This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Best practice for On-Access scan settings

Hello,

I know by default that the On-Access scan settings for Viruses/spyware is set to "Deny access only" but I wanted to get a feel for what others are doing and why?

We are using the defaul setting for On-Access and then in our weekly scan schedule we set the Automatically clean up.  But it seems that when machiens are offline during the weekly scan schedule that they are never getting cleaned unless we manually clean them from the console during the day.

Thoughts about why we should not just set the On-Access scan to automatically clean?

Does anybody know what the defaults are for other AV prodcuts?

:2647


This thread was automatically locked due to age.
Parents
  • If it is a known virus/spyware, then again here, its a no nonsense outlook. We want it to clean up immediately! We are in the same boat that things may not be cleaned for weeks on end otherwise.

    If its suspicious files, then I leave them on the station, but block them. I then go in and submit a sample to Sophos.

    Ideally I'd like to move any suspiciously behaving files to move to my local C: on my admin station, but have so far struggled with implementing that.

    I can't see why you wouldn't automatically clean, as typically you should have a backup of any files that become infected, so you can roll back on those and leaving a virus on the computer may lead to it floating around the system (if some policies aren't up to date or a Sophos services aren't running correctly on a station)

    :2668
Reply
  • If it is a known virus/spyware, then again here, its a no nonsense outlook. We want it to clean up immediately! We are in the same boat that things may not be cleaned for weeks on end otherwise.

    If its suspicious files, then I leave them on the station, but block them. I then go in and submit a sample to Sophos.

    Ideally I'd like to move any suspiciously behaving files to move to my local C: on my admin station, but have so far struggled with implementing that.

    I can't see why you wouldn't automatically clean, as typically you should have a backup of any files that become infected, so you can roll back on those and leaving a virus on the computer may lead to it floating around the system (if some policies aren't up to date or a Sophos services aren't running correctly on a station)

    :2668
Children
No Data