Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Symantec misses viruses that Trend catches

Status
Not open for further replies.

rjs

MIS
Apr 6, 1999
632
US
Although this seems like more of a desktop forum, I have found no other suitable place.

We are running Symantec Mail Security for SMTP 5.0 with the latest patches, virus definitions, etc. I spent over two hours with tech support verifying the settings are correct.

I get about 10-20 alerts EACH day from Trend AV for Exchange that viruses on inbound messages have been caught and deleted. All inbound e-mails go through the SAV SMTP server first and these e-mails are not being caught by the Symantec SMTP gateway. They are only being caught AFTER they pass through the SMTP gateway and reach the Exchange server.

In addition, if I copy the files from the Trend Quarantine directory on my Exchange server to my local PC, the Symantec Corp 10 client running on my local PC will catch some of these files as viruses. So the Corp product sees the virus, the Trend AV product on Exchange sees the virus, but the SMTP 5.0 does not.

In addition, the SMTP 5.0 product has been running for five days now (replaced the 4.1 product recently) and the message status summary and reports show NO (none) viruses detected, though it does should 8 mass mailing worms detected. It seems HIGHLY unlikely that no inbound viruses would be detected.

I am losing confidence in the SMTP product and glad that I have a multi-layer defense established.


R.Sobelman
 
This is fairly typical.

I run antigen with 5 different engines, sometimes the virus will be picked up by the first engine sometimes second engine.... etc.

In the end I just blocked all attachments that I believe to be risky: .vbs, .bat, .exe etc.

If you have a legitimate reason for mailing .exe files then educate the users that require them in changing file extensions.

As you know first hand you can't just say yes we're secure because I have X in place. But because you have X, Y & Z in place you're as secure as you can be!

Iain

P.S. I find the desktop version absolute waste of time and effort, I wouldn't trust it to pick up anything at all. I run v.10 too and can put virus infected files on a machine as a test and they'll never be detected......
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top