Hi Greg,

Sunday, February 8, 2004, 9:47:57 AM, you wrote:

GS> Hello Yuki,

GS> Saturday, February 7, 2004, 6:27:45 PM, Yuki Taga wrote:

YT>> Well, the big thing for me right now is I'm whole again.  Restored
YT>> the message files, deleted the index files, and new indices were
YT>> created and all messages are back.

GS> Glad to hear!

YT>> What a pain in the neck!

GS> Yes, but this is life on the Internet today.

YT>> I'm a bit wary of using this until I understand it.

GS> IMHO using the message dispatcher to delete message before you have a
GS> chance to look at them is not a good LONG term solution. IIRC you said
GS> you had the corporate version of NAV installed.  I'm not familiar with
GS> the corporate version because I had the retail version of NAV 2002
GS> installed.

I tend to agree, and yes, it's the corp.

GS> I suggest you look at the options available in NAV for incoming email. I
GS> would think the options would be similar to those in the retail version.
GS> IIRC on the configuration that I used in the past what you want is NAV
GS> to "quietly" quarantine the file as a last resort. I don't recall exact
GS> wording, but it worked GREAT for me.

It's a pretty Spartan interface, which I like, actually.  There is no
specific setting for 'e-mail'.  For viruses, there is a first action
choice, and an 'if that fails' choice.  I have always run "attempt to
clean" and "quarantine".  Maybe I'll change to "attempt to clean" and
"log only" if this becomes a recurrent thing.

GS> I had an email account with my ISP that I used for Usenet with 10 MB of
GS> storage. It would be full in about 1 day with 99.9% virus attachments
GS> which I would be able to completely download with TB. NAV would strip
GS> the virus attachment from the email and quarantine. If this option is
GS> available in the retail version I would think it would be available in
GS> the corporate version because I've read many times that the corporate
GS> version was better.

That is my big mystery here.  Like everyone, I've been the target of
plenty of these viruses.  One cannot participate on a public mailing
list without becoming a target.  But never, ever, has my AV program
reacted like this to a virus on the server.  It has always downloaded
them, and if I was stupid enough to try and activate the virus, it
would stop me (usually I just know, and I delete).  So the infected
message has always come through, and it could sit harmlessly on the
system until I disposed of it.  But not this time.  Symantec did not
want this on the system at all.  I have changed no settings, either.

GS> I am sorry I can't be more explicit, but I think if you look at options
GS> it should be self explanatory. After you change your incoming email
GS> options as recently discussed in TBUDL I suggest downloading Eicar test
GS> virus file from http://www.eicar.org/anti_virus_test_file.htm and
GS> sending it to yourself for a test on incoming email configuration. You
GS> probably will have to turn off scanning of outgoing mail to send the
GS> virus test file to yourself.

I'll consider reconfiguring to 'log only' and testing this.  I
believe the real time protection would still prevent me from opening
an infected file anyway, but not actually *sure* about that.

--
 
Best,

Yuki

Using The Bat! v2.03 Beta/59 on Windows XP
5.1 Build 2600
Service Pack 1


________________________________________________________
 Current beta is 2.03 Beta/59 | "Using TBBETA" information:
http://www.silverstones.com/thebat/TBUDLInfo.html
IMPORTANT: To register as a Beta tester, use this link first -
http://www.ritlabs.com/en/partners/testers/

Reply via email to