ScanMail uses the virus pattern file to identify known malicious
macro codes during regular virus scanning. ScanMail takes action
against malicious macro code depending on the action that you configure from the
Security Risk Scan screen. Use advanced macro scanning to gain
additional protection against malicious macro code.
Advanced macro scanning supplements regular virus scanning. It
uses heuristic scanning to detect macro viruses/malware or strips all detected macro
codes. Heuristic scanning is an evaluative method of detecting viruses that uses
pattern recognition and rules-based technologies to search for malicious macro code.
This method excels at detecting undiscovered viruses and security risks that do not
have a known virus signature. When a malicious macro code is detected using
heuristic scanning, ScanMail takes action against the malicious code based on the
action that you configured from the Security Risk Scan screen. When you select Delete all macros detected by advanced macro
scan, then
ScanMail strips all
macro code from the scanned files.
Procedure
- Go to the Security Risk Scan screen
by navigating to one of the following:
-
For Real-time scans:
-
For Manual scans:
-
For Scheduled scans:
-
- Click Advanced Options and then click Macros.
- Select Enable advanced macro scan.
- Select a detection type:
- Select Heuristic level and configure a level for the
heuristic rules.
-
Level 1 uses the most specific criteria, but detects the least macro codes.
-
Level 4 detects the most macro codes, but uses the least specific criteria and may falsely identify safe macro code as harboring malicious macro code.
Tip
Trend Micro recommends a heuristic scan level of 2. This level provides a high detection level for unknown macro viruses, a fast scanning speed, and it uses only the necessary rules to check for macro virus/malware strings. Level 2 also has a low level of falsely identifying malicious code in safe macro code. -
- Select Delete all macros detected by advanced macro scan to have ScanMail delete all of the macro codes that it detects.
- Specify the email messages in which the detected macro codes will be deleted:
-
All messages: Select to delete all macro codes detected by advanced macro scan in all messages.
-
Inbound messages: Select to delete all macro codes detected by advanced macro scan only in inbound messages.
- Select Heuristic level and configure a level for the
heuristic rules.
- Click Save.