Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Determining the Location of Groupshield detected Virus'

Status
Not open for further replies.

AuntieEPO

Technical User
Jul 3, 2002
61
GB
Hi

Were running Groupshield for exchange(5.5) v4.5 on an NT4 server.

Each time we recieve virus alerts from Groupshield we're unable to determine who's mailbox the infected email was delivered to.

Surely there is a way of finding out.

Looking in "Quarantine Manager" I can see the instances of detection, but three key columns are always left blank - the "location" "sender" and "owner" column.

Any ideas why these colmns are always left blank.

Is there no way of alerting the actual recipient of the email that they have recieved an infected mail - either by email or on screen messages?

The groupshield token emailed to our administrators states that the attachmnet is quaratined and has been replaced by a txt file explaining this fact - but we will never know whos mailbox this has gone to unless the user actually comes and tells us.

Any ideas anyone?

Ta
 
If you're running Exchange 5.5 w/ SP3, you won't see those info. You'll need to either upgrade to GSE 5.0 or download the Resolve Names Utility. In order to use this utility, your Quarantine option MUST be a database. Doesn't work with the directory option.

HTH,

AVChap ... take my advice, I don't use it anyway!
 
Whats GSE 5.0?

Also, what exactly is the name resolve utility, and is it a McAfee product? or something to do with Microsoft and Exchange?

ps. where are they available from?

cheers very much
 
GSE 5.0 = GroupShield Exchange 5.0

The Resolve Names utility is a McAfee program add-on for GourpShield Exchange 4.5. This allows you to reference the sender and recipient information for those infected attachment.

They can be downloaded from NAI's web site. You'll need your grant number to do this.

HTH,

AVChap ... take my advice, I don't use it anyway!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top