expiration (see Figure 34).
Page 75
License management 75
Figure 34. The server screen displaying the license expiration message
You still will be able to scan your server for viruses and disinfect any infected objects detected, but the program will use an outdated version of the anti-virus database. In such a situation, complete protection against new viruses can hardly be guaranteed.
To avoid possible infection of your computer by new viruses, you are advised to renew your Kaspersky Anti-Virus license.
To renew your license, you must purchase and install a new license. To obtain a new key:
Contact the vendor from whom you purchased the product and purchase a new Kaspersky Anti-Virus for Novell NetWare license key.
or:
purchase a new license key directly from Kaspersky Lab. To do this, send a request directly to the Sales Department of our company (sales@kaspersky.com) or fill in a form at our web site (www.kaspersky.com) in the Products Æ Renew Your License section. Upon receipt of your payment, we will send a new license key to the email address specified in your order.
Page 76
76 Kaspersky Anti-Virus for Novell NetWare
8.2. Installing the license key
To install a new license key through the Snapi n for Novell ConsoleOne, do the following:
1. In the Kaspersky Anti-Virus 5 namespace in the console tree, select the server whose license you wish to renew. Open the shortcut menu and select the Properties item.
2. In the next window, Kaspersky Anti-Virus on <Server name>, select the General tab.
3. Click the Register license key button.
To install a new license key using the web management module,
1. In the Kaspersky Anti-Virus 5 namespace, select a server for which you want to renew the license. Open the shortcut menu and click the Register license key option.
2. This will open the License key for Kaspersky Anti-Virus window (see Figure 35) with a list of license keys installed on this server. The following information is displayed for each key:
File name – name of the license key file.
Serial number.
Number of licenses – number of Novell servers in the LAN on
which Kaspersky Anti-Virus applications can be running at the same time.
Validity period– license expiry date.
Application – product name.
Type – the type of installed key, e.g. commercial, trial etc.
Figure 35. The License key for Kaspersky Anti-Virus window
Page 77
License management 77
Click on the Add key button and in the Select a License Key window (see Figure 36) specify the file of the key you wish to install (*.key).
If the key is selected correctly its file will be added to the list of Kaspersky Anti­Virus keys. Select it in the list and click on Apply.
Figure 36. Selecting the key file
After this, the license validity period will be extended until the expiry date for the new license key.
If the new license key is installed before the current one expires, the new key will have effect from the current expiration date.
Page 78
CHAPTER 9. MANAGING
KASPERSKY ANTI-VIRUS USING KASPERSKY ADMINISTRATION KIT
Kaspersky Administration Kit is a system for centralized management of anti­virus security system based on the applications included into the Kaspersky Anti­Virus Business Optimal suite.
Kaspersky Anti-Virus for Novell NetWare is one of Kaspersky Lab applications, which can be managed through either the application interface (as described in the earlier chapters) or using Kaspersky Administration Kit (if your computer is a member of the system of remote centralized management).
Figure 37. The Administration Console of Kaspersky Administration Kit
To manage the application through Kaspersky Administration Kit, the administrator creates and configures policies, tasks, and application settings. Protection is provided based on these settings.
Centralized management is provided by grouping several computers together and managing their settings through group policies.
Page 79
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 79
A policy is a set of Kaspersky Anti-Virus settings defined at the group level of the logical network.
Using policies, the administrator can fully manage anti-virus protection because policies include both Kaspersky Anti-Virus settings and task settings (except only the settings that should take effect at task startup, for example, task schedule settings).
A policy might also limit or prohibit changes of task or applications settings. The administrator can apply these limits from either the local ConsoleOne interface, web interface, or Kaspersky Administration Kit interface.
A task is a named action performed by the application. According to functionality, tasks are divided into the following types:
Real-time protection task;
On-demand scan task;
Database updating task;
Install license key task.
Every task has own task settings, which are settings of Kaspersky Anti-Virus
used to perform the task.
Application settings are additional settings of Kaspersky Anti-Virus.
9.1. Managing policies
This section describes how to create and configure a policy for Kaspersky Anti­Virus for Novell Netware.
9.1.1. Creating a policy
To create a policy, do the following:
1. In the Groups node of the console tree, select a group of computers to which you want to apply the new policy.
2. Right-click the Policies node inside the selected group and choose CreateÆPolicy from the shortcut menu. You will see a dialog box for creating a new policy.
Policies are created using a Microsoft Windows wizard in several steps. To move to a next step or to a previous step, use the Next and Back buttons. To finish creating a policy, click Finish at the last step. To exit the wizard, click Cancel at any step.
Page 80
80 Kaspersky Anti-Virus for Novell NetWare
At any step during creation of a new policy, you can lock policy settings from changes by clicking the icon. If the lock icon is closed, only the settings of the
policy you are creating now will take effect on client computers (if the policy is applied to them).
1. Specifying general information about the policy
The first step of the New Policy wizard is an introductory step. In the first dialog box, specify the name of the policy (Name field) and in the second dialog box, select the Kaspersky Anti-Virus for Novell NetWare application from the Application name drop-down list. To enable the policy immediately after its creation, select the Enable policy checkbox.
2. Specifying CPU usage settings
At this step, you can specify how much of the server CPU resources can be consumed by Kaspersky Anti-Virus. The lower the CPU usage, the slower Kaspersky Anti-Virus works when executing the on-demand scan task.
You can also specify the number of antiviral engine copies concurrently loaded when the Kaspersky Anti-Virus module is started on the server. This value defines the number of files that can be scanned for viruses simultaneously. Using this option, you can increase the speed of anti-virus scans.
In the CPU usage settings dialog box (see Fig. 38), you can select the level of CPU usage and define the number of anti-virus kernel copies (see section A.3 on page 115).
Page 81
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 81
Figure 38. Specifying CPU usage
3. Selecting updating source
At this step, you can specify the database updating source and connection settings. As an update source, you can select either Kaspersky Administration Kit or a Kaspersky Lab update server.
In the Updating source dialog box (see Fig. 39), select a source from which to retrieve database updates. If an FTP- or HTTP-server of Kaspersky Lab is selected, the following buttons become active:
Add – add a new updating source in a new dialog box.
Connection settings – configure proxy settings in a new dialog box.
The settings are similar to those used when configuring the application via its local interface (see section B.1.4 on page 131).
Page 82
82 Kaspersky Anti-Virus for Novell NetWare
Figure 39. Selecting an updating source
4. Specifying actions for the real-time protection task
The real-time protection task is a set of actions and settings that protect your computer from unauthorized access from the external network.
In the Actions for the real-time protection task (see Fig. 40) dialog box, you can specify the actions for the application to perform on infected objects and on the objects that could not be disinfected. Using the Allow deleting or renaming archives checkbox, you can prohibit / allow the actions to be applied to archives that were flagged by Kaspersky Anti-Virus as suspicious (see section B.2.2 on page 144).
Page 83
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 83
Figure 40. Specifying actions for the real-time protection task
5. Specifying actions for the on-demand scan task
The on-demand scan task is a set of actions and settings that protect your computer from viruses based on preset schedule.
In the Actions for the on-demand scan task dialog box (see Fig. 41), you can specify the actions for the application to perform on infected objects and on the objects that could not be disinfected. You can also prohibit / allow the actions to be applied to archives that were flagged by Kaspersky Anti-Virus as suspicious (see section B.2.2 on page 144).
Page 84
84 Kaspersky Anti-Virus for Novell NetWare
Figure 41. Specifying actions for the on-demand scan task
6. Specifying the method of first policy enforcement
At this step, in the Policy enforcement dialog box (see Fig. 42), you can specify how this policy will be enforced for the first time on the user computer:
Do not modify local settings – the local settings that are locked by the new policy will be changed after the policy is applied for the first time. After the policy is deleted, the original values of these settings are restored. The settings that are not locked by the policy will not change after the policy is applied. The values of settings can be modified through the local applica­tion interface. After the policy is deleted, the original values are not re­stored.
Apply mandatory policy settings to the local settings on the first policy ap­plication – the local settings that are locked by the new policy will be changed after the policy is applied for the first time. After the policy is de­leted, the original values of these settings are not restored. The settings that are not locked by the policy will not change after the policy is applied. The values of settings can be modified through the local application inter­face. After the policy is deleted, the original values are not restored.
Apply all policy settings to the local settings on the first policy applica­tion – the local settings that are locked by the new policy will be changed after the policy is applied for the first time. After the policy is deleted, the original values of these settings are not restored. The settings that are not
Page 85
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 85
locked by the policy will also change after the policy is applied. The val­ues of settings can be modified through the local application interface. Af­ter the policy is deleted, the original values are not restored.
Figure 42. Specifying the method of the first policy enforcement
7. Finishing creating a policy
The last wizard dialog box (see Fig. 43) informs you that the new policy has been successfully created.
After you exit the wizard, the policy for Kaspersky Anti-Virus 5.7 for Novell Netware is added to the Policies folders for the corresponding group and displayed in the results pane.
For this policy, you can configure its settings and lock local settings using the icon. The user will be unable to modify the locked settings through the local interface of Kaspersky Anti-Virus. The policy will take effect on client computers during the first synchronization of the clients with the Administration Server.
Using the Copy/Paste, Cut/Paste, and Delete commands on the context menu and the Actions menu, you can move policies from one group to another and delete them.
Page 86
86 Kaspersky Anti-Virus for Novell NetWare
Figure 43. Finishing creating a policy
9.1.2. Viewing and editing policy settings
You can modify a policy, lock policy settings for nested groups, and lock application and task settings.
1. In the Groups node of the console tree, select a group of computers for which you want to edit policy settings.
2. For the selected group, select the Policies node. The details pane will display all policies created for this group.
3. In the list of policies, select the policy for Kaspersky Anti-Virus for Novell NetWare (the application name is shown in the Application field).
4. In the context menu, select Properties.
A dialog box with the policy settings for this application opens.
The General, Enforcement, and Events tabs are standard tabs for Kaspersky Administration Kit (see the Administrator’s Guide for Kaspersky Administration Kit).
Other tabs contain settings specific for Kaspersky Anti-Virus for Novell NetWare. Below you can see descriptions of each of these tabs.
Page 87
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 87
When editing the policy, use the modifications through the local interface. The user will be unable to modify the locked settings through the local interface of Kaspersky Anti-Virus.
icon to lock the policy settings from
9.1.2.1. Viewing information about the application
On the General tab (see Fig. 44), you can see the general information about the policy: policy name, application name, application version, date and time of policy creation, and the date and time when the policy was last modified.
Figure 44. The General tab
In this window, you can change the policy name, enable or disable the policy, and configure the policy to be enabled upon a specified event.
Page 88
88 Kaspersky Anti-Virus for Novell NetWare
9.1.2.2. Viewing policy enforcement results
The Enforcement tab (see Fig. 45) displays the statistics of policy enforcement on the computers in the group, such as the number of computers on which this policy was:
created;
enforced;
pending;
failed.
Figure 45. The Enforcement tab
Click the Details button to see detailed information about policy enforcement for each computer (see the Administrator’ Guide for Kaspersky Administration Kit 5.0).
Page 89
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 89
9.1.2.3. Configuring event logging settings
During operation, Kaspersky Anti-Virus generates a list of events, and each of these events is characterized by the level of event importance. There are four severity levels for events: critical event, failure, warning, and information.
Depending on the situation, events of the same type can have a different severity level.
The Event processing tab (см. рис. 46) displays the types of events that might occur during application performance and be logged in the report. You can also see and edit the log file location and the settings for notifying the administrator and / or other users.
To view the types of events, select the desired severity level from the Severity level drop-down list. The types of events for the selected level will be displayed below.
For each event, you can specify whether to include this event in the report and notify the administrator upon this event.
Figure 46. The Event processing tab
Page 90
90 Kaspersky Anti-Virus for Novell NetWare
For more information about the settings on the Event processing tab, see the Administrator’ Guide for Kaspersky Administration Kit 5.0.
9.1.2.4. Specifying CPU usage during scans
On the Advanced tab (see Fig. 47), you can specify the how much of the server CPU resources can be consumed by Kaspersky Anti-Virus. The lower the CPU usage, the slower Kaspersky Anti-Virus works. This window also displays the number of antiviral engine copies concurrently loaded when Kaspersky Anti-Virus is started on the server. This value defines the number of files that can be scanned concurrently (see section A.3 on page 115).
Figure 47. The Advanced tab
9.1.2.5. Selecting the updating source for the anti-virus database
On the Updating source tab (see Fig. 48), you can select the updating source and specify connection settings. As an updating source, you can select either
Page 91
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 91
Kaspersky Administration Kit or a Kaspersky Lab update server. You can also set the mode of anti-virus database copying from the source: copy all available updates or only modified.
In this window, click the Connection settings button to configure proxy server settings (see section B.1.4 on page 131).
Figure 48. The Updating source tab
9.1.2.6. Configuring settings for the on-demand scan task
On the Scan settings tab (see Fig. 49), you can define settings for scanning the server for viruses on demand. Specify the scan area by selecting the type of files to scan from the drop-down list:
All files
Files infectable by extension
All infectable files
Page 92
92 Kaspersky Anti-Virus for Novell NetWare
You can define the types of files to be excluded from scans. For this, select the Excluded files checkbox and specify the list of exclusions.
You can also specify the additional scan modes, such as scanning mail databases, archives, packed executable files, plain mail files, and whether to use an heuristic code analyzer (see section B.2.1 on page 139).
Figure 49. The Scan settings tab
9.1.2.7. Selecting actions for the on-demand scan task
On the Actions tab (see Fig. 50), you can specify the actions to be performed on:
Infected and suspicious files detected during scans
Objects that could not be disinfected
Infected workstation, which attempted to transfer an infected file to the
server
Page 93
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 93
Suspicious archives (see section B.2.2 on page 144).
To specify an action on infected objects, select one of the following items from the drop-down list:
Skip – do not apply any actions.
Disinfect
Delete
Move to the quarantine – move the file to the quarantine directory.
Rename – change the file extension to .vir (or .vi1, .vi2 etc, if a file with
the same name exists).
If disinfection of an infected object failed, select one of the following:
Skip – leave the file intact and save the information about it in the log.
Delete
Rename – save the file under another name.
Figure 50. The Actions tab
Page 94
94 Kaspersky Anti-Virus for Novell NetWare
9.1.2.8. Configuring settings for the real-time protection task
On the Scan settings tab (see Fig. 51), you can define settings for scanning the filesystem for viruses. Specify the scan area by selecting the type of files to scan from the drop-down list:
All files
Files infectable by extension
All infectable files
You can define the types of files to be excluded from scans. For this, select the Excluded files checkbox and specify the list of exclusions.
You can also specify the additional scan modes, such as scanning mail databases, archives, packed executable files, plain mail files, and whether to use an heuristic code analyzer (see section B.2.1 on page 139).
Figure 51. The Scan settings tab
Page 95
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 95
9.1.2.9. Selecting actions for the real-time protection task
On the Actions (see Fig. 52), you can specify the actions to be performed on:
Infected and suspicious files detected during scans
Objects that could not be disinfected
Infected workstation that attempted to transfer an infected file to the
server
Suspicious archives (see section B.2.2 on page 144).
To specify an action on infected objects, select one of the following items from the drop-down list:
Skip – do not apply any actions.
Disinfect
Delete
Move to the quarantine – move the file to the quarantine directory.
Rename – change the file extension to .vir (or .vi1, .vi2 etc, if a file with
the same name exists).
If disinfection of an infected object failed, select one of the following:
Skip – leave the file intact and save the information about it in the log.
Delete
Rename – save the file under another name.
Page 96
96 Kaspersky Anti-Virus for Novell NetWare
Figure 52. The Actions tab
9.2. Managing application settings
1. Using application settings, you can modify the settings for Kaspersky Anti-Virus either for separate client computers in a group or for the local computer. You can modify only the settings that are not locked by a policy (see section 9.1 on page 79).
To modify policy settings:
2. In the Groups node, select a folder with the name of the group that contains your client computer.
3. In the details pane, select the computer for which you want to modify application settings. Choose Properties in the context menu or on the Actions menu.
Page 97
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 97
To modify the settings of the anti-virus application installed on your client computer, in the console tree select Local computer (see Fig.
37) and choose Properties in the shortcut menu.
4. As the result, the Properties: <Computer Name> dialog box opens in the application main window. Select the Applications tab (see Fig. 53). On this tab, you can see a full list of Kaspersky Lab applications installed on this client computer.
Figure 53. The dialog box displaying the client computer properties.
The Applications tab
5. Select Kaspersky Anti-Virus for Novell NetWare. Under the list, you can see the following buttons:
Events – view all events that occurred on the client computer and registered on the Administration Server.
Statistics – view statistic information on application perform- ance.
Properties – configure the application in the new dialog box Properties of Kaspersky Anti-Virus for Novell NetWare».
Page 98
98 Kaspersky Anti-Virus for Novell NetWare
9.2.1.1. Viewing the information about the application
On the General tab (see Fig. 54), you can view the information about Kaspersky Anti-Virus 5.7 for Novell NetWare.
The upper part of the window displays the name of the installed application, its version number, installation date, its status (stopped or running on the local computer), and the anti-virus database status.
Figure 54. The dialog box with application properties. The General tab
9.2.1.2. Viewing the information about the location of objects
The Folders tab (see Fig. 55) displays the location of the directories used by the application, such as the directory containing the current anti-virus database and its backup copy, the quarantine folder for infected and suspicious objects, the temporary files folder, and the folder that stores database updates.
Page 99
Managing Kaspersky Anti-Virus using Kaspersky Administration kit 99
Figure 55. The Folders tab
9.2.1.3. Viewing connection settings and CPU usage
The Advanced tab (see Fig. 56) displays information about the parameters for communication with the server and application performance settings.
The following connection parameters are provided in the Information section:
Server IP address – numeric IP address of the server.
Port – decimal number of communication port used for connection with
the Kaspersky Anti-Virus module. The default value is 8195.
Port (for updating) – decimal number of communication port used to connect with the Anti-virus database updating module. The default value is 8196.
The CPU usage scale specifies how much of the server CPU resources can be consumed by the Kaspersky Anti-Virus module. The lower the CPU usage, the slower the Kaspersky Anti-Virus module works.
Page 100
100 Kaspersky Anti-Virus for Novell NetWare
The Number of anti-virus kernel instances field specifies the number of antiviral engine copies concurrently loaded when the Kaspersky Anti-Virus module is started on the server. This value defines the number of files that can be scanned for viruses simultaneously (see section A.3 on page 115).
Figure 56. The Advanced tab
9.2.1.4. Viewing information about license keys
The Licenses tab (see Fig. 57) displays information about the current or backup license keys installed on this computer. You can also view the type of the key, its validity period, and limitations. The dates of key activation and expiry are also shown for the current license key.
Loading...