Re: [Declude.Virus] Management Question

2002-09-25 Thread R. Scott Perry


But I need to know more about managing the files quarantined by the program.
Are all the files in the virus folder infected?

All of the files in the \IMail\spool\virus directory are ones that Declude 
Virus caught, either because the virus scanner detected a virus, or because 
Declude Virus detected a vulnerability.

F-prot lists the Klez as non-disenfected, but that is about 50% of the files.

Note that the viruses almost certainly cannot be cleaned (as they are 
encoded).  However, you probably do not want them cleaned anyways, as Klez 
can send confidential documents along with the virus.

What is the appropriate action with the files in the folder?

In most cases, the appropriate action is to delete the E-mail (or, archive 
them just in case if company policy so requires).

The exception would be if an important E-mail was sent with a virus, and 
needed to be retrieved without the sender re-sending it.
 -Scott

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] Management Question

2002-09-25 Thread Doug McKee


The exception would be if an important E-mail was sent with a virus, and 
needed to be retrieved without the sender re-sending it.
 -Scott

Scott,
How is that important email identified?
Doug
---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] Management Question

2002-09-25 Thread R. Scott Perry


The exception would be if an important E-mail was sent with a virus, and
needed to be retrieved without the sender re-sending it.

How is that important email identified?

However you want to define it.  In most cases, it involves the CEO of a 
company getting an E-mail from the CEO of another company, who has a 
virus.  The E-mail gets caught because it has a virus.  The CEO of your 
company is told that he should ask the CEO of the other company to get rid 
of the virus and re-send the E-mail.  Your CEO is afraid of asking the 
other CEO to do that, so he asks you to retrieve the original E-mail.

Personally, I feel that no E-mail that is sent with a virus is important 
enough to retrieve, and that it should be re-sent after the sender removes 
the virus.  But, if the boss feels otherwise...
-Scott

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.



RE: [Declude.Virus] Management Question

2002-09-25 Thread Doug McKee

I understand that component of important
What I meand is how is it labeled by declude so I can find it should the
need ever arise?
Doug

---
[This E-mail scanned for viruses by Declude Virus]

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.Virus.The archives can be found
at http://www.mail-archive.com.