Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

200 Threat Clean Up Limit (WM97/ColdApe-A)

Hello,

A family member had thousands of Word doc files infected with the WM97/ColdApe-A macro virus. Sophos AV for Mac had identified these documents and offered to clean the threats. After a cleanup, a subsequent scan revealled that the Word documents were still a threat. After another threat removal, a post-cleanup scan indicated that documents still were infected with WM97/ColdApe. After reinstalling Sophos AV, repairing permissions, and even upgrading from 10.4 to 10.6 threats were still identified. Then the half dozen scan logs I have accumulated revealed a pattern; threat counts went down by 200. Sophos failed to clean the infected files all at once using "clean up threat" in the quarantine window, but instead had only taken out 200 after each scan/cleanup. Maybe I missed the 200 threat limit notice in the help and user agreement, or maybe it only effects the macro virus. In any event,  this information may help out somebody else (I didn't find it in a search of posts here). I wish I had noticed the pattern sooner, and could also get my 7 hours back. ;)

:1004607


This thread was automatically locked due to age.
  • Hello me,

    the 200 limit is documented in  About Quarantine Manager in the online Help. Although it's not explicitely stated one can assume that an action of course applies only to the items on the list. Note that you can use an "aggressive" custom scan (with the option to clean up detected items) instead of repeatedly going through QM.

    Christian 

    :1004609