This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to delete threat due to on-access protection

This qusetion is in an office setting.

A lot of times when a threat is identified by Sophos, it is unable to cleanup automatically. A manual clean up (delete the file) is required. However, when I try to delete the file, Sophos does the on-access scanning and blocks the delete too!

What is the best and recommended way to delete the file?

I know I can go to the endpoint and disable the on-access on the client machine, but I prefer to be able to remotely access the infected computer, navigate to the threat location and simply delete it. All from the comfort of my desk.

Can someone kindly give me some advice? Thanks.

:53889


This thread was automatically locked due to age.
Parents
  • Hello Incoloy,

    On-Access doesn't block delete requests. What makes you think it does? Did you actually  try to delete it - could you give a detailed description of what you did and where it seemingly failed?

    I know I can go to the endpoint and disable the on-access on the client machine

    You shouldn't even think of doing so - an unfortunate click could activate the threat. You should never turn off On-Access scanning with a threat present on an endpoint.

    Christian

    :53893
Reply
  • Hello Incoloy,

    On-Access doesn't block delete requests. What makes you think it does? Did you actually  try to delete it - could you give a detailed description of what you did and where it seemingly failed?

    I know I can go to the endpoint and disable the on-access on the client machine

    You shouldn't even think of doing so - an unfortunate click could activate the threat. You should never turn off On-Access scanning with a threat present on an endpoint.

    Christian

    :53893
Children
No Data