User guide

M A I L P R O T E C T I O N
55
EMAIL SCANNING IN THE BAT!
Actions on infected email objects in The Bat! are defined using the application's own tools.
Mail Anti-Virus settings determining if incoming and outgoing messages should be scanned, which actions should be
performed on dangerous objects in email, and which exclusions should apply, are ignored. The only thing that The Bat!
takes into account is scanning of attached archives.
The email protection settings extend to all the anti-virus modules installed on the computer that support work with the
Bat!.
Please remember, incoming email messages are first scanned by Mail Anti-Virus and only after that by The Bat! mail
client plug-in. If a malicious object is detected, Kaspersky Anti-Virus will inform you of this without fail. If you select the
Disinfect (Delete) action in the notification window of Mail Anti-Virus, actions aimed at eliminating the threat will be
performed by Mail Anti-Virus. If you select the Skip action in the notification window, the object will be disinfected by The
Bat! plug-in. When sending email messages, the scan is first performed by the plug-in, then by Mail Anti-Virus.
You must decide:
Which stream of email messages will be scanned (incoming, outgoing).
At what point in time email objects will be scanned (when opening an email message or before it is saved to the
disk).
The actions taken by the mail client when dangerous objects are detected in emails. For example, you could
select:
Attempt to disinfect infected parts if this option is selected, the infected object will be attempted to
disinfect; if it cannot be disinfected, the object will remain in the message.
Delete infected parts if this option is selected, the dangerous object in the message will be deleted
regardless of whether it is infected or suspected to be infected.
By default, The Bat! places all infected email objects in Quarantine without attempting to disinfect them.
The Bat! does not give special headers to emails containing dangerous objects.
To set up email protection rules in The Bat!:
1. Open the main The Bat! window.
2. Select the Settings item from the Properties menu of the mail client.
3. Select the Virus protection item from the settings tree.
USING HEURISTIC ANALYSIS
Essentially, the heuristic method analyzes the object's activities in the system. If those actions are typical of malicious
objects, the object is likely to be classed as malicious or suspicious. This allows new threats to be detected before they
have been analyzed by virus analysts. By default, heuristic analysis is enabled.
Kaspersky Anti-Virus will notify you when a malicious object is detected in a message. You should react to the notification
by further processing the message.
Additionally you can set the detail level for scans: Light, Medium, or Deep. To do so, move the slider bar to the selected
position.