thanks, yes.. I noticed that too.. we need to review both the SIC and VIE docs better I think - in the grand scheme of things, they were quite late additions to the product.
If I remove SEP and reinstall it, are the files still marked as clean? I assume yes.
No, when you remove SEP, you remove our internal file database too - thats where we have the VIE information.
If a pattern file update occurs, these marked files will still go through unscanned, right? I assume yes.
Yes, they will continue to be unscanned. Content updates do not alter the VIE setting
If I patch my server, new files are not marked so occasionally I need to scan the server for viruses and re-run the tool. Defraging doesn't unmark a file, correct? The attribute stays with the file?
Correct, new files would not be whitelisted, defragging doesn'[t change anything
If I run VIETool against an existing server and that server that has "malware" such as cookies or viral JAR files in Java cache, and those files are not deleted by SEP due to policy or whatever reason, am I marking those files as clean and leaving myself without protection from those files?
Yes, if you whitelist it, then its clean as far as AV is concerned. SONAR will continue to run against it, but you are definitely exposing yourself. I would suggest you take the server off the network while you run the VIEtool, then put it back online.