Navigation:  Exchange Server Toolbox >

Antivirus

Previous pageReturn to chapter overviewNext page

Exchange Server Toolbox is able to test incoming messages for viruses using the integrated ClamAV or your installed antivirus software.

 

ClamAV

The integrated antivirus software is the Windows version of ClamAV: ClamWin (http://www.clamwin.com)

 

"Clam AntiVirus is an open source (GPL) antivirus toolkit for UNIX, especially designed for mail scanning on mail gateways. [...] The core of the package is an antivirus engine available in a form of shared library.

 

Here is a list of the main features:

 

   * ...

   * advanced database updater with support for scripted updates and digital signatures

   * virus scanner C library

   * virus database updated multiple times per day (see homepage for total number of signatures)

   * built-in support for various archive formats, including Zip, RAR, Tar, Gzip, Bzip2, OLE2, Cabinet, CHM, BinHex, SIS and others

   * built-in support for almost all mail file formats

   * built-in support for ELF executables and Portable Executable files compressed
      with UPX, FSG, Petite, NsPack, wwpack32, MEW, Upack and obfuscated with SUE, Y0da Cryptor and others

   * built-in support for popular document formats including MS Office and MacOffice files, HTML, RTF and PDF"

(source: http://www.clamav.net/about/lang-pref/en/)

 

 

Installed antivirus software

Exchange Server Toolbox is able to use any antivirus software as long as it includes an "On Access Scanner" that checks all files written to the hard disk.

 

 

Common settings for any virus software you want to use with  Exchange Server Toolbox are:

If a virus is found (files and archives) the software must not prompt for any user interaction. Set "delete file" or "move/rename file" as handling.

 

 

The specific behavior varies a bit dependent on the antivirus software you use.

In the following sections detailed configuration instructions for some antivirus software will be provided:

 

GData
BitDefender
Kaspersky
Sophos

 

 

G Data

 

It is important that the mail scanner of G Data is not active otherwise Exchange Server Toolbox will not work correctly.

 

GDataMailOpt

 

G Data Anti Virus is delivered with an "On Access Scanner" that is able to notice if an infected file was written to / read from the hard disk.

 

To make  Exchange Server Toolbox and G Data virus scanner work together some changes in the configuration of the "AVK Guard" have to be made:

 

Infected files have to be moved or deleted without prompting.
Infected archives should be handled without prompting a warning.
Files have to be scanned while writing to disk.
Also scan archives. Most viruses attached to mail messages are in an archive (e.g. *.zip Files).

GDataOpt

 

 

 

BitDefender

 

BitDefenders virus scanners are able to check incoming messages. If you enable the appropriate antivirus feature in the Antivirus options form,  Exchange Server Toolbox activates this function in your scanner. After activating it, all forwarded messages containing a virus will be replaced by a notification message from the antivirus  software.

 

 

Kaspersky

 

Kaspersky virus scanners are delivered with an so called "On Access Scanner", that is able to notice if an infected file was written to / read from the hard disk.

 

To make  Exchange Server Toolbox and Kaspersky virus scanner work together some changes in the configuration of the "Anti-Virus Monitor" have to be made.

 

Following changes are required:

Viruses have to be renamed or deleted without asking.
Disable the warning message box.
Also scan archives. Most viruses attached to mail messages are in an archive (e.g. *.zip Files).

 

Following changes are recommended:

To get better results scan all files (not only infectable files).

 

 

Sophos

 

Sophos virus scanners are delivered with an so called "On Access Scanner", that is able to notice if an infected file was written to / read from the hard disk.

 

To make  Exchange Server Toolbox and Sophos virus scanner work together some changes in the configuration of the "InterCheck - Client" have to be made.

 

Following changes are required:

Viruses have to be renamed, removed or deleted without asking.
Files have to be scanned while writing to disk.
Also scan compressed files. Most viruses attached to mail messages are in an archive (e.g. *.zip Files).

 

Following changes are recommended:

Scan Files while reading and renaming files.