Home > Microsoft Exchange Tips > Exchange Security Tips > How file-level antivirus software can harm your Exchange Server
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SECURITY TIPS

How file-level antivirus software can harm your Exchange Server


Brien Posey, Contributor
06.16.2009
Rating: -2.75- (out of 5)


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


There are countless email viruses out there, all of which are capable of unleashing havoc on your network. What you may not realize is that unless your antivirus software is properly configured, it can actually do more damage to Exchange Server than a virus could.

How can antivirus software harm Exchange Server more than a virus? It all depends on how that program works and how the Exchange information store functions.

Many antivirus programs on the market are Exchange Server-aware. This means that the application knows about Exchange Server's requirements and is written so that it does not damage Exchange. These types of antivirus programs are not the problem. What cause the problem are basic file-level virus scanning software products.

The use of file-level antivirus software can cause database failure. This happens because a file-level antivirus application may lock or even quarantine a log file, or database itself, when Exchange tries to use it. The end result is a catastrophic failure. When this occurs, Exchange will log Event ID 1018 in the server's Application log.

Note: If you are using Exchange 2000, you probably know that Exchange uses an M: drive. If you scan this drive with file-level antivirus software, you can cause calendar entries to disappear.
More on antivirus and email security:
Microsoft Exchange Server security dos and don'ts

Secure Edge Transport servers using the Security Configuration Wizard

The six-layered secret of effective Exchange Server email filtering

As you can see, file-level antivirus software can wreak havoc on your Exchange Server. You may not have to completely replace what you're using, but what can you do if you're using file level antivirus software?

Some vendors offer Exchange Server modules to augment basic antivirus products. If your antivirus vendor can't guarantee Exchange Server compatibility, it may be time to move to a different antivirus application. However, you do have the option to circumvent the problems by excluding certain folders from being scanned. The folders that you should remove from scanning are:

  • In Exchange Server 2003:
    • \Exchsrvr\MDBData
    • \SRS

  • In Exchange 2000
    • \Exchsrvr\MDBData
    • \SRS
    • M:

  • In Exchange 5.5
    • \Exchsrvr\MDBData
    • \DSAData

In Exchange 2007, things aren't quite as simple. The folders that need to be excluded vary depending on which server roles are installed. Furthermore, many of these paths are not absolute, but vary depending on your server's configuration.

There are Exchange Management Shell commands that you can use to determine which paths to avoid. Microsoft provides a document that explains which paths should not be scanned at the file level.

It's always best to use an Exchange-aware antivirus application, rather than simply configuring a file-level antivirus application to avoid damage. Non-Exchange aware antivirus applications can cause Exchange Server performance to suffer because it's scanning file types or even processes that are better left untouched.

File-level scanners only protect against viruses that reside in the file system. They do not protect against email viruses as they flow through the message transport server. They also do not scan Exchange server databases for infected attachments.

About the author: Brien M. Posey, MCSE, is a five-time recipient of Microsoft's Most Valuable Professional (MVP) award for his work with Exchange Server, Windows Server, Internet Information Services (IIS), and File Systems and Storage. Brien has served as CIO for a nationwide chain of hospitals and was once responsible for the Department of Information Management at Fort Knox. As a freelance technical writer, Brien has written for Microsoft, TechTarget, CNET, ZDNet, MSD2D, Relevant Technologies and other technology companies. You can visit Brien's personal website at www.brienposey.com.

Do you have comments on this tip? Let us know.

Please let others know how useful this tip was via the rating scale below. Do you know a helpful Exchange Server, Microsoft Outlook or SharePoint tip, timesaver or workaround? Email the editors to talk about writing for SearchExchange.com.

Rate this Tip
To rate tips, you must be a member of SearchExchange.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Exchange Security Tips
Is full email encryption the solution to Exchange security?
Lock down direct file access and protect OWA users
Controlling spam in Exchange 2007 at the edge transport server level
When to use a self-signed certificate with Exchange Server 2007
Obtaining and verifying SSL certificates in Exchange Server
Understanding Exchange Server 2007 SP1 mobile security settings
Which ActiveSync authentication method is best for your mobile device?
Why you should secure Exchange 2007 using administrative policies
Microsoft Exchange Server security dos and don'ts
Create a journal rule in Exchange 2007 to secure journaling mailboxes

Spam and virus protection
Controlling spam in Exchange 2007 at the edge transport server level
Problems with email spoofing on SBS 2003
Exchange Insider e-zine
Securing your Exchange Server 2007 journaling archives
Troubleshooting Outlook Web Access issues on a 64-bit system
Microsoft Exchange Server security dos and don'ts
Troubleshooting Microsoft Exchange Server Event ID error 6009
How effective is tracking the IP address of an email hacker?
How can I configure Exchange IMF to allow an IP address or DNS?
Tool helps identify inbound Exchange Server email flow issues
Spam and virus protection Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
greylist  (SearchExchange.com)
hash buster  (SearchExchange.com)
image spam  (SearchExchange.com)
KnujOn  (SearchExchange.com)
Sender ID  (SearchExchange.com)
spam confidence level  (SearchExchange.com)
spamblock  (SearchExchange.com)
spim  (SearchExchange.com)
tarpitting  (SearchExchange.com)
teergrube  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Email Server Solutions: Exchange 2007, Exchange 2003, Exchange 2000, SharePoint
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts