McAfee GSSCDE-AA-DA User Guide - Page 118

Anti-Virus Scanner Actions, Default Actions

Page 118 highlights

McAfee® GroupShield™ 7.0 User Guide Policy Manager 10 Scanners and filters Editing anti-virus scanner actions 1 From Policy Manager, select a submenu item that has anti-virus scanner. The policy page for the submenu item appears. 2 Choose a desired policy. 3 Click Anti-Virus Scanner. The View Settings tab for the anti-virus scanner appears. 4 Under Actions to take section, click the Edit link. The Anti-Virus Scanner Actions page appears. 5 In Cleaning tab, under Virus and trojans cleaning, select the option Attempt to clean any detected virus or trojan to enable the cleaning of any virus or trojan. 6 Under If cleaning succeeds, take the following action, select the desired option(s) if the cleaning succeeds: „ Log - to record the detection in a log. „ Quarantine - to take a copy of the item and store it in the quarantine database. „ Notify administrator - to send an alert message to the email administrator. „ Notify sender - to send an alert message to the sender, when the original email message does not originate in the same domain as Microsoft® Exchange Server 2003/2007. „ Notify recipient - to send an alert message to the recipient, when the recipient is not in the same domain as Microsoft® Exchange Server 2003/2007. 7 In the remaining tabs (Default Actions, Custom Malware, Packers, and PUPs), choose a primary action from the drop-down list and select one or more secondary actions. In the Custom Malware tab, you can also see the custom malware categories that you have selected while creating a new set of anti-virus scanner options (Advanced tab) Note Primary and secondary anti-virus scanner actions Primary actions for On-Access scan include: „ Replace detected item with an alert - to replace the detected item with an alert message. „ Delete embedded item - to delete the detected item. For example, to delete an attachment that triggers a detection rule. „ Delete message - to delete the email message item. „ Allow through - to allow the item to continue to the next scanning phase or on to its final destination. 118

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180

118
McAfee
®
GroupShield
7.0 User Guide
Policy Manager
Scanners and filters
10
Editing anti-virus scanner actions
1
From
Policy Manager
, select a submenu item that has anti-virus scanner. The policy
page for the submenu item appears.
2
Choose a desired policy.
3
Click
Anti-Virus Scanner
. The
View Settings
tab for the anti-virus scanner appears.
4
Under
Actions to take
section, click the
Edit
link. The
Anti-Virus Scanner Actions
page
appears.
5
In
Cleaning
tab, under
Virus and trojans cleaning
, select the option
Attempt to clean any
detected virus or trojan
to enable the cleaning of any virus or trojan.
6
Under
If cleaning succeeds, take the following action
, select the desired option(s) if the
cleaning succeeds:
Log
— to record the detection in a log.
Quarantine
— to take a copy of the item and store it in the quarantine database.
Notify administrator
— to send an alert message to the email administrator.
Notify sender
— to send an alert message to the sender, when the original email
message does not originate in the same domain as Microsoft
®
Exchange Server
2003/2007.
Notify recipient
— to send an alert message to the recipient, when the recipient is not
in the same domain as Microsoft
®
Exchange Server 2003/2007.
7
In the remaining tabs (
Default Actions
,
Custom Malware
,
Packers
, and
PUPs
), choose a
primary action from the drop-down list and select one or more secondary actions.
Primary and secondary anti-virus scanner actions
Primary actions for
On-Access
scan include:
Replace detected item with an alert
— to replace the detected item with an alert
message.
Delete embedded item
— to delete the detected item. For example, to delete an
attachment that triggers a detection rule.
Delete message
— to delete the email message item.
Allow through
— to allow the item to continue to the next scanning phase or on to its
final destination.
Note
In the
Custom Malware
tab, you can also see the custom malware categories that you
have selected while creating a new set of anti-virus scanner options (
Advanced
tab)