Symantec 10551441 Administration Guide - Page 174

Defining Symantec AntiVirus actions for handling suspicious files

Page 174 highlights

174 Responding to virus outbreaks Preparing for a virus outbreak Defining Symantec AntiVirus actions for handling suspicious files By default, Symantec AntiVirus performs the following actions when it identifies a suspicious file: ■ Symantec AntiVirus attempts to repair the file. ■ If the file cannot be repaired with the current set of virus definitions files, the infected file is moved to the Quarantine on the local computer. In addition, the Symantec AntiVirus client makes a log entry of the threat event in its log. The Symantec AntiVirus client data is forwarded to a primary server. You can view log data from the Symantec System Center console. You can perform the following additional actions to complete your virus handling strategy: ■ Define different repair actions based on virus type. For example, you can have Symantec AntiVirus automatically fix macro viruses, but ask what action to take when a program file virus is detected. ■ Assign a backup action for files that Symantec AntiVirus cannot repair, such as deleting the infected file. ■ Receive virus alerts, such as a page or email message, if you are using AMS2. ■ Configure the local Quarantine to forward infected files to the Central Quarantine. You can configure the Central Quarantine to attempt a repair based on its set of virus definitions files (which may be more up-to-date than the definitions on the local computer), or automatically forward samples of infected files to Symantec Security Response for analysis. See "About the Alert Management System" on page 61. For more information, see the Symantec Central Quarantine Administrator's Guide. Automatically purging suspicious files from local Quarantines When Symantec AntiVirus scans a suspicious file, it places the file in the local Quarantine folder on the affected computer. The Quarantine purge feature automatically deletes files in the Quarantine that exceed a specified age. Registry settings for Quarantine purge are located in this registry key: \\HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\ CurrentVersion\Quarantine

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

174
Responding to virus outbreaks
Preparing for a virus outbreak
Defining Symantec AntiVirus actions for handling suspicious files
By default, Symantec AntiVirus performs the following actions when it
identifies a suspicious file:
Symantec AntiVirus attempts to repair the file.
If the file cannot be repaired with the current set of virus definitions files,
the infected file is moved to the Quarantine on the local computer. In
addition, the Symantec AntiVirus client makes a log entry of the threat
event in its log. The Symantec AntiVirus client data is forwarded to a
primary server. You can view log data from the Symantec System Center
console.
You can perform the following additional actions to complete your virus
handling strategy:
Define different repair actions based on virus type. For example, you can
have Symantec AntiVirus automatically fix macro viruses, but ask what
action to take when a program file virus is detected.
Assign a backup action for files that Symantec AntiVirus cannot repair, such
as deleting the infected file.
Receive virus alerts, such as a page or email message, if you are using AMS
2
.
Configure the local Quarantine to forward infected files to the Central
Quarantine. You can configure the Central Quarantine to attempt a repair
based on its set of virus definitions files (which may be more up-to-date than
the definitions on the local computer), or automatically forward samples of
infected files to Symantec Security Response for analysis.
See
“About the Alert Management System”
on page 61.
For more information, see the
Symantec Central Quarantine Administrator’s
Guide
.
Automatically purging suspicious files from local Quarantines
When Symantec AntiVirus scans a suspicious file, it places the file in the local
Quarantine folder on the affected computer. The Quarantine purge feature
automatically deletes files in the Quarantine that exceed a specified age.
Registry settings for Quarantine purge are located in this registry key:
\\HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\
CurrentVersion\Quarantine