Security Basics mailing list archives

Re: Why NOT to disable Real Time Antivirus on Servers


From: edizzle56 () hotmail com
Date: 3 Nov 2005 05:24:55 -0000

Will the real-time anti-virus even be able to suck viruses out of the exchange information store after they've arrived 
via SMTP?  That would be a key thing to find out..   If you're running a pure exchange server, without having any file 
shares, I'd advocate disabling the realtime anti-virus as well..   Unless you're actually running an email client or 
browsing the web from the exchange server..   If it's a server, clients aren't running code on it, does this 
"real-time" a/v provide some worm protection as well?  That would be a valid argument if it defended against 
network-based attacks--  Verify CPU utilization though, run performance monitor on CPU utilization for a day with it 
disabled and a day with it enabled, is it really worth arguing about?   


Current thread: