Hexamail Guard Configuration Reference [Antivirus]

[Antivirus]

The following settings can be used in this section:

Enable
You can turn off antivirus entirely using this switch
bool
On/Off, True/False, Yes/No, 1/0
on
Enable=on
Hide
You can hide the Antivirus interface entirely using this switch
bool
On/Off, True/False, Yes/No, 1/0
off
Hide=off
Action
this sets what you wish to do with email containing forbidden attachment types
flags
Block+Mark+Store
Action=Mark
MarkPrefix
this sets the subject prefix you wish to use to mark infected email
text
Potential Virus:
MarkPrefix=Potential Virus:
Alert
Alert administrator via email if the quarantine contains more than the configured number of infected email
bool
On/Off, True/False, Yes/No, 1/0
on
Alert=on
AlertAfter
Alert administrator via email if the quarantine contains more than this number of infected email
number
1 - 500 Email
10 Email
AlertAfter=50
AlertOnVirus
this sets who you wish to alert when an infected email is detected
flags
Sender+Admin
AlertOnVirus=Sender
CheckAttachments
Defines what to do when attachments matching those configured are found
select
Off, Mark, Detach, Block
Block
CheckAttachments=Block
AttachmentMatches
Wild cards for identifying attachments you wish to ALWAYS block or mark (regardless of infection)
text
*.exe,*.cmd,*.lnk,*.scr,*.ceo,*.bat,*.com,*.js,*.vbs,*.pif,*.jar,*.adp,*.app,*.asp,*.bas,*.bat,*.ce,*.cmd,*.cnt,*.com,*.cpl,*.crt,*.csh,*.de,*.exe,*.fxp,*.gadget,*.hlp,*.hpj,*.hta,*.inf,*.ins,*.isp,*.its,*.js,*.jse,*.ksh,*.lnk,*.mad,*.maf,*.mag,*.mam,*.maq,*.ma,*.mas,*.mat,*.mau,*.mav,*.maw,*.mda,*.mdb,*.mde,*.mdt,*.mdw,*.mdz,*.msc,*.msh,*.msh1,*.msh2,*.mshxml,*.msh1xml,*.msh2xml,*.msi,*.msp,*.mst,*.ops,*.osd,*.pcd,*.pif,*.plg,*.prf,*.prg,*.pst,*.reg,*.scf,*.sc,*.sct,*.shb,*.shs,*.ps1,*.ps1xml,*.ps2,*.ps2xml,*.psc1,*.psc2,*.tmp,*.url,*.vb,*.vbe,*.vbp,*.vbs,*.vsmacros,*.vsw,*.ws,*.wsc,*.wsf,*.wsh,*.xnk,*.ade,*.cla,*.class,*.grp,*.ja,*.mcf,*.ocx,*.pl,*.xbap
AttachmentMatches=*.exe,*.cmd,*.lnk,*.scr,*.ceo,*.bat,*.com,*.js,*.vbs,*.pif,*.jar,*.adp,*.app,*.asp,*.bas,*.bat,*.ce,*.cmd,*.cnt,*.com,*.cpl,*.crt,*.csh,*.de,*.exe,*.fxp,*.gadget,*.hlp,*.hpj,*.hta,*.inf,*.ins,*.isp,*.its,*.js,*.jse,*.ksh,*.lnk,*.mad,*.maf,*.mag,*.mam,*.maq,*.ma,*.mas,*.mat,*.mau,*.mav,*.maw,*.mda,*.mdb,*.mde,*.mdt,*.mdw,*.mdz,*.msc,*.msh,*.msh1,*.msh2,*.mshxml,*.msh1xml,*.msh2xml,*.msi,*.msp,*.mst,*.ops,*.osd,*.pcd,*.pif,*.plg,*.prf,*.prg,*.pst,*.reg,*.scf,*.sc,*.sct,*.shb,*.shs,*.ps1,*.ps1xml,*.ps2,*.ps2xml,*.psc1,*.psc2,*.tmp,*.url,*.vb,*.vbe,*.vbp,*.vbs,*.vsmacros,*.vsw,*.ws,*.wsc,*.wsf,*.wsh,*.xnk,*.ade,*.cla,*.class,*.grp,*.ja,*.mcf,*.ocx,*.pl,*.xbap
AttachmentInvalidChars
Attachments with names containing these characters will be blocked
text
?!"'`$;:,(){}[]<>%^*=@~#|\\=*%
AttachmentInvalidChars=?!"'`$;:,(){}[]<>%^*=@~#|\\=*%
Scanner
Defines what to do when attachments matching those configured are found to be infected
select
Off, Mark, Detach, Block
Block
Scanner=Block
ScannerAttachmentMatches
Wild cards for identifying attachments you wish to be scanned for virus, worms or other malicious or undesireable automated scripts
text
*.*
ScannerAttachmentMatches=*.exe,*.zip,*.doc,*.ppt,*.xls,*.eml,*.scr,*.ceo,*.bat,*.com,*.js,*.vbs,*.pif,*.jar,*.adp,*.app,*.asp,*.bas,*.bat,*.ce,*.chm,*.cmd,*.cnt,*.com,*.cpl,*.crt,*.csh,*.de,*.exe,*.fxp,*.gadget,*.hlp,*.hpj,*.hta,*.inf,*.ins,*.isp,*.its,*.js,*.jse,*.ksh,*.lnk,*.mad,*.maf,*.mag,*.mam,*.maq,*.ma,*.mas,*.mat,*.mau,*.mav,*.maw,*.mda,*.mdb,*.mde,*.mdt,*.mdw,*.mdz,*.msc,*.msh,*.msh1,*.msh2,*.mshxml,*.msh1xml,*.msh2xml,*.msi,*.msp,*.mst,*.ops,*.osd,*.pcd,*.pif,*.plg,*.prf,*.prg,*.pst,*.reg,*.scf,*.sc,*.sct,*.shb,*.shs,*.ps1,*.ps1xml,*.ps2,*.ps2xml,*.psc1,*.psc2,*.tmp,*.url,*.vb,*.vbe,*.vbp,*.vbs,*.vsmacros,*.vsw,*.ws,*.wsc,*.wsf,*.wsh,*.xnk,*.ade,*.cla,*.class,*.grp,*.ja,*.mcf,*.ocx,*.pl,*.xbap
ScannerAttachmentSkip
Wild cards for identifying attachments you do not wish to be scanned for virus, worms or other malicious or undesireable automated scripts
text
ScannerAttachmentSkip=*.mp3,*.wav
ScannerSigIgnore
Wild cards for identifying signatures you wish to ignore if detected
text
PUA.*
ScannerSigIgnore=PUA.*
BlockMacros
Block macros within office documents
bool
On/Off, True/False, Yes/No, 1/0
CmdScanner
Defines what to do when attachments matching those configured are found to be infected
select
Off, Mark, Detach, Block
Block
CmdScanner=Block
CmdScannerAttachmentMatches
Wild cards for identifying attachments you wish to be scanned for virus, worms or other malicious or undesireable automated scripts
text
*.*
CmdScannerAttachmentMatches=*.*
ScannerUpdateInterval
How often automatic updates should be made for the antivirus database and engine
number
1 - 168 hours
4 hours
ScannerUpdateInterval=4
AlertFrom
Enter the display name you wish to use for the Alert Sender. ex: Administrator
text
Postmaster
AlertFrom=Administrator
Alertsender
Enter the email address you wish to use for for the Alert Sender. ex: postmaster@domain.com
text
Alertsender=postmaster@domain.com
AlertSubject
Enter the Virus alert subject you would like to use.
text
Virus warning: <subject>
AlertSubject=Virus warning: <subject>
AlertMessage
Enter the virus alert message you would like to use.
text
This is the virus scanner at <domain>. The message from <from> to <to> was blocked by the antivirus scanner. <virusThe virus found was: > <attachmentA forbidden attachment type was found: >
AlertMessage= This is the virus scanner at <domain>. The message from <from> to <to> was blocked by the antivirus scanner. <virusYOUR MESSAGE HERE:> <attachmentYOUR MESSAGE HERE:>
AlertTo
This sets who will get a virus warning message when a virus is found
flags
Administrator
AlertTo=Recipient
AdviceMessageVirus
Enter the virus advice message you would like to use. This is the message inserted if attachments are detached from an email because the scanner detects a virus.
text
The attachment '<attachname>' was removed because it contained the virus '<virus>' (<viruscode>)
AdviceMessageVirus=The attachment '<attachname>' was removed because it contained the virus '<virus>' (<viruscode>)
AdviceMessageType
Enter the attachment advice message you would like to use. This is the message inserted if attachments are detached from an email because the type of attachment is blocked.
text
The attachment '<attachname>' was removed because attachments of that type have been blocked by the administrator
AdviceMessageType=The attachment '<attachname>' was removed because attachments of that type have been blocked by the administrator
FileScanGeneric
Use command line virus scanner
false
FileScanGeneric=false
FileScanGenericCommandLine
FileScanAVG
Use AVG installed on this machine
off
FileScanAVG=off
FileScanAvast
Use Avast installed on this machine
off
FileScanAvast=off
FileScanKaspersky
Use Kaspersky installed on this machine
off
FileScanKaspersky=off
FileScanBitDefender
Use BitDefender installed on this machine
off
FileScanBitDefender=off
FileScanESET
Use ESET installed on this machine
off
FileScanESET=off
FileScanGData
Use G Data installed on this machine
off
FileScanGData=off
FileScanClamD
Use ClamD installed on this machine
off
FileScanClamD=off
FileScanClamDPath
Specify the folder or path containing the clamdscan.exe executable
EnableAlerts
Enable alerts to be sent. No virus alerts will be sent when this is unchecked.
bool
On/Off, True/False, Yes/No, 1/0
off
EnableAlerts=off