FAQs about IKARUS anti.virus with cloud Interface
IKARUS anti.virus
IKARUS anti.virus
Yes, IKARUS anti.virus interacts with the Windows Security Center API and disables Windows Defender during installation.
The exact behavior depends on the Windows or Windows version.
On the AD server in Group Policy. Policy -> Administrative Template -> Windows Components -> Windows Defender -> Disable Windows Defender: Activates
Alternatively, real-time protection -> Disable real-time protection: Enabled
The reason for this is that during the wizard installation Windows permissions for “C:WindowsTemp” and C:WindowsInstaller” are missing.
The silent installation is not affected by this and can be used for installation.
No, a restart after the installation is not necessary.
A GUID is created for each device.
Yes, a restart after uninstalling is mandatory.
The AV Remover can be found at IKARUS anti.virus remover
This can happen when we distribute a new AV version. The rollouts are spread over several days. Only when the regular rollout is finished, the new version will be kept as the latest version in the database.
No, the client does not differentiate between the systems.
System requirements
All Windows versions supported by Microsoft on 64bit (Intel/AMD/ARM)
Yes – but only as File Antivirus, as on any Windows server.
IKARUS anti.virus does not provide email protection within Exchange.
The client is terminal server capable.
Exceptions can be created via the AV portal and locally via the client.
The exclusions always apply, even for a scan profile.
No, IKARUS anti.virus was designed for monitoring and securing endpoints.
To scan network drives, IKARUS anti.virus can also be installed on file servers and perform regular scans there.
The answer is yes, the size for on-access scans is the predefined 128 MB, this value cannot be changed.
On-demand scans can limit the size of the files to be scanned. For example: Do not scan files larger than 1 MB. This limit can be adjusted to up to 8 GB in the settings under Exclusions. If no adjustments are made, the default size is 128 MB.
Please use Microsoft’s documentation and information on the respective server.
Files can be sent to IKARUS for analysis via Quarantine -> Right-click on the virus and send to IKARUS.
Please send an email with the infected file to probe(at)ikarus(dot)at. The file will be analyzed there.
A local virus scanner or one integrated in the firewall can remove the file when sending it.
This removes the entries from the quarantine list.
Entries older than 7 days are automatically removed from the list.
IKARUS anti.virus does not move any files.
As soon as a contaminated file is found on a computer, IKARUS anti.virus blocks it (copying and executing the file is no longer possible) and displays it in quarantine.
A special case is a corrected false alarm: The quarantine checks as soon as it is opened whether all entries are still verifiable.
If the virus database has been updated in the meantime and the entries are no longer verifiable with the current VDB, they are removed from quarantine and the files are released again.
This feature can be configured via the AV Portal. See also Configuration Profiles
IKARUS anti.virus Client cannot perform NTLM authentication on the client.
As a workaround, an authentication exception can be set up in the HTTP proxy.
.*.ikarus.at
.*.mailsecurity.at
For more information, see the Wiki article -> HTTP proxy and IKARUS anti.virus
A license is required for one operating system instance (Windows). This applies to installations directly on the hardware (bare metal) as well as for virtual instances. The licensing is identical for client and server operating systems. A further distinction does not exist.
When uninstalling, the activation is removed in the portal.
Updating the license reloads the information about the license and devices.
Yes, notifications can be set up in the license for reaching a number of activations.
Via the AV portal or under Extras -> Settings -> Extras in the client.
No, the administration is only possible via the AV portal in the reseller portal.
USB ports cannot be blocked, but can be checked when plugged in.
See Client Overview
If transparent mode is activated in the HTTP proxy, these rules must be entered as exceptions in the virus scanner.
^[^:]*://[^.]*.ikarus.at/
^[^:]*://[^.]*.mailsecurity.at/
For the complete log, all for options under
Extras -> Settings -> Protocols
must be activated.
Extras -> Protocols
C:Program FilesIKARUSanti.viruslog
info [ 870](compattelrunne,2,s)[s] on-access scan of "c:Program Files (x86)Mozilla
Thunderbirddistributionextensions{e2fda1a4-762b-4020-b5ad-a41df1933103}chrome.jar", size 1048196 B,
CRC: 5188e7c97a1401c3 in 1.008 sec [B: 0.003 C1: 0.0000 C2: 0.0000 S: 1.005 A: 0.0000]
Description:
AV_Registration: INFO: Using TID for registration: xxxx-xx-xx-xx-xxxxxx
AV_Registration: INFO: No proxy will be used for connection.
AV_Registration: INFO: Connecting to server: https://avitc.ikarus.at
AV_Registration: ERROR: Could not establish connection to the server. Please check your internet connectivity.
Cause: No connection to the backend servers.
Solution: Check the Internet connection.
CAQuietExec: Entering CAQuietExec in C:WindowsInstallerMSIF3D9.tmp, version 3.11.2318.0
CAQuietExec: ” C:Program FilesIKARUSanti.virusbinguardxservice_x64.exe” -install
CAQuietExec: Service already installed, but stopped. Starting it.
CAQuietExec: Error: Starting service ‘start service: :(2) The system cannot find the specified file. ‘
CAQuietExec: Error 0xffffffff: Command line returned an error.
CAQuietExec: Error 0xffffffff: QuietExec Failed
CAQuietExec: Error 0xffffffff: Failed in ExecCommon method
CustomAction InstallService64 returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
Cause: Residuals present on the operating system after the AV could not be installed correctly.
Solution: Remove the remains with AV Remover.
AV_Registration: INFO: Backend return code: 402
AV_Registration: ERROR: An error occured while checking validity of License. Aborting!
AV_Registration: ERROR: The server returned an error message: ‘License TID has reached usercount limit!‘
Reason: No further activations available, the license is full.
Solution: The license must be checked.
AV_Registration: INFO: Connecting to server: https://avitc.ikarus.at
AV_Registration: ERROR: Could not establish connection to the server. Please check your internet connectivity.
Returncode: 400 BAD_REQUEST
Response:
Cause: SSL interception without exceptions.
Solution: Exceptions for SSL interception must be entered in the firewall.
Error: Starting service ‘start service starten : :(577) The digital signature of this file cannot be verified.
A recent hardware or software change may have installed an incorrectly signed or corrupted file or a file that is malicious software from an unknown source.
Cause 1:
Operating system is Windows 7: The update KB3033929 is missing (support for SHA-2 certificates)
Solution 1:
Install KB3033929 and reboot the operating system.
Cause 2:
Operating system is not Windows 7: AV was already installed and there are still remnants of the service or driver.
Solution 2:
Remove the remnants of the installation with the remover and then perform installation.
It is possible to participate as a verified reseller in the Reseller Preview.
Activation in the AV Portal / menu Configuration Profiles / edit corresponding profile / tab Client Configuration / last entry: Participate in Reseller Preview / activate and save & transfer
The abbreviation stands for Possible Unwanted Program (or Application) and means translated a possibly unwanted program.
This term is used to define programs and applications that are of no use to the user or are not desired by him.
PUA and PUP applications are not removed from the virus database.
Here you can either set an exclusion for the file paths or deactivate scanning for potentially unwanted applications in the Guard.
The portal is hosted on our georedundant servers in Germany.
The client checks every 60 seconds if the status has changed, if there has been a change it is reported to the portal.
Infections are transmitted immediately after detection.
If the client has not connected to the backend for 7 days, the job will be marked as failed.
The status in the portal in the action log then changes from pending to failed.
Is there a rescue CD?
There is no IKARUS anti.virus Rescue CD.
The names can be renamed using the AV Portal.
The cache limit for all operating systems under Windows 10 can be adjusted using the following script. If you have any questions, please contact our support.
@echo off
echo Detecting installation…
for /f “tokens=2*” %%a in (‘REG QUERY “HKEY_LOCAL_MACHINESoftwareIkarusguardx” /v MainPath’) do set “AppPath=%%~b”
echo SPAV found in %AppPath%
“%AppPath%binguardxup” -cfgwrite “%AppPath%confguardx.conf” cache/limit 4000000
echo .
echo The Limit for the Cache has been updated.
pause.
IKARUS Security Software GmbH Blechturmgasse 11
1050 Vienna
Phone: +43 1 58995-0
Sales Hotline:
+43 1 58995-500
sales@ikarus.at
Support hotline:
+43 1 58995-400
support@ikarus.at
Support hours:
Mon – Thu: 8am – 5pm
Fri: 8am – 3pm
24/7 support by arrangement
Remote maintenance software:
AnyDesk Download