Jump to content

Archived

This topic is now archived and is closed to further replies.

Campbell IT

How to delete files from client quarantine?

Recommended Posts

Using ESMC 7.1.717.0, trying to figure out the process for deleting detections from the quarantine on a client. For the life of me, I cannot figure out how to do this. I get an alert that there is a detection that has not been resolved, so I look at the detections and click on Show Details. It shows me the details of the detection and has the client name in the upper left. I click on the Show Details button below the client name and it takes me to the details of that client. It lists the detections for that client, so I click on Show Details and it takes me right back where I started. Can we please just have a button to delete items from quarantine?

This product is so overly complicated it's making me start to think of alternative products.

Share this post


Link to post
Share on other sites

Never mind. Now I see there is another tab. Everything was so easy in 5.x. Even after 18 months + of using 7.x, I still get stumped. It really needs to be redesigned and streamlined.

Share this post


Link to post
Share on other sites

Deleting files from quarantine does not resolve detections. Files can be kept in quarantine unless they take up a lot of disk space which usually doesn't happen; malware is typically quite small with the size even below 1 MB. In quarantine objects are kept in a safe encrypted form to prevent execution.

Share this post


Link to post
Share on other sites
9 hours ago, Marcos said:

Deleting files from quarantine does not resolve detections. Files can be kept in quarantine unless they take up a lot of disk space which usually doesn't happen; malware is typically quite small with the size even below 1 MB. In quarantine objects are kept in a safe encrypted form to prevent execution.

How do I know what detections have been resolved and no longer need my attention? I have set the filter to the Preset filter "All unresolved threats" and it shows all threats back to Oct 2019, even those that have a check in the column "Resolved". If they are resolved and I set the ESET Preset filter "All unresolved threats", why is it showing me resolved threats? It is very difficult to tell what computers need to be examined more closely.

Also, what does ESET consider as an action taken? Because that filter also shows detections back to Oct 2019 if I select "All threats without action taken".

Is this a browser issue? I am using FIrefox 75.0

Share this post


Link to post
Share on other sites

Did you upgrade from ERA v6 to ESMC just recently ? For me the "Detection resolved" filter in the Detection window works fine:

image.png

Share this post


Link to post
Share on other sites

No, I installed ESMC 7 fresh some time ago and upgraded to 7.1.717.0 in the last few months.

Share this post


Link to post
Share on other sites

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...