Delete newly created infected files if the action is “Leave alone (log only)” - Explanation of setting
book
Article ID: 152951
calendar_today
Updated On:
Products
Endpoint Protection
Issue/Introduction
Provide more information on the setting that could be configured on the SEP client by following the steps below:
Click on Change Settings in the SEP client console,
Click on Antivirus and Antispyware Protection, Configure Settings and then switch to File System Auto-Protect tab and click on the Advanced button,
Checkbox next to "Delete newly created infected files if the action is “Leave alone (log only)”
Resolution
You can enable this option to delete a new file that is infected with a type of risk that you configured Auto-Protect to leave alone.
This does not apply to infected files already detected as infected by Auto-Protect with the status of "Leave alone (log only)", "Quarantined" or any other status since Auto-Protect runs in real-time it will only apply to those new detections.
Although this is an added feature of protection you should be aware of a possible issue if you encounter false positive detections. Those files which are detected as infected may need to be restored from a backup