Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Recommendation for Scan Compressed/Archives Setting

Hi.  New to forum.  Recent 'reconvert' back to Mac platform.  Question is what is Sophos best practice for the 'scan compressed/archives' setting?  It's check by default when I installed, but from reading some of the post here it gives me pause.  It certainly speeds up the scan times.  Initially it seems it would provide a risk to leave it off, but in all honesty given the current Mac malware exposure is it necessary?

Comments welcome :)

:1000683


This thread was automatically locked due to age.
  • Hello prg,

    if you are content with my personal view ...

    The setting is not global. 

    • It is not set for on-access and you better leave it off. See Jupp's post for an explanation.
    • Sweep from the terminal has it off.
    • Scan Local Drives has it on to make sure there are no threats lurking in objects which might be (only be opened and) used somewhere else. Its settings also apply to a Finder Scan.
    • A new Custom Scan has it on.

    So the Best Practice is to use it  for scans but only in the following cases

    - for an initial scan to assess "what's there" (but note the reported issues e.g. with NTFS partitions or large archives)

    - for archives to be sent "somewhere else" (except when they have recently been built on the machine and on-access scan was enabled)

    - for archives stored on the Mac from "somehere else"

    HTH

    Christian

    :1000689