This FAQ is outdated! This FAQ was for the SBC product which incorporated the v6 product and made use of silverlight and ISS

remember this is unofficial and if there is any wrong answer/solution or assumption in it please correct me…
I have composed this on my own initiative.
Here you can find the official FAQ:,1,23

Last edit: 15-03-2012 addition of corrupt mirror

Where can i find (BPP) documentation?

Where can i find system requirements for the console / database / client
In the admin guide posted above

SBC wont install using a remote dedicated database server
The BUG for this problem is solved in the latest SBC release

However the machineaccount where SBC is getting installed needs permission on the database. Not a user account.

There are 2 methods for this:
Method 1 (machine local group):
Create a local group on the sql server
Add the Server account that is going to host the BP Console to that group
Add the group into the SQL Server as a login with permission to create a database.

Method 2 (domain local group):
Create a domain local group in Active Directory
Add the Server account that is going to host the BP Console to that group
Add the DL group into the SQL Server as a login with permission to create a database.

For method 2 its imperative that the settings for the group are DOMAIN LOCAL and not GLOBAL. The advantage is that you control it from Active Directory and not locally on a server where these settings could be forgotten.

How do i license now (reseller or avast input appreciated)
Every computer (server or client) gets a license. If you have 132 clients, then you buy 132 licenses. Depending on what you need to protect and what you desire to have it will be a BP or BPP license.
If you need to protect Exchange and/or Sharepoint then you automatically turn to BPP
If you desire to use the firewall or antispam then you also turn to BPP

Do i need an internet connection for installing the SBC
Yes its required for downloading the prerequisites and of course all the installation files and virus definitions

Where can i find any error logs?
Open the SB Console go to ADMIN - SETTINGS - TROUBLESHOOTING - DOWNLOAD → open zip file
In case of failed installation:
C:\Documents and Settings\All Users\Application Data\AVAST Software\Administration Console\Logs - WinXP/2k3
C:\ProgramData\AVAST Software\Administration Console\Logs - Win Vista/7/2k8

What does it mean when a Windows 7 Computer is rejected by the SBC after a successful roll out and the reason listed is “Computer banned”

Can i import the ADNM database to SBC database?
No, you have to start from scratch.

Is there a 64bit Outlook antispam plugin
No (not yet?)

When i turn off the firewall or antispam in a group, all computers in that group turn yellow and the client tells me its not fully secured
[1] Edit Group Settings → Shields → Firewall (Uncheck)
[2] Edit Group Settings → Status Bar → Firewall (Uncheck)

Unchecking those TWO settings will:
[1] Disable the Firewall
[2] Prevent the Status Bar issuing a Warning. Is this a NEW option?
(thanks studio_two for the new way with SBC release

Where can i control the firewall or antispam in the GUI
No GUI controls yet available. see previous FAQ item.

How can i get email alerts back?
This comes from VLK

avastcfg://avast5/Communication/SMTPPort 25

Please note that this change becomes effective only after the shields are restarted (e.g. computer rebooted).

Will SBC work with more then the stated 200 clients
With SBC 1.1 the boundary is 1000 clients. With appropriate HW it might handle little bit more.
Avast has been testing this and confirmed that 2000 clients is possible to and will support this in a later release (added this at 12-12-2011)

Can i deploy the SBC client without removing the obsolete ADNM 4.8 client
Yes you can. From own experience this worked flawless (although tested on just 1 computer)
Keep in mind that several directories from the old installation will stay behind on the computer, these need to be removed manually.

My unattended deployment fails, why
Did you give the account that you install the client with the LOGON AS SERVICE rights on all the computers? you have to set that in the grouppolicy security settings.
In a domain its easiest to do this with a GPO setting so it gets deployed to all domain clients automatically

How can i turn of the AUTO SANDBOX feature, its interfering with my users work
Edit group settings → Expert Settings → AutoSandboxEnabled → 0

Does SBC has Active Directory integration for access control
No it does not. I (WPN) have read about possible plans to implement this in the (near) future.

Can i install SBC on a server that is already running ISS
No problems with installing, but you have to note that SBC is installing in “Default Web Site”. So if you have another active website and the “Default Web Site” is stopped, you will need to move the Avast virtual directory to the active website.

Can SBC use a proxy server
Yes, it should automatically detect proxy settings from the default IE settings

Can i do an offline update of the VPS files
No, this is not supported at this moment. For a full answer check this thread:

Can ADNM manage v6 clients
No it can not at this moment. Rumors have been going around about a connector for controlling v6 clients from an ADNM server.
12-12-2011: the SBC is going to support 2000 clients. This could solve ADNM reliability for several people.

On average how much a day are the VPS updates in traffic
typically < 200KB a day per client
On a network setup with 100 client this would come down to about 20MB traffic

Is there a French translation for the admin guide and possibly an FAQ
some faq :
the administrator guide :

Installer fails with a rollback claiming the service already excists
You probably run an installation before and cancelled it. This leaves the avast! Administration Console service installed.

Open a CLI as administrator and issue the following command:
sc delete “avast! Administration Console”
The quotes are there for the spaces in the name, dont forget them!
Now start your installer again.

Can I change the server from where the clients get their updates from?
Yes you can, you have to go into the expert settings from the the group settings.

Setting avastcfg://avast5/Common/MirrorURL


Avast is reporting a lot of different infections on the same machine, but im sure i have no infection
Highly possible that you have some definitions from another AV product, most likely Windows Defender. Remove the conflicting AV product causing Avast problems and it should be fine.

when I try to connect to the avast! admin console I get: “unable to connect to website”
When checking the services, both services are in stopped state. When restarting the services theses errors are generated:

  • “avast! Administration Console Monitor is not a valid win32 application”.
  • a dependency is not started (avast! admin console)

One workaround:
add a double quote (") in regedit around the path of the image : “C:\Program Files\AVAST Software\Administration Console\Avast.Sbc.Manager.exe”
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\avast! Administration Console Monitor]
[/i]See attachment for image of regedit[/i]

Possibly this issue is caused by upgrading over an excisting installation of the console. But this is unconfirmed

Mirror Corrupted - Package Broken
The Error given in the Administration console is Package Broken (20000011).
Restarting the administration console services and manually running the Update Server definitions task will hang at xx% and does not create any entries in the mirror.log.

There is a temp file with the corrupted files.
Stop the Administration Console service and made sure Mirror.exe is not running
Delete the file from the temp folder
Restart the Services and the mirror should update successfully.

Depending on your environment settings in this case from Evangelist MAC (thnx for reporting) the file was found in C:\WINDOWS\Temp and was named

More to come of course. Any corrections or suggestions are welcome!

Can i install SBC on a server that is already running IIS
No problems with installing, but you have to note that SBc is installing in “Default Web Site”. So if you have another active website and the “Default Web Site” is stopped, you will need to move the Avast virtual directory to the active webite.

How to upgrade the old 4.8 managed clients to the new 6.0 clients:
Just run the deployment job, the existing 4.8 will be uninstalled and the new will be installed.


I wanted to post this scenario with the management Console (SBC) and the deployment Wizard. If you DONOT want the PCs to reboot automatically (you would like it to happen on your schedule, like at night) then do not start the deployment Wizard. When the wizard was launched, the default started immediately to auto deploy and reboot. This occured while customer transactions were live. This can cause undesirable effects to business. We immediately closed the Console to stop this process. We moved forward with installation and created a new deployment without reboot. We tested this with 1 install on a single PC, and it successfully installed and successfully DID NOT reboot. Great, all is well. We then created a scheduled new deployment for the rest of the clients, install, and DO NOT reboot. What we did NOT know, is that the original install (auto-deploy and instantly reboot) was still in the queue from starting the wizard. We removed the console, and reinstalled the console, did NOT start the wizard, and now all is well.

This 2nd issue I want to post is related, but is an OLD issue, that presents itself with every version of every MFGR of every anti-virus product out there. The removal of an antivirus program (uninstall) and the reinstallation of a newer or different antivirus, does not always go as planned. I battled this with Symantec, Norton, and McAfee that I sold for 20 years prior to avast! Antivirus is very invasive. Windows decomposes just sitting there. Just using Windows, uninstalling and reinstalling programs, and endless updates replacing endless updates, causes Windows corruption to occur with usage. That’s why every Windows XP has to be refreshed every now and then. Uninstallers are sometimes useful, and sometimes not, and always leave leftovers on the system in the registry, and in program files, and in … So, sometimes nothing replaces the manual “scrape” We all will eventually see this issue during deployment from the Console, it is inevitable! J.R.

We have translate in French

some faq :

[s]the administrator guide :[/s]

the administrator guide :

Since the GUI is so lacking for what we need in most corporate environments, I’d like to see some examples with setting other Expert Settings in the console.
We have created a SERVER group and turned off unwanted shields - (When will P2P or IM be running on a corporate server console??- it’s not generally something we would condone- ever!) ::slight_smile:
We also need much more control of the AV behaviour in almost all of our corporate environments. For example, vendors of many of our customer’s require that their server processes and files are excluded from scans.

When we try to get support from the vendor, generally the first thing they will ask is:
“Have you turned off file/process scanning on our application and data files in your AntiVirus solution? - If not then go away and do that before we will support you!”

For example, if a vendor writes MSSQL Server based product, they generally have specific install instructions which mandate AV scanning exclusions on all of the following:

  • sqlserver.exe process
  • *.mdf and *.ldf files must be explicitly excluded

When I asked the avast team if we need to tweak anything on a server, I was told “it should not be necessary to tweak anything”- So, I presume by this comment we are supposed to just trust avast to do the right thing on a server. ???
But can we just ‘assume’ that *.mdf and *.ldf files are already excluded by Avast BPP default settings and if so, how would we verify this?

Similarly what about Exchange folders or files(*.edb, .log) or Microsoft Internal Database files (.mdb). Do we just assume these will not be impacted by avasts shields?

I’m afraid it just won’t wash with our vendors- they will want a cast iron guarantee that the AV is not impacting their solution.

In closing we MUST have a way to easily add “Trusted Processes” from the Behaviour Shield, and “Excluded Folders and Files” from the File Shield.

So until avast team gets this in the UI - can someone please post how we bandaid this by fiddling with ‘Expert Settings’ in the BPP Console?

Found this one with a client recently.

Can’t move computer from one group to another
If your computers have special characters in their names that are not standard (like “_”), you won’t be able to move said computer to another group when doing it from the “edit” button.
There’s an easy solution to this.
Go to the “Network” section, choose “Grid view”.There, you can simply select the computers you want to move and do so by simply right-clicking → “move to group” → “name_of_group”.

(You should really not use special characters in your computer names, though.)

The installer automatically is assigned the domain name of the management server. However, since some of my clients are outside our Intranet, I have to manually change systems to use its external name: and even then, not all my systems show up as connected. An ability to change this setting would be most helpful!