Re: Antivirus checking backup shadow copy





In news:eZ2gwZzeFHA.3160@xxxxxxxxxxxxxxxxxxxx,
Dave Nickason [SBS MVP] <gwdibble@xxxxxxxxxxxxxxxxxxxxxx> typed:
> I run realtime scanning on the server and have for years. You do
> need to properly configure it to not scan certain directories. I'm
> not sure exactly what you're seeing - you have a share that's blocked
> from virus scanning and you're running into a problem when shadow
> copies of that directory are scanned? What problem is that causing?
>
> As far as scanning only on write, IMO that's a bad idea. Let's say I
> send you a file that's a brand new virus. You save the file, which
> won't make itit into the virus definitions until tomorrow. If you're
> scanning only on write, that file was never detected as a virus, and
> tomorrow when you execute the file, it won't be caught then either,
> even though the signature file has been updated to included it. ETrust AV
> won't even allow you to turn off scanning of outbound files
> (say what you want about CA, that's the AV they use at MS).

Enabling bidirectional scanning will absolutely more often than not lead to
huuuuge network/file access performance problems and you will get a lot of
calls. Especially in single-server networks, which comprise the vast
majority of SBS installs, I'd say.

Yes, you're always running a risk of infection, and other problems, by the
sheer fact of letting users access computers at all - but you can mitigate
this risk.

a) use managed corporate workstation AV and make sure it updates often.
Trend is set to update hourly, on all my systems.
b) run full nightly scans on the server, which should also be set to update
hourly
c) use different scan engines on servers/workstations if you really want to
cast your net wide.
d) run nightly full scans of all workstations (make sure users log out, not
shut down, at night).

Etc. It's all risk management, as is anything these days...

Most viruses these days are mail-borne anyway, and I find waaay more
trojans/malware than actual viruses in the file system these days. I expect
my experience is not unique.
>
>
>
> "NickC" <NoSpam@xxxxxxxxxxxxxx> wrote in message
> news:%23kKEm0meFHA.3712@xxxxxxxxxxxxxxxxxxxxxxx
>>
>> "Andrew Hodgson" <me3@xxxxxxxxxxx> wrote in message
>> news:fhhtb11b8fqog2o6ln2rfg3ic9j73dg9l2@xxxxxxxxxx
>>> On Sun, 26 Jun 2005 12:15:58 +0100, "NickC" <NoSpam@xxxxxxxxxxxxxx>
>>> wrote:
>>>
>>>> Has anyone found a fix to prevent Trend Micro SMB from triggering
>>>> during backup shadow copy when detecting viruses in excluded
>>>> directories?
>>>
>>> Don't use the on access virus scanner on a server machine.
>>
>> Andrew,
>>
>> Wow that sounds dangerous, I'm not sure I would feel safe without
>> Real-time
>> scan (as Trend Micro call it) running on the server. It would
>> certainly solve the problem but is it worth the risk?
>>
>> What does everyone else do, on access / real-time scanning on the
>> server or
>> not?
>>
>> Nick


.



Relevant Pages

  • Re: Disappearing disk space?
    ... I switched off the AV scanning completely last night and the ... Windows Server 2003, Windows 2000, or Windows XP ... %systemroot%\Sysvol folder ... KB309422 - Guidelines for choosing antivirus software to run on the ...
    (microsoft.public.windows.server.sbs)
  • Re: On Access Virus Scanner Recommendation
    ... Linux is not vulnerable to windows virus. ... Note the careful wording;-) So don't waste valuable server cpu cycles on-access scanning on a Linux server. ... Best you can do is have have regular full virus scans on the Windows PCs hard disks to fix once the anti-virus companies catch up. ...
    (Debian-User)
  • Re: OE Version.
    ... scanning has also been responsible for wiping out entire dbx files. ... Turn of NAV email scanning. ... "Your server has unexpectedly terminated the connection. ... your mail client and the incoming data, ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Sbs 2003 r2 running very slowly
    ... on-access virus scanning? ... is you get a virus-infected file and save it to the server today. ... Because you've disabled on-access scanning, ... Am having problems with a sbs server running at snails pace.. ...
    (microsoft.public.windows.server.sbs)
  • Re: Information Store taking all available memory.
    ... There are cases where the virus software is scanning things it should not ... The aforementioned should be excluded in the virus software. ... Do Not Back Up or Scan Exchange 2000 Drive M ... Understanding Virus Scanning API 2.0 in Exchange 2000 Server ...
    (microsoft.public.exchange2000.information.store)

Quantcast