This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Removed from quarantine list

I have noticed a new Action Taken catagory within the Sophos Enterprise Console  for Endpoint Secuirty and Control ver 9 call "Removed from quarantine list".  What does this mean?  DId the user remove the virus from the Quarantine manager or did Sophos do something internally?

:1184


This thread was automatically locked due to age.
Parents
  • Hi,

    Just did a quick test... If you detect eicar.com on a client machine, an entry gets created in the QM on the client and you get an alert in SEC.  If however the file, lets say C:\eicar.com is deleted by the user or an application for example: The QM on the client doesn't update as it doesn't constantly check that everything that has been detected is still on disk, presumably for performance reasons.

    So then in SEC you might issue a clean-up on C:\Eicar.com as it's still outstanding in SEC, this essentially fails as the file has already been deleted; hence "Removed from quarantine list".  It then clears the alert in SEC as essentially the threat has been dealt with.  It seems like just extra info to me that the file has been removed externally to SAV which can often be the case if a file is in a temp location and then purged.

    Regards,

    Jak

    :8061
Reply
  • Hi,

    Just did a quick test... If you detect eicar.com on a client machine, an entry gets created in the QM on the client and you get an alert in SEC.  If however the file, lets say C:\eicar.com is deleted by the user or an application for example: The QM on the client doesn't update as it doesn't constantly check that everything that has been detected is still on disk, presumably for performance reasons.

    So then in SEC you might issue a clean-up on C:\Eicar.com as it's still outstanding in SEC, this essentially fails as the file has already been deleted; hence "Removed from quarantine list".  It then clears the alert in SEC as essentially the threat has been dealt with.  It seems like just extra info to me that the file has been removed externally to SAV which can often be the case if a file is in a temp location and then purged.

    Regards,

    Jak

    :8061
Children
No Data