12-12-2011 05:05 AM
Dear all,
we are implementing EV 9.0 in an Mixed MS Exchange environemnt (2003/2007/2010).
Today the McAfee Virusscanner pops up because some process touched an email with an EICAR Testfile. This is fine, because it shows the Virusscanner is working somehow.
But why is the mail touched by EV ? It does not meet the archiving criterias (older than 30 days) nor was it manually archived. The path however (please see screenshot) points to EV as the process touching this email.
Can someone please enlighten me ?
best regards,
SK
Solved! Go to Solution.
12-13-2011 02:09 AM
Correct me if i'm wrong. The pre-emptive trawl is of the .ost file so just exclude the folder where the file resides.
12-12-2011 06:41 AM
Based on the names of the files and the folder it may be that AV is scanning vault cache / offline vault?
Normally though I would expect the users folder structure to be more like this:
C:\Users\fred_bloggs\AppData\Local\KVS\Enterprise Vault............
Do you have group policy set to redirect folders? or perhaps somone has copied the files to that folder.
The program folder for the installed client is usually: C:\Program Files (x86)\Enterprise Vault\EVClient
or C:\Program Files\Enterprise Vault\EVClient
12-12-2011 08:54 AM
what shows EV is doing this? Apart from the EV letters in the filename....
Are you using Vault Cache? This may be the Pre-emptive scan kicking in.
12-13-2011 01:57 AM
Yes, we use Vault Cache and I have also the pre-emptive scan under suspicion... But the (google) results are very rare regarding the pre-emptive scan...If it is wise to exclude the folders the pre-emptive scan is using, it would be nice to know which folder(s) are used for it...
best regards,
SK
12-13-2011 02:09 AM
Correct me if i'm wrong. The pre-emptive trawl is of the .ost file so just exclude the folder where the file resides.