eScan BlogeScan Blog    eScan WebsiteeScan Website    eScan ForumeScan Forum    eScan FeedseScan Feeds     

From eScan Wiki

Jump to: navigation, search
· eScan  · MailScan  · Technologies   · Technical Info  · Security Awareness  · User Guides


Back to FAQs Main Page

eScan Configuration

  1. What is Rule-Set?
  2. How does Rule-Set gets updated?
  3. Can I manually configure Rule-Set to meet my requirement?
  4. Can I install eScan on a Standalone PC?
  5. Is there more than one type of eScan?
  6. Can I install eScan on any version of Windows?
  7. Can any PC be configured as eScan Server?
  8. What are the requirements for eScan Server?
  9. Do I need a dedicated system for eScan Server?
  10. What is the Pre-requisite before deploying eScan installation / Rule-Set on client system from eScan Management Console?
  11. Do I need to define the Server's IP Address on the eScan Client?
  12. If I change the IP Address of my eScan Server or in case I change my eScan Server, do I need to re-configure all the eScan clients with the eScan Server's new IP Address?
  13. Can I have multiple eScan Server? If Yes, How?
  14. Can I configure two eScan Servers as Master, for redundancy?
  15. Can I restrict the user from disabling eScan? If Yes, how?
  16. While installing eScan do I have to change any settings in my email client?
  17. Are there any compatibility issues with MS-MWL?
  18. Can eScan be deployed over the network using the Microsoft Management Console (MMC)?
  19. I have installed eScan and due to some problem, I had to uninstall it. But now I am unable to browse the Internet and do other Internet activities. How can I restore my computer back to normal?
  20. After installing eScan, I am unable to browse the Network Neighbourhood.What could be wrong?
  21. When I have more than 250-300 eScan clients connected to my eScan Server, the CPU utilization goes upto 100%?
  22. On eScan Clients, I want to change the Mail-Server IP number to which warning messages should be sent. How can I do it from eScan Server?
  23. When I upgrade my eScan, after running the setup file, the progress bar gets stuck at 0% and does not move at all.What should I do?
  24. How do I retrieve emails that has been quarantined by eScan inside the Quarantine Folder?
  25. When the auto-update runs there is activity running on the WWW proxy in WinGate. It appears that eScan is trying to go to . Any idea why does auto update go to that URL?
  26. How do I deploy customized warning messages I have created on my eScan Server to all my eScan clients?
  27. I have installed eScan on my Laptop. Now my Laptop never does a clean shutdown. It just seems to wait indefinitely. What should I do?
  28. Client is using Novell Netware 4.11. All email comes in through Wingate Proxy Server located on Windows 2000 Professional system. If the workstations are protected with eScan and the email server is also protected, does the Netware Server needs a scanner for viruses?
  29. I had a customer reporting that with eScan installed, his XP machine was constantly crashing (BSOD) with an error referencing avkfilt.sys.All other XP machines on the network, running the same version of eScan, were experiencing no problems! What could be the possible remedy?
  30. I have installed eScan on my machine. But it does not scan emails sent using Outlook Express. What could be the problem? I use Microsoft Proxy Client to access my Mail Server.?
  31. I have installed ZoneAlarm Firewall. After installing eScan,I keep getting messages from ZoneAlarm about download.exe, trayicos.exe, etc. trying to connect to Internet. What should I do?
  32. Can I have multiple Anti-Virus softwares / programs running on my PC simultaneously?
  33. During installation of eScan,it asks me for a reboot. After rebooting, the installation continues, again asking me for a reboot.What should I do?
  34. I have installed eScan on my Windows 2000 computer. When I login as an Administrator, everything works fine. But if I login as an ordinary user, my mails and web stop working. What should I do?
  35. I have installed eScan on my Windows XP Pro. When I log in as an administrator, all functions work fine. But if I login as a normal user, Outlook and other Net related functions stop working! What should be done?
  36. Are there any incompatibility issues between Zone Alarm Basic and eScan/MailScan?
  37. My eScan clients are unable to recognize the eScan Server. The Server does make proper announcements and no errors are logged too. What should be done?
  38. Can I scan my network drives from one PC?
  39. Can I manually install eScan Corporate as a client using the setup file cwn2k3ek.exe without being prompted for the default mode message "Do you want to make this System as eScan Server?
  40. While deploying Rule-Set on the client system with the Merge Option selected from eScan Management Console, the Rule-Set does not merge with the existing rules on the client. How does the Merge Option work?
  41. How can I block an USB drive access in eScan version 10?
  42. After installing eScan on Windows 2008 64 Bit Edition, DNS, ADS does not work and are not able to connect to internet or LAN?
  43. How do I remove Firewall driver without uninstalling eScan?
  44. How do I install Firewall driver?
  45. What does the entry deleteflags does under MailScan.ini?
  46. Can eScan take backup of infected files before disinfecting it?
  47. Is there any utility to add multiple email IDs in eScan Auto-Spam Whitelist?
  48. A lot of disk space is occupied by eScan FBackUp folder in my Local Drive. What is the use and how can we configure it?
  49. How can I display IP Address of client computers under "Normal View" in eScan Management Console?
  50. How can I configure my system to block eScan Popups?
  51. How can I change the port settings for my eScan server and deploy it using the eScan management console (EMC)?
  52. A vulnerability tool identifies MWAgent as a high security risk. It can be exploited to cause a stack-based buffer overflow via an overly long command sent to the service (default port 2222/tcp)?
  53. Can the tools menu be removed or disabled?
  54. After Installing eScan, users/recepients start receiving the notification emails with "Subject: eScan found an email having Virus or objectionable content!?"
  55. Can we automate the installation of eScan Internet Security Suite?
  56. How can I install eScan silently ? And also it should reboot automatically after completion of the installation
  57. How to White-list a file blocked during proactive scanning?
  58. How to disable eScan Notification pop-up message when a spam / virus infected email /attachment has been detected by eScan Anti-Spam/Mail Antivirus module ?
  59. How to manually whitelist a Malware URL ?
  60. How can I deny RDP access of a server from any ip address?
  61. How can I allow RDP access to only specific ip address?

  1. What is Rule-Set?

    Rule-Set are set of rules defined within eScan.
    For Example:
    If you define a rule that any file with the name KAK.HTA should be deleted.
    eScan will detect this file and if found will delete it.

Back to Top

  1. How does Rule-Set gets updated?

    Whenever we confirm the existence of a new Virus (or a Worm, etc) in the form of a standard filename, we update the Rule-Set on the Internet Server. So, when eScan connects to Internet to download the latest updates, it even updates the Rule-Set.

  2. Can I manually configure Rule-Set to meet my requirement?

    Yes, you can configure the Rule-Set to meet your requirement.

  3. Can I install eScan on a Standalone PC?

    Yes. For this, you need to install Professional Edition of eScan (version 9) or eScan SOHO/Home Edition rather than the Corporate Edition / Enterprise (version 9 or 10) or SMB/SME edition (version 10).

  4. Is there more than one type of eScan?

    Below are the editions of eScan:
    Version 10
    • eScan SOHO/Home edition
    This edition is designed for standalone platforms (eg at home)
    • eScan SMB/SME edition
    This edition is designed for Small and Medium Business organizations.
    • eScan Corporate/Enterprise edition
    This edition is designed for Large organizations.</I>
    Version 9
    • eScan Pro
    This edition is designed for standalone platforms (eg at home)
    • eScan Corporate
    This edition is designed for networked platforms, and includes the `eServ' Central Management Console.
    • eScan Enterprise
    This edition is designed to protect entire Networks and incorporates both the 'eServ' Central Management Console and various editions of 'MailScan'.
    • eScan VC (Virus Control)
    eScan VC has only the Virus Control features. It does not have Content-Analyzing features.

  5. Can I install eScan on any version of Windows?

    Yes. In fact, eScan version 9 is available for the DOS and Win3.1 platforms, as well as Win95, Win98, Win98SE, WinME, WinNt 4.0 Workstation / Server, Win2000 Pro / Server / Datacenter Server and Windows XP Platforms.
    While eScan version 10 is available for Windows 2000 (SP4), Windows XP Home/Professional, Windows XP 64-bit, Windows Vista Ultimate/Home Premium, Windows Vista Home, Basic/Business/Enterprise. Support for 98/ME/NT, will be provided soon.</I>

  6. Can any PC be configured as the eScan Server?

    Yes. You can configure any PC as the eScan Server provided that PC has access to the Internet.

  7. What are the requirements for eScan Server?

    For eScan to be installed in Server mode, you will need a PC which has Internet connectivity.

  8. If I make one PC as eScan Server, can I work on that PC? Does it need to be a dedicated PC?

    The eScan Server does not require a dedicated PC. You can use the eScan Server for other duties and run other applications without any problems.

  9. What is the pre-requisite before deploying eScan installation / rule-sets on client systems from the eScan Management Console?


    Below are the settings that is required to be configured on the client system:

    I) For Win 2000 system, Only to set Administrator Password at eServ.

    II) For Win XP PRO systems
    a)On the Windows XP Go to Control Panel - Administrative Tools - LocalSecurity Policy
    b)Click on Local Policies - Security Options
    c)On the Right hand Side Double click the option "Network Access: Sharing and Security Model for Local accounts"
    d)Change the default mode to "Classic - Local user authenticate as themselves.
    e)Change the value of the entry, "Accounts: Limit local account use of blank passwords to console logon only" to "Disabled".
    f)And if fireWall is enabled we need to Allow "File and Printer Sharing" option in "Exceptions" Section of Firewall.
    III) For Win Xp Home:
    Mwagent should be installed on the PC.
    Click here to download the MWAGENT
    IV) For Windows Vista & Windows 7
    a) Goto Start->Run, type secpol.msc
    b) Click on Local Policies - Security Options
    c) On the Right hand Side Double click the option "Network Access: Sharing and Security Model for Local accounts"
    d) Change the default mode to "Classic - Local user authenticate as themselves.
    e) Change the value of the entry, "Accounts: Limit local account use of blank passwords to console logon only" to "Disabled".
    f) And if fireWall is enabled we need to Allow "File and Printer Sharing" option in "Exceptions" Section of Firewall.
    g) Right click on My Computer -> Manage -> Local Users and Groups -> Users
    h) On the right hand side double click the account "Administrator"
    i) Uncheck Password never expires and Account is disabled -> ok
    j) Right click on the account "Administrator" -> set password -> proceed -> new password -> confirm password -> ok

  10. Do I need to define the Server's IP address on the eScan Client?

    No. The eScan server has an announcement mechanism wherein it broadcasts its availability over the network. All the eScan clients will listen to this broadcast & update themselves with the eScan Server's IP address.

  11. If I change the IP address of my eScan Server or in case I change my eScan Server, do I need to re-configure all the Clients with the eScan Server's new IP address?

    No. Since the eScan Server will now broadcast its new IP address, all eScan clients will automatically sense this change & will accordingly update their configuration files.

  12. Can I have multiple eScan Servers? If Yes, Why?

    Yes, you can have multiple eScan Servers. We recommend you to have at least two (2) eScan Servers since, in case one goes down, the other will take care of the eScan clients.
    This provides redundancy and additional protection for your network.

  13. Can I configure two eScan Servers as Masters, for redundancy?

    Yes. You can do that. In this case, both eScan Master Servers will announce on different ports & eScan clients will attach themselves to the Server whose announcement they get first.

  14. Can I restrict the user from disabling eScan? If Yes, how?

    Yes, you can.
    At the time of installation eScan prompts for "Should user be given the option to disable background monitoring". If you select NO, it won't allow the user to make any changes or disable eScan.

  15. While installing eScan do I have to change any settings in my email clients?


  16. Are there any compatibility issues with MS-MWL?

    a) We are currently in the process of resolving certain issues with Lotus notes R4.6 & SendMail NT. This work is expected to be completed shortly and an appropriate product update will be issued ASAP.
    b) We have also identified an issue for platforms running Novell Client/32 with WinSock 2 - they do not seem to interoperate. We are still seeking to resolve this issue.
    Please Note that this is NOT an eScan problem - it is a problem between Client/32 and WinSock 2.

  17. Can eScan be deployed over the network using the Microsoft Management Console (MMC)?

    This is not been tested so far. The FAQ will be updated as soon as the testing is complete.

  18. I have installed eScan & because of some problem, I had to uninstall it. But I am unable to browse the Internet & do other Internet activities! How should I bring my computer back to normal?

    Click on Start >> run
    and type INST_TSP 2 & press OK. Restart the machine & you should be able to browse the Internet.

  19. After installing eScan, I am unable to browse the Network Neighbourhood! What could be wrong?

    Run regedit.exe, Goto

    Set the value of

    IRPStackSize (DWORD) to 12 (hexadecimal 0x0C).
    After the setting is done, reboot your machine. This should solve your problem.

  20. When I have more than 250-300 eScan clients connected to my eScan Server, the CPU utilization goes upto 100%!

    We recommend eScan Server PC to have atleast 512MB RAM for heavy loads (upwards of 500 clients) and pagefile size should be double your RAM. Please make necessary modifications and then check.


    If the 100% problem still persists, do the follow
    A. Close eServ Application
    B. Edit the ESERV.INI file and set FTPMaxClients=2
    C. Start eServ.
    D. When the eServ reaches 100%, kill the eServ application (Using Task Manager).
    E. Check your eServ.LOG file
    F. See which machine last connected to the eServ application (Every machine that connects to eServ for FTP download of updates, will have two entries in eServ.LOG. First entry will be "FTP Connection initiated from x.x.x.x" and a corresponding "FTP Connection terminated from x.x.x.x". The last machine whose connection was initiated BUT NOT terminated, might be causing the problem). Note down this IP number.
    G. Edit eServ.INI file & set FTPConnectionsDisallowedFromIP = <this IP number> (this is comma separated list).
    H. Restart eServ.exe

  21. On eScan Clients, I want to change the Mail-Server IP number to which warning messages should be sent. How do I do it from the eScan Server?

    Run eScan Content Administrator
    • Click on Scanner Administration - Port Configuration (...)
    • Put the desired SMTP address in the field

    "Warnings to SMTP Server"

    • Save and exit out of eScan Content Administrator.
    • Double-click on eScan Management Console (eServ)
    • Click on Services - Deploy Rule-Sets.
    • Click on MailScan Settings - Click on Deploy.
    When clients pull the update, it will take the Mail-Server IP to the SMTP Address that you have entered above.

  22. When I upgrade my eScan, after running the setup file, the progress bar gets stuck at 0% & doesn't move at all!What could be done?

    In the eScan directory, you will find a file LOADED.SEM. Try deleting this file & then running the setup file.

  23. How do I retrieve any of the emails that has been quarantined by eScan inside the Quarantine Folder?


    Go to the eScan Quarantine Folder.
    a. Identify the eMail you want by checking the MSG files.
    b. Rename the required .MSG file(s) to .EML
    c. Disable eScan eMail Scanning facility (right-click on eScan icon in task-tray and click on disable email scan).
    e. Start Outlook
    f. Send yourself an email with the .EML file(s) as an attachment.

  24. Also when the auto-update runs there is activity showing in the WWW proxy in WinGate. It appears that eScan is trying to go to . Any ideas why the auto update would try to go to that URL?

    Answer: is a page which has the date and time of the last updated file.
    MailScan Auto-Updater downloads this information after a scheduled interval to check whether new updates have arrived. Once MailScan gets this info, it then contacts one of the many FTP servers to download the latest update.
    Microworld's FTP server is the first FTP-server to get updated.Updates are mirrored to all other FTP servers from our server.
    If you disable Automatic Updates, the access to sendinfo will stop.
    NOTE: This will happen only in eScan version 9.

  25. How do I deploy the customised warning messages I have created on my eScan Server to all my eScan clients?


    From the DOS prompt go to MailScan Folder.

    Copy *.SND to C:\PUB\UPDATE
    When eScan clients update, they will also take the Warning Message Template from the eScan Server.

  26. I have installed eScan on my Laptops. Now my Laptop never does a clean shutdown! It just seems to wait indefinitely.What could be done?

    When you shutdown your machine, eScan checks your floppy drive to see if a floppy has been accidently left & if so, checks the floppy's boot-sector for viruses. This check could be causing the problem.
    To disable the check, go to eScan folder, edit the eupdate.ini file, set CheckFloppyOnReboot=0 and reset the PC after saving the file. This should solve your problem.

  27. Client is using Novell Netware 4.11. All email comes in through Wingate proxy server located on Windows 2000 PRO system. If the workstations are protected with escan and the email server is protected does the netware server need a scanner for viruses?

    Netware Server does not need a scanner for Viruses. Install MailScan for Mail Servers on your Wingate Server and install eScan on the Workstations. This will ensure that all your Mails are scanned for Viruses and Virus does not enter your network.
    You do not require a Scanner on the Netware Server. You can always scan the Netware volumes from the Workstations having eScan.Just map netware volume on the Workstation and scan these drives thru eScan.

  28. I had a customer reporting that with eScan installed, his XP machine was constantly crashing (BSOD) with an error referencing avkfilt.sys. All other XP machines on the network, running the same version of eScan, were experiencing no problems! What could be the possible remedy?

    Turn off the Alerter service within the Window's services. This should solve your problem.

  29. I have installed eScan on my machine. But it does not scan emails sent using my Outlook Express! What could be the problem? I use Microsoft Proxy Client to access my Mail Server.


    If you are using the Microsoft Proxy Client on your PC, do the following:

    a. Uninstall Microsoft Proxy Client.
    b. Uninstall eScan.
    c. Reboot the PC
    d. Install Microsoft Proxy Client
    e. Install eScan.
    If you install MPC *after* installing eScan, eScan will not be able to scan email traffic.

  30. I have the ZoneAlarm Firewall installed. After installing eScan, I keep gettings messages from ZoneAlarm about download.exe,trayicos.exe, etc. trying to connect to the Internet! What should I do?


    Please exclude the following executables from inside ZoneAlarm:

    After excluding the above, you will not get any messages.

  31. Can I have multiple anti-virus softwares / programs running on my PC simultaneously?

    No. Two simultaneous antivirus softwares on the same PC can cause System Crashes, data loss and/or freezing. So please uninstall any anti-virus you already have installed, before installing eScan.

  32. After installation of eScan, it asks me for a reboot. After reboot,the installation continues, but it yet again asks me for a reboot!!!How should I get over this problem?

    This happens because of incomplete eScan installation or improper uninstallation of an earlier version of eScan.

    To overcome this problem, do the following:

    • When eScan asks for reboot, *do not* click on Yes or No.
    • Come to the MSDOS prompt, change directory to the eScan\TEMP folder and
    • run the command "AVKWCTL /unregserver". Exit out of command prompt & then click on Yes (for the question "reboot to continue installation?").

  33. I have installed eScan on my Windows 2000 computer. When I login as an Administrator, everything works fine. But if I login as an ordinary user, my mails & web stop working! What could be the problem?

    Please give full rights to everyone for the eScan folder and read access to the WINNT\System32 folder. This should resolve the issue.

  34. I have installed eScan on my Windows XP Pro. When I log in as an administrator, all functions work fine. But if I login as a normal user, Outlook and other Net related functions stop working! What should be done?

    For eScan to function properly when normal users are logged on, you need to give proper access rights for the eScan folder.

    Please follow the following step-by-step approach & the problem should be solved.

    a. Go to Start--> Control panel--> Folder Options
    b. Go to View tab UNCHECK the "Use Simple File Sharing" Option & Close.
    c. Go to Windows Explorer
    d. Right Click on the eScan Folder & select Properties &/OR Share & Security Option.
    e. Select Security Tab on top
    f. You need to add the user or the group in "Group Or User Names:" Window.
    g. To do so select Add --> Advanced --> Find Now.
    h. Select the user from the list given below & Click on "OK" button.
    i. Now Highlight the User Just added & Check the Full Control Option in the permission list window.

  35. Are there any incompatibility issues between Zone Alarm Basic and eScan/MailScan?

    Yes. Few have been reported. To remove any incompatibilities,please install eScan/MailScan first & then install Zone Alarm.

  36. My eScan clients are unable to recognize the eScan Server! The Server does make proper announcements & no errors are logged too. What should be done?

    Please check if you have some Software package like Norton Internet Security/ or Zone Alarm or similar softwares / products installed. These softwares stop UDP broadcast on ports being used by eScan Server and also stop eScan Server from acting like an FTP/HTTP server.
    Add eServ.exe to the exclude list of NIS/ZA or if this is not possible, instruct these softwares / products to allow communication on default eScan ports of 2001, 3333 and 2021.

  37. Can I scan my network drives from one PC?

    Yes. But, for this, you need to map the network drives.

  38. Can I manually install eScan Corporate as a client using the setup file cwn2k3ek.exe without being prompted for the default mode message i.e. "Do you want to make this System as the eScan Server?"

    Yes. You can install eScan Corporate as a client using the setup file cwn2k3ek.exe without the default message being displayed during the installation.
    To directly install eScan Corporate as an eScan client without being prompted for the default mode "Do you want to make this System as the eScan Server?" message, rename the setup file cwn2k3ek.exe as client.exe. When you execute the client.exe, the setup will be installed as eScan client directly.
    Similarly, if you want to install eScan Corporate as an eScan Server without being prompted for the default mode "Do you want to make this System as the eScan Server?" message, rename the file cwn2k3ek.exe as server.exe. When you execute the server.exe, the setup will be installed as eScan server directly.

  39. While deploying rule set on the client system with the Merge Option selected from the eScan Management Console, the rule sets does not merge with the existing rules on the clients. How does the Merge Option work?

    While deploying rule set using EMC if Merge option is selected, then only following files will be merged, apart from these files no other feature gets merged.
    a. Phrases.txt

    MWL Exclusion List
    b. Exclude.dat

    MWL Inclusion List
    c. Include.dat

    Web Protection
    d. Groups.TXT
    e. KidsGro.txt
    f. TeenagerGro.TXT
    g. AdolescentGro.TXT
    h. AdultGro.TXT
    i. Popup_WhiteList.txt

    All files in Groups folder

  40. How can I block an USB drive access completely in eScan version 10?


    To block an USB drive access completely follow the below steps:

    a) Open the eScan Protection Center,
    b) Click on Endpoint Security feature in the Protection section and then click on the Settings options,

    c) In the Endpoint Security Settings window, go to the USB Control tab. Check the Enable USB Control and then check the Block USB Ports

    d) To save the settings, click on the Apply and then the OK button.

  41. After installing eScan on Windows 2008 64 bit edition, DNS, ADS doesn't work and also not able to connect to internet or LAN?

    a. Click on Start

    b. Click on Run. In the Run box type cmd and click on OK

    c. In the command prompt, go to windows folder (i.e. %windir%) and type
    inst_tsp 2 2

    then type

    inst_tspx 2 2

    d. Then rename the inst_tsp.exe to inst_tsp.old

    and then rename inst_tspx.exe to inst_tspx.old

    e. Restart the machine.

  42. How do I remove Firewall driver without uninstalling eScan?

    a. Click on Start

    b. Click on Run. In the Run box type cmd and click on OK

    c. Go to eScan installed directory and execute the command
    snetcfg.exe -v -u nt_econceal

    [in Windows XP (64bit), Windows Vista and above]

    snetcfg.Vista32.exe -v -u nt_econceal

    [in Windows XP (32 bit) and Windows 2003]

  43. How do I install Firewall driver?

    a. Click on Start

    b. Click on Run. In the Run box type cmd and click on OK

    c. Go to eScan installed directory and execute the command
    snetcfg.exe -v -l econceal.inf -m econceal_m.inf -c s -i nt_econceal
    [in Windows XP (64bit), Windows Vista and above]
    snetcfg.Vista32.exe -v -l econceal.inf -m econceal_m.inf -c s -i nt_econceal
    [in Windows XP (32 bit) and Windows 2003]

    d. Restart the computer

  44. What does the entry "deleteFlags" under mailscan.ini stands for in Microworld products.?


    Under MailScan.ini

    • If deleteflags = 2 then it will delete SURBL related emails
    • If deleteflags = 1 If tagged by bayesian filter it will delete those emails ( 2 +1 =3 means delete both type of emails )
    • If deleteflags = 0 then it will quarantine the emails

  45. Can eScan take the backup of infected file before disinfecting it?

    Yes, eScan can take backup of infected file before disinfecting it during Real Time Monitoring. The backup is stored and available for "Restore".

    To configure eScan Real Time monitor to enable Backup of infected files before Disinfection,

    a. Open the eScan Protection Center
    b. Go to File Antivirus and Click on Settings.
    c. In the Objects tab, under Actions in case of Virus Disinfection expand Disinfect and check the Make Backup File Before Disinfection. Then apply the setting.

    To access the infected backup file, please do the following:

    a. Open the eScan Protection center
    b. Go to File Antivirus and click on View Quarantine objects and go to the "Backup" tab.
    (On your hard drive it will be located under C:\Program Files\eScan\Infected in an encrypted format).

  46. Is there any utility to add multiple email ids in Auto-Spam White list in eScan?

    Yes. We have a utility called "vereml" which will import all the email ids in auto-spam whitelist. It is a command line utility, to use it you have to go to command prompt and then go to the location of this file and type vereml and press enter.
    This will give you all the parameters to import the users in auto-spam whitelist. Click here to download the VEREML UTILITY
    (NOTE: Copy the VEREML utility to the \program files\eScan folder)

  47. A lot of disk space is occupied by eScan “FBackUp” folder in my Local Drive. What is the use and how can we stop this ?

    FBackUp is a folder created by eScan, which is used to take auto-backup of clean files having extensions *.EXE, *.DLL, *.OCX, *.SYS, *.DRV, and *.CPL after scanning, these files are stored in an encrypted format.

    Configuring / Checking pre-requisite disk space for Auto-backup to function

    The eScan Auto-backup will first check for the minimum available space limit defined for a hard disk drive. If the minimum define space is available then only the Auto-backup will function, if not it will stop without notifying.

    Below is the step from which one can define the space limit required for Auto Backup to work:-

    First, Install the latest eScan hotfix. Click here to download the eScan Hotfix

    a. Then, click on Start >> Programs >> eScan for Windows >> eScan Protection Center.
    b. Click on File Anti-virus >> Settings >> Options. Expand the option "Enable backup" and click on "Minimum disk space(MB)"
    c. The Default Value is 500 MB. Change the Value from 500 to any desired value.
    d. Click on "Apply" then on "OK"
    Note: In above case when the hard disk drive has less than 500MB of free space, the Auto-Backup will stop.

    How to stop Auto-backup Feature (FBackUp)

    To stop the Auto-Backup feature:

    a. Click on Start >> Programs >> eScan for Windows >> eScan Protection Center,
    b. Click on File Anti-virus >> Settings >> Options and UNCHECK the option "Enable backup",
    c. Click on "Apply" then on "OK".

    How to change the location of Auto-Backup folder (FBackUp)

    To change the Auto-Backup folder path:

    a. Click on Start >> Programs >> eScan for Windows >> eScan Protection Center
    b. Click on Protection >> File Anti-Virus >> Settings >> Options
    c. Expand the link “For quarantining of infected objects”
    d. Double click “Use Folder name”
    e. By Default the path is C:\Program Files\eScan\Infected. eScan will automatically create folder namde "FBackUp" in C:\Program Files\eScan\ and start storing the clean files.
    f. Change this path to a different location. For example: If you select D:\Infected, then the "FBackUp" folder will automatically be created in D:\FBackUp
    g. Any path given it will create "FBackup" in the root directory of the path given.

  48. How can I display IP address of client computers under "Normal View" in eScan Management Console?

    a. Open eScan Management Console >> Go to Services, click on "Stop Announcement' and then shutdown the eScan management console.
    b. Go to C:\Program Files\eScan, open eupdate.ini >> Enter the following entry under [config] >> IpOnly=1 >> Save the changes.
    c. Rename the file DmainLst.ini to DmainLst.iniold
    d. Delete all the folders under C:\PUB\LOG
    e. Go to Start >> Programs>>eScan for Windows >> eScan Server >> Start the server announcement
    Once the eScan clients take the updates from the eScan server, the computers will be displayed as per their IP address under "Normal View"

  49. How can I configure my system to block eScan Popups?

    When eScan intercept a virus or downloads updates, it gives a popup. This might be sometimes annoying, for this reason, we have given a facility to block all popups.

    Configuring Popup Block:

    a. Run regedit.exe, Go to

    b. On the right hand side, select the DWORD

    MWErrorMode = DWORD

    You can specify the below DWORD value to block the related popups.

    Stop all popup block = 1 (decimal)
    Start all Web Protection popup = 2 (decimal)
    - all other pop up will be stopped
    Start all Avpmtray popup = 4 (decimal)
    - all other pop up will be stopped
    Start MailScan popup = 8 (decimal)
    - all other pop up will be stopped
    Start License related popup = 16 (decimal)
    - all other pop up will be stopped
    Start USB Popup = 32 (decimal)
    - all other pop up will be stopped
    Start Firewall popup = 128 (decimal)
    - all other pop up will be stopped
    Start trayicos popup = 256 (decimal)
    - all other pop up will be stopped
    Start trayicoc popup = 512 (decimal)
    - all other pop up will be stopped
    Start download.exe popup = 1024 (decimal)
    - all other pop up will be stopped
    Start Application Control popup = 2048 (decimal)
    - all other pop up will be stopped

    Important Note:

    If you want to start two or more popups together, then you need to add all the values for it to work.

    For Example: Application Control popup value = 2048 & econceal firewall popup value = 128, then you have to add both of these values:
    2048 + 128 = 2176 for Application Control popup and Firewall popup to work together.

    Deploying from eScan Server to all clients:

    a. On the eScan server, export registry entry


    as errormode.reg to the desktop.

    (Ref: FAQ - How to take the backup of windows registry?)

    b. Edit the errormode.reg with notepad. Only keep the following entries:

    Windows Registry Editor Version 5.00

    Note: The data value of the MWErrorMode entry will depend upon the settings required
    For Example: If you want to block all the pop-up except the USB pop-up, the value will be 20 (Hexadecimal) or 32 (Decimal).

    c. Copy this file in C:\pub\update folder of the eScan server.

    Now when the client computer takes the download from eScan server the errormode.reg will be downloaded and the changes will be applied to the eScan clients.

  50. How can I change the port settings for my eScan server and deploy it using the eScan management console (EMC)?

    The eScan Server mainly uses three ports:
    a. HTTP port - used to query for virus definition updates.
    b. FTP port – used to deliver updates to client.
    c. UDP port – used to broadcast announcement to its clients.
    Note: You can change the eScan Server HTTP and FTP port settings in EMC.

    To change the port settings for eScan server

    a. Open eScan Management Console >> Go to Services, click on "Stop Announcement' and then shutdown the eScan management console.
    b. Open the file Eserv.ini from the location C:\Program Files\eScan
    c. Find the entry for FTPPort=xxxx and HTTPPort=xxxx
    d. Change the port entries to the new desired value and save the file.
    e. Start the eScan Management console, by Clicking on Start >> Program files >> eScan for Windows >> eScan management console.
    One can deploy the port settings to the client.

    To deploy the port settings use the below steps:

    1. Open eScan Management Console >> Go to Services >> EMC settings >> check the box Enable Advanced Settings in ‘Deploy Rule – Sets’ wizard, if it is unchecked, this will enable Advanced feature while deploying. Close the window once done.
    2. Then click on Services >> Deploy Rule – Set >> Create New Policy >> click Advanced >> Check the box “eScan Auto-Updater Settings” >> click Edit >> Add
    3. For HTTP host add the value
    http://<eScan-Server-IP>:<New HTTP port number>
    Please note the Section & Keyname give in figure below must be selected.


    4. For FTP host add the value
       ftp://<eScan-Server-IP>:<New FTP port number>
    Please note the Section & Keyname give in figure below must be selected.



    5. Deploy these setting on all clients.
    Note: If clients are not getting updates after changing the port on server, we need to deploy the setting as described above & force the clients to take updates with the features available in EMC.

  51. A vulnerability tool identifies MWAgent as a high security risk. It can be exploited to cause a stack-based buffer overflow via an overly long command sent to the service (default port 2222/tcp)?

    The vulnerability is caused due to a boundary error in the MicroWorld Agent service (MWAGENT.EXE) when decrypting received commands. This can be exploited to cause a stack-based buffer overflow via an overly long command sent to the service (default port 2222/tcp).
    This vulnerability has been resolved in the latest hotfix and version and later. MWAGENT.EXE is a gateway between eScan client and server. To avoid this vulnerability, we are using encrypted data format.

  52. Can the tools menu be removed or disabled?

    Yes, disable option under tools menu is available now. And can be enabled by doing following steps
    a.Download the latest updates from the internet.
    b.Then open my computer.
    c.Go to c:\progra~1\escan\ folder
    d.Then open eupdate.ini file using notepad or any editing tool.
    e.Then under [Config] Section add following value.
    f.Following are the values for each tool option to disable.
    1 = To disable “System Information”
    2 = To disable “Send Debug Information”
    4 = To disable “Download Latest Hotfix (eScan).”
    8 = To disable “Restore Windows Default Settings”
    16= To disable “Download Latest Hotfix (Microsoft Windows OS)”
    32= To disable “eScan Remote Support”
    You can add the values to disable multiple tools option e.g. if you want to disable “Send Debug Information” and “eScan Remote Support” then you will have to add 2 + 32 = 34.

    You can deploy this option using eScan Management console, to do this follow the below steps:

    a. Open eScan Management Console.
    b. Click on “Services” Menu
    c. Then click on “EMC Settings”
    d. Tick mark on “Enable Advance settings in “Deploy Rule-sets” Wizard” and click on “OK”
    e. Then again click on “Services” Menu.
    f. Then click on “Deploy Rule-sets ”
    g. Then click on “Create new policy”
    h. Then click on “Advance” button and then
    i. Then tick mark on “eScan Auto-Updater Settings” and then click on “Edit” button.

    j. Select “Config” under Section tab and type “Disabletools” under keyname tab and under Value insert 34, Then click on “Add” button. And then click on Close and again click on close button. And then click on “OK” button.
    k. Type the Policy name, once you type in the policy name “Next” button will get enable click on Next button to deploy the policy.

  53. After Installing eScan, users/recepients receive a notification emails with :Subject: eScan found an email having Virus or objectionable content!
    Email removed at the SMTP/POP3 Gateway for one of the following reasons.
    1. It had a virus.
    2. It had objectionable content.
    3. The sender email-id was banned.
    4. The email itself was corrupted.
    We apologise for any inconvenience.

    This notification message received is by design in eScan.
    When a mail is downloaded by an application (a mail-client like outlook express), it is scanned by eScan at the Transport Layer of the OSI and then delivered to the mail-client. During the scanning process, if the mail has any Restricted Attachments / Viruses, it is either deleted or forwarded to the Administrator by eScan. Since the mail-client has initiated and established the connection to download the mails from the Mail server, it has to receive a mail to complete the connection session. Hence, eScan has to generate this notification to avoid the application from being crashed.
    A workaround to stop this message from being delivered to your INBOX, you can define a RULE-SET in the mail-clients that mails with the above subject should be deleted or moved to a predefines folder.

  54. Can we automate the installation of eScan Internet Security Suite?

    Yes. You can use usetup.exe to customize the installation option so that you can run unattended installations of eScan.
    For more information on the customization utility, please visit the eScan Customization Kit page.

  55. How can I install eScan silently ? And also it should reboot automatically after completion of the installation.

    Yes. You can install eScan silently with the help of below mentioned parameters, which need to execute from the command prompt.
    NOTE: But this can ONLY be used with eScan Version 11 Setup file.
    • /s  : Silent installation
    [ For Silent installation of eScan setup, we can use parameter /s . ( eg:- iwn2k3ek.exe /s )]
    • /Autoreboot=1 : Auto reboot after installation without dialog box
    [ For Reboot without dialog box, parameter /Autoreboot=1 can be used ( eg:- iwn2k3ek.exe /Autoreboot=1 )]
    • /dialog=0  : Not to reboot automatically and not to display dialog box
    [ For not to reboot automatically and not to display dialog box too, parameter /dialog=0 can be used
    ( eg:- iwn2k3ek.exe /dialog=0 )]

  56. How to White-list a file blocked during proactive scanning?

    Proactive scanning is scanning of suspicious files that are in the process of execution, using an algorithm which checks for certain parameters and other details in the file. In the event when a file fails to pass the check, the file is assumed to be suspicious and is consequently blocked.

    In order to white-list such a file, the following steps are to be followed:

    1. Open the eScan Protection Center
    2. Select the Endpoint Security module
    3. Under Reports select View Report
    4. In the Report for Endpoint Security window, look for entries with a red cross and the required filename under Application Name
    5. Select the entry, right click and select Add to Whitelist
    The file has now been whitelisted and will not be blocked in future when attempt is made to run it.

  57. How to disable eScan Notification pop-up message when a spam / virus infected email /attachment has been detected by eScan Anti-Spam/Mail Antivirus module ?

    In order to disable the eScan Notification pop-up message for spam/infected emails, uncheck the “Show Alert Dialog Box” option in Virus Alerts section of Notification settings of Anti-Spam/Mail Antivirus modules respectively.

  58. How to manually whitelist a Malware URL ?


    There are two methods to whitelist Malware URL.

    Method 1:
    1. Apply the latest hotfix.
    2. Reboot the machine
    3. Try to access the URL.
    4. You will get a pop-up, as Malware URL Blocked and below you will have a check box Add to Whitelist.
    5. Check the box Add to Whitelist to whitelist the specific URL.

    Method 2:

    1. Apply the latest hotfix.
    2. Reboot the machine
    3. Try to access the URL
    4. Then you can Whitelist the URL manually from the Protection center > File AV > View reports
    5. Right click and the click on Add to Whitelist.

    Please Note: This Feature is avialable with hotfix and above.

  59. How can I deny RDP access of a server from any ip address?


    Follow the below mentioned steps:

    1. Open the “eScan Protection center”.

    2. Goto to Firewall, click on “Settings”.

    3. Click on “Zone Rule”, Select the zone rule “Allow Local Network….” And click on the “Remove” button to remove the selected rule.

    4. Click on the “Expert Rule” tab, select the “Remote Desktop (RDP)”, right click on the rule and click on “Enable Rule. Click on “Apply”.

    5. Click on the “Expert Rule” tab, select the “Remote Desktop (RDP)”, right click on the rule and click on “Modify”.

    6. Click on the “General” tab, select “Deny Packet”. Click “Ok. Then click on “Apply”

    7. Click on the “Interactive Filter” mode, to put the firewall in the Interactive mode.

    These steps will deny RDP access of a server from all ip-addresses.

  60. How can I allow RDP access to only specific ip address?


    Follow the below mentioned steps:

    1. Open the “eScan Protection center”.

    2. Goto to Firewall, click on “Settings”.

    3. Click on “Zone Rule”, Select the zone rule “Allow Local Network….” And click on the “Remove” button to remove the selected rule.

    4. Click on the “Expert Rule” tab, select the “Remote Desktop (RDP)”, right click on the rule and click on “Enable Rule. Click on “Apply”.

    5. Click on the “Expert Rule” tab, select the “Remote Desktop (RDP)”, right click on the rule and click on “Modify”.

    6. Click on the “General” tab, select “Deny Packet”. Click “Ok. Then click on “Apply”

    7. Click on Settings, click on “Expert Rule”, click on the “Add” button.

    8. In the New window, click the “General” tab, add a name for the rule, select “Permit Packet”, select the protocol to be “TCP”.

    9. Select the “Source” tab, select the “Single IP address” and enter the ip address which needs to be allowed the RDP connection. In the “Source Port” select “Any”.

    10. Click the “Destination” tab, select “My computer” under “Destination IP address”. In the “Destination Port” select “Single Port” and add the port number as 3389. Click on ”OK”

    11. A new rule will be added as seen, click on the rule and click on the move up arrow. And move the new rule above the “Remote Desktop(RDP)” rule and click on “Apply” and then “OK”.

    12. Click on the “Interactive Filter” mode, to put the firewall in the Interactive mode.

    These steps allow RDP access to only said ip address.

eScan Copyright © 2015 MicroWorld Technologies Inc.- AntiVirus & Content Security.       Send your feedback to eScan Wiki

    Privacy policy  About eScan Wiki  Disclaimers   This page has been accessed 178,840 times.