Jason Haar wrote:
> However, a lot of sites complained. They actually looked at the logs and
> they didn't like seeing that 44% of their quarantine events were "PIF
> blocked" - they wanted to know WHAT VIRUS IT WAS.

But you have the PIF in quarantine anyway.  Couldn't you save CPU by 
PIF-blocking the attachment, then scanning it later (during off-peak hours, or 
in a nice process) to find out what virus it was?

Matthew.van.Eerde (at) hbinc.com                 805.964.4554 x902
Hispanic Business Inc./HireDiversity.com         Software Engineer
perl -e"map{y/a-z/l-za-k/;print}shift" "Jjhi pcdiwtg Ptga wprztg,"
_______________________________________________
http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users

Reply via email to