Alright, here is the thing, I DO NOT have an Exchange server. The company I work for has no interest in setting one up either. That being said, here is the situation.
My mail server has SEP installed on it as a client as well as every Windows workstation that could potentially have access to mail or the internet.
Between my ISP and my mail server I have a dedicated Anti-Spam firewall with integrated AV- actually 2 AVs (different products). Works great.
The other day, my SPAM firewall, not to be confused with the perimeter firewall, had an issue with the HDD (5 minute fix), while doing the FSCK on the drive, the power supply blew out. An older machine, P4, 2 gigs ram, etc. No replacement parts. So I need to rebuild a new one. No longer a 5 minute fix. The bosses upset at this point, "we have AV, open the pipe directly". Well, in the 2 hours that the mail server was now accepting blindly every e.mail coming to it, Virus, SPAM, and redistributing it to all the mailboxes in the place. Now, we keep all messages on our server, and all connections are IMAP. In those 2 hours, I have over 2,400 Viruses that have infected the individual mailboxes. Really harmless bugs to tell the truth. Amongst them are:
- W32.Toal.A@mm
- Packed.Generic.233
- Packed.Generic.243
- Antivirus2008
and a few more.
********
Now the issue I have is every single mailbox is/was infected with these same bugs. But every single mailbox "cleaned" or "quarantined" is different. For example:
Mailbox A has -
W32.Toal.A@mm (4 times) and each instance of this file is quarantined and each quarantined file is 13,681 KB (That's right 13 Megs)
Mailbox B has the same -
W32.Toal.A@mm (4 itmes) and each instance of the file is quarantined. However eah quarantine file is 870,619 KB (Roughly 850 Megs) for a total of 3.4 Gigs...
Now, if I let this whole thing go, without monitoring and cleaning the quarantine folder, which potentially contains abot 1,700 files of varying size, from 4 MEGS to 850 Megs... My quarantine folder is filling up Terrabytes of Space, completely choking the mail server...
Why is the size difference in the quarantine folder so huge??
Furthermore, the attachment, be it in ZIP format is less than 1 MEG. Unzipped 2 Megs and quarantined up to 850!!!