Avira Premium Security Suite User Manual
Trademarks and Copyright Trademarks AntiVir is a registered trademark of Avira GmbH. Windows is a registered trademark of the Microsoft Corporation in the United States and other countries. All other brand and product names are trademarks or registered trademarks of their respective owners. Protected trademarks are not marked as such in this manual. This does not mean, however that they may be used freely.
Table of Contents 1 Introduction ............................................................................................................ 1 2 Icons and emphases .................................................................................................. 2 3 Product information ................................................................................................ 3 3.1 3.2 3.3 4 Installation and uninstallation.........................................................................
Table of Contents 6 Scanner .................................................................................................................. 42 7 Updates .................................................................................................................. 43 8 Avira FireWall :: Overview ...................................................................................... 44 9 Backup .......................................................................................................
Avira Premium Security Suite 13.4 13.5 13.6 13.7 13.8 13.9 iv 13.3.2.3. MailGuard .................................................................................................... 90 13.3.2.4. Footer ........................................................................................................... 91 13.3.3 Report .................................................................................................................. 91 Firewall ...................................................
1 Introduction Your AntiVir program protects your computer against viruses, worms, Trojans, adware and spyware and other risks. In this manual these are referred to as viruses or malware (harmful software) and unwanted programs. The manual describes the program installation and operation. For further options and information, please visit our website: http://www.avira.com The Avira website lets you...
2 Icons and emphases The following icons are used: Icon / designation Explanation Placed before a condition which must be fulfilled prior to execution of an action. Placed before an action step that you perform. Placed before an event that follows the previous action. Warning Placed before a warning of the danger of critical data loss. Note Placed before a link to particularly important information or a tip which makes your AntiVir program easier to use.
3 Product information This chapter contains all information relevant to the purchase and use of your AntiVir product: – see Chapter: Delivery scope – see Chapter: System requirements – see Chapter: Licensing – see Chapter: License Manager AntiVir programs are comprehensive and flexible tools you can rely on to protect your computer from viruses, malware, unwanted programs and other dangers. Please note the following information: Note Loss of valuable data usually has dramatic consequences.
Avira Premium Security Suite – Integrated quarantine management to isolate and process suspicious files – Rootkit protection for detecting hidden malware installed in your computer system (rootkits) (Not available under Windows XP 64 bit) – Direct access to detailed information on the detected viruses and malware via the Internet – Simple and quick updates to the program, virus definitions, and search engine through Single File Update and incremental VDF updates via a web server on the Internet – User-frien
Product information In order to be able to use your AntiVir product, you require a license. You thereby accept the license terms. The license is provided in the form of an activation key. The activation key is a code comprising letters and numbers that you will receive after purchasing the AntiVir product. The activation key contains the exact data of your license, i.e. which programs have been licensed for which period of time.
4 Installation and uninstallation This chapter contains information relating to the installation and uninstallation of your AntiVir program. – see Chapter Installation: Conditions, Installation types, Install – see Chapter Installation modules – see Chapter Modification installation – see Chapter Uninstallation: Uninstall 4.1 Installation Before installation, check whether your computer fulfils all the minimum system requirements.
Installation and uninstallation – A target folder can be selected for the program files to be installed. – You can disable Create a desktop icon and program group in the Start menu. – Using the configuration wizard, you can define custom settings for your AntiVir program and initiate a short system scan that is performed automatically after installation. Before starting installation Close your email program. It is also recommended to end all running applications.
Avira Premium Security Suite Note The following actions for disabling the Windows FireWall only apply to the Windows XP operating system. Start the installation program by double-clicking the installation file you have downloaded from the Internet or insert the program CD. Internet-based installation The dialog box Welcome... appears. Click Next to continue with the installation. The dialog box Language selection appears.
Installation and uninstallation obtain more details on the expanded online scan. Enable or disable participation in the AntiVir ProActiv Community and confirm by clicking Next. In the following dialog box you can decide whether to create a desktop shortcut and/or a program group in the Start menu. Click Next. Skip the following section "Express installation". Express installation The AntiVir ProActiv Community window appears.
Avira Premium Security Suite Your license data will be displayed in the next window. Click Next. Skip the following chapter on "Activate by selecting the option Valid hbedv.key available ". Select the option "Valid hbedv.key available" A box will be opened for loading the license file. Select the license file hbedv.key with your license data for the program, and click Open Your license data will be displayed in the next window.
Installation and uninstallation Enable the required option and continue the configuration by clicking Next. If you have selected the AntiVir WebGuard installation module, theEnable parental controls dialog box appears. You can stipulate the Guard start time. At each computer reboot, the Guard will be started in the start mode specified. You have the option of assigning different roles – child, young person, adult – to computer users for Internet use. You can disable parental controls.
Avira Premium Security Suite 4.3 Installation modules In a user-defined installation or a change installation, the following installation modules can be selected, added or removed. – Premium Security Suite This module contains all components required for successful installation of your AntiVir program. – AntiVir Guard The AntiVir Guard runs in the background. It monitors and repairs, if possible, files during operations such as open, write and copy in on-access mode.
Installation and uninstallation – Shell Extension The Shell Extension generates an entry ‘Scan selected files with AntiVir’ in the context menu of the Windows Explorer (right-hand mouse button). With this entry you can directly scan files or directories. – Backup The Backup component lets you create mirror backups of your data manually and automatically. 4.
5 Overview of Premium Security Suite This chapter contains an overview of the functionality and operation of your AntiVir program. – see Chapter Interface and operation – see Chapter How to...? 5.1 User interface and operation You operate your AntiVir program via three program interface elements: – Control Center: monitoring and controlling the AntiVir program – Configuration: Configuring the AntiVir program – Tray Icon in the system tray of the taskbar: Opening the Control Center and other functions 5.1.
Overview of Premium Security Suite – Navigation area: In the navigation area, you can easily swap between the individual sections of the Control Center. The individual sections contain information and functions of the program components and are arranged in the navigation bar according to activity. Example: Activity Overview - Section Status. – View: This window shows the section selected in the navigation area.
Avira Premium Security Suite • The Status section lets you see at a glance which program modules are active and provides information on the last update performed. You can also see whether you own a valid license. • The Events section enables you to view events generated by certain program modules. • Die Reports section enables you to view the results of actions performed.
Overview of Premium Security Suite 5.1.2 Configuration You can define settings for your AntiVir program in the Configuration. After installation, your AntiVir program is configured with standard settings, ensuring optimal protection for your computer system. However, your computer system or your specific requirements for your AntiVir program may mean you need to adapt the protective components of the program.
Avira Premium Security Suite Navigate in the configuration window as you would in Windows Explorer: Click an entry in the tree structure to display this configuration section in the detail window. Click the plus symbol in front of an entry to expand the configuration section and display configuration subsections in the tree structure. To hide configuration subsections, click on the minus symbol in front of the expanded configuration section.
Overview of Premium Security Suite On-access scan exceptions On-access scan heuristics Report function setting – MailGuard: Configuration of MailGuard Scan options: Enable the monitoring of POP3 accounts, IMAP accounts, outgoing emails (SMTP) Actions on malware MailGuard scan heuristics AntiBot function: Permitted SMTP servers, permitted email senders MailGuard scan exceptions Configuration of cache, empty cache Configuration of the anti-spam training database, empty training database Configuration of a foo
Avira Premium Security Suite Security: Update status display, complete system scan status display, product protection WMI: Enable WMI support Event log configuration Configuration of report functions Setting of directories used Update: Configuration of connection to download server, set-up of product updates Configuration of acoustic alerts when malware is detected 5.1.
Overview of Premium Security Suite 5.2 How to...? 5.2.1 Activate product To activate your AntiVir product, you have the following options: • Activation with a valid full license To activate the program with a full license, you need a valid activation key, which holds data of the license you have purchased. You have received the activation key from us either by email or it has been printed on the product packaging.
Avira Premium Security Suite 5.2.2 Perform automatic updates To create a job with the AntiVir Scheduler to update your AntiVir program automatically: In the Control Center, select the section Management :: Scheduler. Click the Create new job with the wizard icon. The dialog box Name and description of job appears. Give the job a name and, where appropriate, a description. Click Next. The dialog box Type of job is displayed. Select Update job from the list. Click Next.
Overview of Premium Security Suite Use the following icons to further define your jobs: View properties of a job Modify job Delete job Start job Stop job 5.2.3 Start a manual update You have various options for starting an update manually: When an update is started manually, the virus definition file and scan engine are always updated.
Avira Premium Security Suite if you want to scan with a customized scan profile. – Create and apply new scan profile if you want to create your own scan profile. Depending on the operating system, various icons are available for starting a scan profile: – In Windows XP and 2000: This icon starts the scan via a scan profile. – In Windows Vista: In Microsoft Windows Vista, the Control Center only has limited rights at the moment, e.g. for access to directories and files.
Overview of Premium Security Suite • Directory excluding sub-directories (green check mark) • Sub-directories of one directory only (grey check mark, sub-directories have black check marks) • No directory (no check mark) If you want to create a new scan profile: Click the icon Create new profile. The profile New profile appears below the profiles previously created. Where appropriate, rename the scan profile by clicking on the icon .
Avira Premium Security Suite 5.2.7 On-demand scan: Automatically scan for viruses and malware Note After installation, the scan job Full system scan is created in the Scheduler: A complete system scan is automatically performed at a recommended interval. To create a job to automatically scan for viruses and malware: In the Control Center, select the section Management:: Scheduler. Click the icon . The dialog box Name and description of job appears.
Overview of Premium Security Suite Click Finish. Your newly created job appears on the start page of the Manager :: Scheduler section with the status activated (check mark). Where appropriate, deactivate jobs that are not to be performed. Use the following icons to further define your jobs: View properties of a job Modify job Delete job Start job Stop job 5.2.
Avira Premium Security Suite In interactive action mode, the results of the Scanner scan are displayed in a dialog box. This option is enabled as the default setting. In the case of Scanner scan, you will receive an alert with a list of the affected files when the scan is complete. You can use the content-sensitive menu to select an action to be executed for the various infected files. You can execute the standard actions for all infected files or cancel the Scanner.
Overview of Premium Security Suite – Delete The file will be deleted. This process is much quicker than overwrite and delete. If a boot sector virus is detected, this can be deleted by deleting the boot sector. A new boot sector is written. – Overwrite and delete The file is overwritten with a default template and then deleted. It cannot be restored. – Rename The file is renamed with a *.vir extension. Direct access to these files (e.g. with double-click) is therefore no longer possible.
Avira Premium Security Suite The application is blocked, i.e. the application is terminated. The program is added to list of blocked applications and can no longer be run (see Configuration::Guard::ProActiv::Application filter: Applications to be blocked). – Ignore The application continues to run. The actions of the application continue to be monitored by the ProActiv component. MailGuard actions: Incoming emails – Move to quarantine The email including all attachments is moved to quarantine.
Overview of Premium Security Suite – Deny access The website requested from the web server and/or any data or files transferred are not sent to your web browser. An error message to notify you that access has been denied is displayed in the web browser. – Move to quarantine The website requested from the web server and/or any data or files transferred are moved to quarantine.
Avira Premium Security Suite Highlight the file and click on . If you want to upload the file to a Avira Malware Research Center web server for analysis: Highlight the file you want to upload. Click on . A dialog opens with a form for inputting your contact data. Enter all the required data. Select a type: Suspicious file or False positive. Click OK. The file is uploaded to a Avira Malware Research Center web server in compressed form.
Overview of Premium Security Suite 5.2.11 Quarantine: Restore the files in quarantine Different icons control the restore procedure, depending on the operating system: – In Windows XP and 2000: This icon restores the files to their original directory. This icon restores the files to a directory of your choice. – In Windows Vista: In Microsoft Windows Vista, the Control Center only has limited rights at the moment, e.g. for access to directories and files.
Avira Premium Security Suite Click Yes. The Windows default window for selecting the directory appears. Select the directory to restore the file to and confirm. The file is restored to the selected directory. 5.2.12 Quarantine: Move suspicious files to quarantine To move a suspect file to quarantine manually: In the Control Center, select the section Management :: Quarantine section. Click on . The Windows default window for selecting a file appears. Select the file and confirm.
Overview of Premium Security Suite In the Control Center, go to the Local protection:: Scan section. Select the scan profile for which you want to create a shortcut. Click the icon . The desktop shortcut is created. 5.2.15 Events: Filter events Events that have been generated by program components of your AntiVir program are displayed in the Control Center under Overview::Events (analogous to the event display of your Windows operating system).
Avira Premium Security Suite The list shows incoming emails. Highlight the email you want to exclude from the MailGuard scan. Click the appropriate icon to exclude the email from the MailGuard scan: In future, the selected email address will no longer be scanned for viruses and unwanted programs. In the future, the selected email address will no longer be scanned for spam. The email sender address is included in the exclusion list and no longer scanned for viruses, malware or spam .
Overview of Premium Security Suite • Suspicious TCP and UDP packages are discarded. • Flooding and port scan are prevented. – High • Computer is not visible on the network. • Connections from outside are blocked. • Flooding and port scan are prevented. – User • User-defined rules: If this security level is selected, the program automatically recognizes that the adapter rules have been modified.
Avira Premium Security Suite Click the icon . The window Avira Backup appears and the backup starts. The status and results of the backup are displayed in the backup window. If you want to modify a backup profile: In the scan profile, expand the Manual Selection file tree so that all drives and directories to be saved are open: • Click the + icon: The next directory level is displayed. • Click the - icon: The next directory level is hidden.
Overview of Premium Security Suite Click Next. The dialog box Select profile appears. Select the profile to be scanned. Note Only backup profiles for which a save location has been stipulated are displayed. Click Next. The dialog box Time of job appears.
Avira Premium Security Suite Start job Stop job 40
41
Avira Premium Security Suite 6 Scanner With the Scanner component, you can carry out targeted scans (on-demand scans) for viruses and unwanted programs. The following options are available for scanning for infected files: – On-demand scan via context menu The on-demand-scan via the context menu (right-hand mouse button - entry Scan selected files with AntiVir) is recommended if, for example, you wish to scan individual files and directories.
7 Updates The effectiveness of anti-virus software depends on how up-to-date the program is, in particular the virus definition file and the scan engine. To carry out regular updates, the Updater component is integrated into your AntiVir. The Updater ensures that your AntiVir program is always up-to-date and able to deal with the new viruses that appear every day.
8 Avira FireWall :: Overview Avira FireWall monitors and regulates incoming and outgoing data traffic on your computer system and protects you from a wide range of attacks and threats from the Internet: Incoming or outgoing data traffic or listening to ports will be allowed or denied based on security guidelines. You will receive a desktop notification if Avira FireWall denies network activity and thus blocks network connections.
9 Backup There are various options available to you for creating a backup of your data: Backup via the backup tool You can use the backup tool to select or create backup profiles and start a backup of a selected profile manually. Backup via a backup job in Scheduler Scheduler gives you the option of creating scheduled or event-controlled backup jobs. Scheduler automatically executes the backup jobs. This process is particularly useful if you want to make regular backups of specific data.
10 FAQ, Tips This chapter contains important information on troubleshooting and further tips on using your AntiVir program. see Chapter Troubleshooting see Chapter Keyboard commands see Chapter Windows Security Center 10.1 Help in case of a problem Here you will find information on causes and solutions of possible problems. – The error message The license file cannot be opened appears. – AntiVir MailGuard does not work. – There is no network connection available in a virtual machine (e.g.
FAQ, Tips Check your settings in the Configuration (expert mode) under General::UpdateYour settings. Viruses and malware cannot be moved or deleted. Reason: The file was loaded by windows and is active. Update your AntiVir product. If you use the Windows XP operating system, deactivate System Restore. Start the computer in Safe Mode. Start the AntiVir program and the Configuration (expert mode). Select Scanner::Scan::Files::All files and confirm the window with OK. Start a scan of all local drives.
Avira Premium Security Suite Define a general approval for AntiVir Guard and AntiVir MailGuard. AntiVir Guard only works with the address 127.0.0.1 (localhost). An Internet connection is not established. The same applies to AntiVir MailGuard. AntiVir MailGuard does not work. Please check correct functioning of AntiVir MailGuard with the aid of the following checklists if problems occur with AntiVir MailGuard. Checklist Check whether your mail client logs in on the server via Kerberos, APOP or RPA.
FAQ, Tips Reason: The virtual machine emulates a network card by means of software. This emulation encapsulates the data packages of the guest system in special packages (UDP packages) and routes them via the external gateway back to the host system. Avira FireWall rejects these packages coming from outside, starting from security level medium. To avoid this behavior do the following: Go to Control Center and select the section Online protection :: FireWall. Click the Configuration link.
Avira Premium Security Suite This phenomenon may occur during chats, which are based on the HTTP protocol with 'transfer-encoding= chunked’. Reason: WebGuard checks the data sent completely for viruses and undesired programs first of all, before the data are loaded into the web browser. During a data transfer with ‘transfer-encoding= chunked’, WebGuard cannot determine the message length or the data volume.
FAQ, Tips Enter Start command for the active option or button. 10.2.2 In the help Shortcut Description Alt + Space Display system menu. Alt + Tab Shift between the help and the other opened windows. Alt + F4 Close help. Shift + F10 Display context menu of the help. Ctrl + Tab Go to next section in the navigation window. Ctrl + Shift + Tab Go to previous section in the navigation window.
Avira Premium Security Suite FireWall section Shortcut Description Return Properties Quarantine section Shortcut Description F2 Rescan object F3 Restore object F4 Send object F6 Restore object to...
FAQ, Tips 10.3 Windows Security Center - Windows XP Service Pack 2 or higher - 10.3.1 General The Windows Security Center checks the status of a computer for important security aspects. If a problem is detected with one of these important points (e.g. an outdated anti-virus program), the Security Center issues an alert and gives recommendations on how to protect your computer better. 10.3.
Avira Premium Security Suite You may receive the following information from the Windows Security Center with regard to your virus protection: Virus protection NOT FOUND Virus protection OUT OF DATE Virus protection ON Virus protection OFF Virus protection NOT MONITORED Virus protection NOT FOUND This information of the Windows Security Center appears when the Windows Security Center has not found any anti-virus software on your computer.
FAQ, Tips Your AntiVir program is now up-to-date and the AntiVir Guard is enabled. Virus protection OFF You receive the following message if you disable the AntiVir Guard or stop the Guard service. Note You can enable or disabled AntiVir Guard in the Overview::Status section of the Control Center. You can also see that the AntiVir Guard is enabled if the red umbrella in your taskbar is open.
11 Viruses and more 11.1 Extended threat categories Dialer (DIALER) Certain services available in the Internet have to be paid for. They are invoiced in Germany via dialers with 0190/0900 numbers (or via 09x0 numbers in Austria and Switzerland; in Germany, the number is set to change to 09x0 in the medium term). Once installed on the computer, these programs guarantee a connection via a suitable premium rate number whose scale of charges can vary widely.
Viruses and more Studies have shown that the number of working hours devoted to computer games has long reached economically significant proportions. It is therefore not surprising that more and more companies are considering ways of banning computer games from workplace computers. Your AntiVir program recognizes computer games. If the Games option is enabled with a check mark in the configuration under Threat categories, you receive a corresponding alert if your AntiVir program detects a game.
Avira Premium Security Suite Your AntiVir program recognizes "Adware/Spyware". If the option Adware/Spyware (ADSPY) is enabled with a check mark in the configuration under Extended threat categories, you receive a corresponding alert if your AntiVir program detects adware or spyware. Unusual Runtime Packers (PCK) Files that have been compressed with an unusual runtime packer and that can therefore be classified as potentially suspicious. Your AntiVir program recognizes "Unusual runtime packers".
Viruses and more Adware is software that presents banner ads or in pop-up windows through a bar that appears on a computer screen. These advertisements usually cannot be removed and are consequently always visible. The connection data allow many conclusions on the usage behavior and are problematic in terms of data security. Backdoors A backdoor can gain access to a computer by bypassing the computer access security mechanisms.
Avira Premium Security Suite Macro viruses Macroviruses are small programs that are written in the macro language of an application (e.g. WordBasic under WinWord 6.0) and that can normally only spread within documents of this application. Because of this, they are also called document viruses. In order to be active, they need that the corresponding applications are activated and that one of the infected macros has been executed.
Viruses and more Such viruses are extremely easy to program and they can spread - if the required technology is on hand - within a few hours via email round the globe. Script viruses and worms use one of the script languages, such as Javascript, VBScript etc., to insert themselves in other, new scripts or to spread themselves by calling operating system functions. This frequently happens via email or through the exchange of files (documents).
12 Info and Service This chapter contains information on how to contact us. see Chapter Contact address see Chapter Technical support see Chapter Suspicious files see Chapter Report false positives see Chapter Your feedback for more security 12.1 Contact address If you have any questions or requests concerning the AntiVir product range, we will be pleased to help you. For our contact addresses, please refer to the Control Center under Help :: About Avira Premium Security Suite. 12.
Info and Service – Identify the file in the quarantine manager of the Control Center and select the item Send file via the context menu or the corresponding button. – Send the required file packed (WinZIP, PKZip, Arj etc.) in the attachment of an email to the following address: virus-premium-suite@avira.com As some email gateways work with anti-virus software, you should also provide the file(s) with a password (please remember to tell us the password).
13 Reference: Configuration options The configuration reference documents all available configuration options. 13.1 Scanner The Scanner section of the Configuration is responsible for the configuration of the ondemand scan. 13.1.1 Scan Here you define the basic behavior of the scan routine for an on-demand scan.
Reference: Configuration options Note If this option is enabled and you have deleted all entries from the list with file extensions, this is indicated with the text "No file extensions" under the button File extensions. File extensions With the aid of this button, a dialog box is opened in which all file extensions are displayed that are scanned in "Use file extension list" mode. Default entries are set for the extensions, but entries can be added or deleted.
Avira Premium Security Suite Important The option does not include any shortcuts, but refers exclusively to symbolic links (generated by mklink.exe) or Junction Points (generated by junction.exe) that are transparent in the file system. Search for Rootkits before scan If this option is enabled and a scan is started, the Scanner scans the Windows system directory for active rootkits in a so-called shortcut.
Reference: Configuration options If this option is enabled, the results of the Scanner scan are displayed in a dialog box. When carrying out a scan with the Scanner, you will receive an alert with a list of the affected files at the end of the scan. You can use the content-sensitive menu to select an action to be executed for the various infected files. You can execute the standard actions for all infected files or cancel the Scanner.
Avira Premium Security Suite If this option is enabled, the Scanner moves the file to the quarantine. These files can later be repaired or - if necessary - sent to the Avira Malware Research Center. Secondary action The option "Secondary action" can only be selected if the setting repair was selected under "Primary action". With this option it can now be decided what is to be done with the affected file if it cannot be repaired. delete If this option is enabled, the file is deleted.
Reference: Configuration options Recursion depth Unpacking and scanning recursive archives can require a great deal of computer time and resources. If this option is enabled, you limit the depth of the scan in multi-packed archives to a certain number of packing levels (maximum recursion depth). This saves time and computer resources. Note In order to find a virus or an unwanted program in an archive, the Scanner must scan up to the recursion level in which the virus or the unwanted program is located.
Avira Premium Security Suite The button opens a window in which you can select the required file or the required path. When you have entered a file name with its complete path, only this file is not scanned for infection. If you have entered a file name without a path, all files with this name (irrespective of the path or drive) are not scanned. Add With this button, you can add the file object entered in the input box to the display window. Delete The button deletes a selected entry from the list.
Reference: Configuration options If this option is enabled, slightly less unknown malware is detected, the risk of false alerts is low in this case. Medium detection level This option is enabled as the default setting if you have selected the use of this heuristic. High detection level If this option is enabled, significantly more unknown malware is detected, but there are also likely to be false positives. 13.1.2 Report The Scanner has a comprehensive reporting function.
Avira Premium Security Suite You will normally want to monitor your system constantly. To this end, use the Guard (= on-access Scanner). You can thus scan all files that are copied or opened on the computer "on the fly", for viruses and unwanted programs. Scan mode Here the time for scanning of a file is defined. Scan when reading If this option is enabled, the Guard scans the files before they are read or executed by the application or the operating system.
Reference: Configuration options Note Please note that the file extension list may vary from version to version. Archives Scan archives If this option is enabled, then archives will be scanned. Compressed files are scanned, then decompressed and scanned again. This option is deactivated by default. The archive scan is restricted by the recursion depth, the number of files to be scanned and the archive size.
Avira Premium Security Suite If this option is enabled, the Guard creates a backup copy before carrying out the requested primary or secondary action. The backup copy is saved in quarantine. It can be restored via the quarantine manager if it is of informative value. You can also send the backup copy to the Avira Malware Research Center. Depending on the object, more selection options are available in the quarantine manager .
Reference: Configuration options If this option is enabled, the file is deleted. This process is much faster than "overwrite and delete". overwrite and delete If this option is enabled, the Guard overwrites the file with a default pattern and then deletes it. It cannot be restored. rename If this option is enabled, the Guard renames the file. Direct access to these files (e.g. with double-click) is therefore no longer possible. Files can later be repaired and given their original names again.
Avira Premium Security Suite When this option is enabled, the execution of the Windows Autostart function is blocked on all connected drives, including USB sticks, CD and DVD drives and network drives. With the Windows Autostart function, files on data media or network drives are read immediately on loading or connection, and files can therefore be started and copied automatically.
Reference: Configuration options Note When specifying the process, you can use the wildcards* (any number of characters) and ?? (a single character). C:\Program Files\Application\application.exe C:\Program Files\Application\applicatio?.exe C:\Program Files\Application\applic*.exe C:\Program Files\Application\*.
Avira Premium Security Suite Note If a directory is excluded, all its sub-directories are automatically also excluded. Note For each drive you can specify a maximum of 20 exceptions by entering the complete path (starting with the drive letter). For example: C:\Program Files\Application\Name.log The maximum number of exceptions without a complete path is 64. For example: *.
Reference: Configuration options The process for the file application.exe, which is located under the path C:\Program Files1, is excluded from the Guard scan. – C:\Program Files1\*.exe All processes for executable files located under the path C:\Program Files1 are excluded from the Guard scan. Examples for files to be excluded: – *.mdb All files with the extension 'mdb’ are excluded from the Guard scan – *.xls* All files with a file extension beginning 'xls’ are excluded from the Guard scan, e.g.
Avira Premium Security Suite If this option is enabled, slightly less unknown malware is detected, the risk of false alerts is low in this case. Medium detection level This option is enabled as the default setting if you have selected the use of this heuristic. High detection level If this option is enabled, significantly more unknown malware is detected, but there are also likely to be false positives. 13.2.
Reference: Configuration options 13.2.2.1. Application filter: Applications to be blocked Under Application filter: Applications to be blocked you can enter applications which you classify as harmful and which you want Avira AntiVir ProActiv to block by default. The applications added cannot be executed on your computer system. You can also add programs to the application filter for blocking via Guard notifications of suspicious program behavior, by selecting theAlways block this program option.
Avira Premium Security Suite Applications The list contains applications excluded from monitoring by the ProActiv component. In the default installation settings, the list contains signed applications from trusted producers. You have the option of adding applications that you consider to be trustworthy via the configuration or via Guard notifications. The ProActiv component identifies applications using the path, the file name and the content.
Reference: Configuration options If this option is enabled, then Guard does not create a log. It is recommended that you should turn off the logging function only in exceptional cases, such as if you are executing trials with multiple viruses or unwanted programs. Default If this option is enabled, Guard records important information (concerning detections, alerts and errors) in the report file, with less important information ignored for improved clarity. This option is enabled as the default setting.
Avira Premium Security Suite If this option is enabled, email traffic is monitored by MailGuard. MailGuard is a proxy server which checks data traffic between the email server you use and the email client program on your computer system: incoming emails are scanned for malware by default. If this option is disabled, the MailGuard service is still started, but monitoring by MailGuard is disabled.
Reference: Configuration options Interactive If this option is enabled, a dialog box appears when a virus or unwanted program is detected in an email or attachment in which you can choose what is to be done with the email or attachment concerned. This option is enabled as the default setting. Show progress bar If this option is enabled, the MailGuard shows a progress bar during downloading of emails. This option can only be enabled if the option Interactive has been selected.
Avira Premium Security Suite 13.3.1.2. Other actions This configuration section contains other settings for actions performed when MailGuard finds a virus or unwanted program in an email or in an attachment. Note These actions are performed exclusively when a virus is detected in incoming emails. Default text for deleted and moved emails The text in this box is inserted in the email as a message instead of the affected email. You can edit this message. A text may contain a maximum of 500 characters.
Reference: Configuration options Advanced Heuristic Analysis and Detection (AHeAD) enable AHeAD Your AntiVir program contains a very powerful heuristic in the form of AntiVir AHeAD technology, which can also detect unknown (new) malware. If this option is enabled, you can define how "aggressive" this heuristic should be. This option is enabled as the default setting. Low detection level If this option is enabled, slightly less unknown malware is detected, the risk of false alerts is low in this case.
Avira Premium Security Suite This button deletes all entries from the list of permitted servers. Permitted Sender(s) All senders in this list are authorized by MailGuard to send emails: Emails sent from this email address are not blocked by MailGuard. If no senders are included the list, the email address used to send outgoing emails is not scanned. If the list is populated, MailGuard blocks emails from senders not included in the list. Input box Enter your email sender address(es) in this box.
Reference: Configuration options When this option is enabled, the email address is no longer scanned for spam. Up You can use this button to move a highlighted email address to a higher position. If no entry is highlighted or the highlighted address is at the first position in the list, this button is not enabled. Down You can use this button to move a highlighted email address to a lower position.
Avira Premium Security Suite 13.3.2.2. Cache Cache The MailGuard cache contains data regarding the scanned emails that is displayed as statistical data in the Control Center under MailGuard. Copies of incoming emails are also deposited in the cache. The emails can also be used for the anti-spam module's training functions (Good email – use for training, Spam – use for training). Note The anti-spam module must be activated for incoming emails to be backed up in the cache.
Reference: Configuration options When this option is enabled, a so-called "black list" is queried in real time, which provides additional information to classify emails of dubious origin as spam. Timeout: n second(s) If the information of a black list is not available after n seconds, the attempt to query the black list is aborted. Clear training database Click on the button to delete the training database.
Avira Premium Security Suite Reporting This group allows for the content of the report file to be determined. Off If this option is enabled, then MailGuard does not create a log. It is recommended that you should turn off the logging function only in exceptional cases, such as if you are executing trials with multiple viruses or unwanted programs.
Reference: Configuration options The Avira FireWall displays the adapter rules of all existing adapters on your computer for which a driver was installed. A predefined adapter rule depends on the security level. You can change the security level in the Online protection :: You can change the FireWall settings in the Control Center or define your own adapter rules. If you have defined your own adapter rules, in the FireWall section of the Control Center, the security level is set to custom.
Avira Premium Security Suite TCP port scan With this rule, you can define when a TCP port scan is assumed by the FireWall and what should be done in this case. This rule serves for preventing so-called TCP port scan attacks that result in a detection of open TCP ports on your computer. This kind of attack is used to search a computer for weak spots and is often followed by more dangerous attack types.
Reference: Configuration options add rule to block the attack. to block the attack. Ports With a mouse click on the link a dialog box appears in which you can enter the number of ports that must have been scanned so that a UDP port scan is assumed. Port scan time window With a mouse click on this link a dialog box appears in which you can enter the time span for a certain number of port scans, so that a UDP port scan is assumed.
Avira Premium Security Suite with mask at offset 0. – Deny TCP packets on 135 Deny TCP packets from address 0.0.0.0 with mask 0.0.0.0 if local ports in {135} and remote ports in {0-65535}. Apply for all packets. Don't log when packet matches rule. Advanced: Discard packets that have following bytes with mask at offset 0. – Monitor TCP healthy data traffic Allow TCP packets from address 0.0.0.0 with mask 0.0.0.0 if local ports in {065535} and remote ports in {0-65535}.
Reference: Configuration options Discard packets that have following bytes with mask at offset 0. – Deny all TCP packets Deny TCP packetsfrom address 0.0.0.0 with mask 0.0.0.0 if local ports are in range {0-65535} and the remote port is in range {065535}. Apply for all packets. Don't log when packet matches rule. Advanced: Discard packets that have following bytes with mask at offset 0.
Avira Premium Security Suite Application method With a mouse click on this link you have the choice to apply the rule for connection initiation and existing connection packets or only for packets of existing connections or for all packets. Report file By clicking on the link with the mouse you can decide whether to write to a report file or not if the package complies with the rule. The advanced feature enables content filtering.
Reference: Configuration options packets Deny UDP packetsfrom address 0.0.0.0 with mask 0.0.0.0 if local ports are in range {0-65535} and the remote port is in range {0-65535}. Apply for all ports. Don't log when packet matches rule. Advanced: Discard packets that have following bytes with mask at offset 0. Accept / reject UDP packets With a mouse click on the link you have the choice to allow or deny special defined incoming UDP packets.
Avira Premium Security Suite With a mouse click on the link a dialog box appears in which you can select a file that contains the specific buffer. Filtered content: Mask With a mouse click on the link a dialog box appears in which you can select the specific mask. Filtered content: Offset With a mouse click on the link a dialog box appears in which you can define the filtered content offset. The offset is computed from where UDP header ends.
Reference: Configuration options Filtered content: Data With a mouse click on the link a dialog box appears in which you can select a file that contains the specific buffer. Filtered content: Mask With a mouse click on the link a dialog box appears in which you can select the specific mask. Filtered content: Offset With a mouse click on the link a dialog box appears in which you can define the filtered content offset. The offset is computed from where ICMP header ends.
Avira Premium Security Suite By clicking on this link with the mouse, a dialog box opens in which you can enter the required IP protocol. Report file By clicking on the link with the mouse you can decide whether to write to a report file or not if the package complies with the rule. 13.4.1.2. Outgoing Rules Outgoing rules are defined to control outgoing data traffic by the Avira FireWall. You can define an outgoing rule for one of the following protocols: IP, ICMP, UDP and TCP.
Reference: Configuration options Application list This table shows the list of applications for which rules are defined. The application list contains the settings of each application that was executed and had a rule saved since the Avira FireWall was installed. Normal view Description Application Name of the application. Mode Displays the selected application rule mode : In filtered mode, adapter rules are checked and executed after execution of the application rule.
Avira Premium Security Suite carried out on all network activities performed by the software application. Advanced: With this type of filtering, the rules that were added to the extended configuration are applied. If you want to create specific rules for an application, select the Advanced entry under Filtering. The Rules entry is then displayed in the Action column. Click on Rules to open the window for creating specific application rules.
Reference: Configuration options Remove rule Removes the selected application rule. Reload Reloads the list of applications and simultaneously discards the changes just made to the application rules just made. 13.4.3 Trusted providers A list of trusted software producers is displayed under Trusted providers. You can add / remove producers to / from the list using the Always trust this provider option in the Network Event popup window.
Avira Premium Security Suite 13.4.4 Settings Advanced options Enable FireWall If the option is activated, the Avira FireWall is enabled and protects your computer from risks originating from the Internet and other networks. Stop Windows Firewall on startup If this option is enabled, the Windows Firewall is deactivated when the computer is rebooted. This option is enabled as the default setting.
Reference: Configuration options The application rules options are used to set the configuration options for application rules in the FireWall::Application rules section. Advanced options If this option is enabled, you can regulate different network accesses of an application on an individual basis. Basic settings If this option is enabled, only one action can be set for different network accesses of the application. 13.4.
Avira Premium Security Suite When this option is enabled, the option "Remember action for this application" in the dialog box "Network event" is enabled in the same way as for the last network event. If the option "Remember action for this application" was enabled, this option is enabled for the following network event. If the option "Remember action for this application" was disabled for the last network event, this option is also disabled for the following network event.
Reference: Configuration options The WebGuard section of the Configuration is responsible for the configuration of the WebGuard. 13.5.1 Scan WebGuard protects you against viruses or malware that reaches your computer from web pages that you load on your web browser from the Internet. The Scan heading can be used to set the behavior of the WebGuard component. Scan Enable WebGuard If this option is enabled, the web pages you request using an Internet browser are scanned for viruses and malware.
Avira Premium Security Suite Interactive If this option is enabled, a dialog box appears when a virus or unwanted program is detected during an on-demand scan, in which you can choose what is to be done with the affected file. This option is enabled as the default setting. Click here for more information. Show progress bar If this option is enabled, a desktop notification appears with a download progress bar if a download of website content exceeds a 20 second timeout.
Reference: Configuration options In this box, enter the names of the MIME types and file types you want WebGuard to block. For file types, enter the file extension, e.g. .htm. For MIME types, indicate the media type and, where applicable, sub-type. The two statements are separated from one another by a single slash, e.g. video/mpeg or audio/x-wav.
Avira Premium Security Suite In the Web filter list you can select the content categories whose URLs are to be blocked by WebGuard. Note The Web filter is ignored for entries in the list of excluded URLs under WebGuard::Scan::Exceptions. Note Spam URLs are URLs sent with spam emails. The Fraud and Deception category covers web pages with “Subscription Expires” and other offers of services whose costs are hidden by the provider. 13.5.1.3.
Reference: Configuration options – audio/ = All audio media type files are excluded from WebGuard scans – video/quicktime = All Quicktime sub-type video files (*.qt, *.mov) are excluded from WebGuard scans – .pdf = All Adobe PDF files are excluded from WebGuard scans. Add The button allows you to copy MIME and file types from the input field into the display window. Delete The button deletes a selected entry from the list. This button is inactive if no entry is selected.
Avira Premium Security Suite = All URLs with the domain 'www.avira.com' are excluded from WebGuard scans: www.avira.com/en/pages/index.php, www.avira.com/en/support/index.html, www.avira.com/en/download/index.html, etc. URLs with the domain 'www.avira.de' are not excluded from WebGuard scans. – avira.com -OR- *.avira.com = All URLs with the second and top-level domain 'avira.com' are excluded from WebGuard scans: The specification implies all existing subdomains for '.avira.com': www.avira.com, forum.avira.
Reference: Configuration options Your AntiVir product contains a highly powerful macrovirus heuristic. If this option is enabled, all macros in the relevant document are deleted in the event of a repair, alternatively suspect documents are only reported, i.e. you receive an alert. This option is enabled as the default setting and is recommended.
Avira Premium Security Suite Limit size to n MB If this option is enabled, the report file can be limited to a certain size; possible values: Permitted values are between 1 and 100 MB. Around 50 kilobytes of extra space are allowed when limiting the size of the report file to minimize the use of system resources. If the size of the log file exceeds the indicated size by more than 50 kilobytes, old entries are then deleted until the indicated size has been reduced by 20% .
Reference: Configuration options Password Protected To enable the parental control configuration, press the "Password Protected" button and enter the parental control password in the "Enter Password" window. Enable parental control If this option is enabled, all the web pages requested by the user while navigating in the Internet are scanned on the basis of the role assigned to the registered user in the parental control function.
Avira Premium Security Suite Note The roles that have already been assigned to a user cannot be deleted. Role properties The Edit button takes you to the Role Properties dialog where you can define the user role with prohibited and permitted URLs, as well as prohibited web content. The following options are available: – Prohibit access to URLs – Permit access to URLs – Block web content: You can select categories for web content to be blocked.
Reference: Configuration options Input box Enter the names of the file objects that are not to be saved in this box. The path for the temporary directory for the local settings of the logged-in user is entered as default. The button opens a window in which you can select the required file or the required path. You can isolate a particular file from the backup if you have the full name and path of the file.
Avira Premium Security Suite C:\Program Files\Application\applic?????.e* C:\Program Files\ C:\Program Files C:\Program Files\Application\*.mdb Lists of file extensions Consider all file extensions If this option is enabled, all files in the backup profile are saved. Enable backup of skipped file extensions If this option is enabled, all files in the backup profile are saved, except files whose extensions are entered in the list of excluded file extensions.
Reference: Configuration options 13.8 Update In the Update section you can configure the automatic receiving of updates. You can specify various update intervals and activate or deactivate automatic updating. Automatic update Activate If this option is enabled, automatic updates are performed for the enabled events at the specified interval. Automatic update every n days / hours / minutes In this box you can specify the interval at which the automatic update is performed.
Avira Premium Security Suite If this option is enabled, you will be notified by email when new product updates become available. Updates to the virus definition file and scan engine are performed independently of this setting. The conditions for this option are: complete configuration of the update and an open connection to a download server. You will receive notifications via a desktop popup window and via an alert from the Updater in the Control Centre under Overview::Events.
Reference: Configuration options Reminder message for restart every n seconds If this option is enabled, the restart which is necessary after a product update has been executed is not performed automatically. At the specified interval, you will receive restart notifications without cancel options. These notifications let you confirm the computer restart or select the "Remind me again" option.
Avira Premium Security Suite 13.9.1 Threat categories Selection of threat categories Your AntiVir product protects you against computer viruses. In addition, you can scan according to the following extended threat categories.
Reference: Configuration options Areas protected by password Your AntiVir program can protect individual areas with a password. By clicking the relevant box, the password request can be disabled or re-enabled for individual areas as required. Password-protected area Function Control Center If this option is enabled, the pre-defined password is required to start the Control Center.
Avira Premium Security Suite Configuration Enable expert mode Installation / Uninstallation If this option is enabled, configuration of the program is only possible after entering the predefined password. If this option is enabled, the pre-defined password is required to enable expert mode. If this option is enabled, the pre-defined password is required for installation or uninstallation of the program. 13.9.
Reference: Configuration options If this option is enabled, all registry entries of the program and all program files (binary and configuration files) are protected from manipulation. Protection against manipulation entails preventing write, delete and, in some cases, read access to the registry entries or program files by users or external programs. To enable this option, you have to restart your computer.
Avira Premium Security Suite Warning If you are using a proxy server which requires authentication, enter all the required data under the option Use this proxy server. The Use Windows system settings option can only be used for proxy servers without authentication. Use this proxy server If your web server connection is set up via a proxy server, you can enter the relevant information here. Address Enter the computer name or IP address of the proxy server you want to use to connect to the web server.
Reference: Configuration options 13.9.7 Events Limit size of event database Limit maximum number of events to n entries If this option is enabled, the maximum number of events listed in the event database can be limited to a certain size; possible values: 100 to 10000 entries. If the number of entered entries is exceeded, the oldest entries are deleted.
Avira Premium Security Suite If this option is enabled, there is an acoustic alert with the default signal when a virus is detected by the Scanner or Guard. The acoustic alert is sounded on the PC’s internal speaker. Use the following Wave file (interactive mode only) If this option is enabled, there is an acoustic alert with the selected Wave file when a virus is detected by the Scanner or Guard. The selected Wave file is played over a connected external speaker.
This manual was created with great care. However, errors in design and contents cannot be excluded. The reproduction of this publication or parts thereof in any form is prohibited without previous written consent from Avira GmbH. Errors and technical subject to change. Issued Q2-2011 AntiVir® is a registered trademark of the Avira GmbH. All other brand and product names are trademarks or registered trademarks of their respective owners. Protected trademarks are not marked as such in this manual.