This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to delete manually files in quarantine

Hi all,

Environment : Windows 2008R2 Server used as a file server

Running Sophos Endpoint Security and Control v10.2 on the server

The antivirus detected several infected files.

In the Quanrantine manager, under the "Available actions" column :

"no action (manual cleanup required)"

When trying to manually remove these files (with a basic Shift+Del), there is a message "Authorization Required" (as files are in quarantine).

Even the main domain administrator login is unsufficient.

How are we supposed to delete those files ?

All the best-

:38977


This thread was automatically locked due to age.
Parents
  • Path is U:\***\Documents\***\Downloads\SuperOneClickv1.9.1-ShortFuse\Exploits

    File is U:\***\Documents\***\Downloads\SuperOneClickv1.9.1-ShortFuse\Exploits\psneuter

    Threat is Andr/DroidRt-A

    I am connected as the main domain administrator (DOMAINNAME\Administrator)

    I click on the file to select it, then I press the "Delete" button on my keyboard.

    First, a popup appears in the taskbar :

    "Threats detected by Sophos

    'Virus/Spyware' Andr/DroidRt-A has been detected and moved to quarantine

    Click there to see the Quanrantine Manager"

    (this is a translation : English exact equivalent may differ)

    Then (a few milliseconds after), a Windows popup window appears :

    "Delete several elements

    Do you really want to delete permanently these 1 elements ?

    [Yes] [No]"

    I click on "[Yes]"

    The Sophos popup in the taskbar appears again, exactly the same.

    A Windows popup appears :

    "Access to file denied

    You must have permission to perform this action.
    You need permission from DOMAINNAME\Administrator to edit this file.
    psneuter

    Type : File

    Size : 572 Ko

    Modified : 08/01/11 18:02

    [Retry] [Abort]"

    One again I am connected as DOMAINNAME\Administrator !!!


    When I click on [Retry], the same Windows popup appears endlessly.

    Any advice is welcome !

    :39323
Reply
  • Path is U:\***\Documents\***\Downloads\SuperOneClickv1.9.1-ShortFuse\Exploits

    File is U:\***\Documents\***\Downloads\SuperOneClickv1.9.1-ShortFuse\Exploits\psneuter

    Threat is Andr/DroidRt-A

    I am connected as the main domain administrator (DOMAINNAME\Administrator)

    I click on the file to select it, then I press the "Delete" button on my keyboard.

    First, a popup appears in the taskbar :

    "Threats detected by Sophos

    'Virus/Spyware' Andr/DroidRt-A has been detected and moved to quarantine

    Click there to see the Quanrantine Manager"

    (this is a translation : English exact equivalent may differ)

    Then (a few milliseconds after), a Windows popup window appears :

    "Delete several elements

    Do you really want to delete permanently these 1 elements ?

    [Yes] [No]"

    I click on "[Yes]"

    The Sophos popup in the taskbar appears again, exactly the same.

    A Windows popup appears :

    "Access to file denied

    You must have permission to perform this action.
    You need permission from DOMAINNAME\Administrator to edit this file.
    psneuter

    Type : File

    Size : 572 Ko

    Modified : 08/01/11 18:02

    [Retry] [Abort]"

    One again I am connected as DOMAINNAME\Administrator !!!


    When I click on [Retry], the same Windows popup appears endlessly.

    Any advice is welcome !

    :39323
Children
No Data