stapp Posted February 7, 2021 Report Share Posted February 7, 2021 I have quite a few different types of eicar files that I keep in downloads so I can test EAM scanner. I always have EAM set to ALERT so that I can see in Forensic logs what they found. Today I was copying my pics and docs (including downloads) onto a memory stick as an additional backup along side Macrium. EAM quarantined 2 of the items... why? The other 2 eicar were left in downloads and copied over to the memory stick. (they were zip files) Link to comment Share on other sites More sharing options...
Frank H Posted February 8, 2021 Report Share Posted February 8, 2021 When you have set the File Guard in Default Scan mode, .com files are scanned. Zip files are not. Link to comment Share on other sites More sharing options...
JeremyNicoll Posted February 8, 2021 Report Share Posted February 8, 2021 But why was anything quarantined? @stappsaid that EAM was configured just to /alert/. Link to comment Share on other sites More sharing options...
ShadowPuterDude Posted February 8, 2021 Report Share Posted February 8, 2021 Check and make sure that "Automatically quarantine files with bad reputation" is not checked in Settings => Advanced. That looks like a a reputation based action was taken. Link to comment Share on other sites More sharing options...
Frank H Posted February 8, 2021 Report Share Posted February 8, 2021 30 minutes ago, JeremyNicoll said: But why was anything quarantined? @stappsaid that EAM was configured just to /alert/. I just tested and i got an alert while copying. @Kevin Zoll Alert overrules that setting you pointed to. Link to comment Share on other sites More sharing options...
stapp Posted February 9, 2021 Author Report Share Posted February 9, 2021 @Frank H I didn't see an alert. Is it expected behaviour for 'copy' to quarantine something even when I just have 'alert' as my preferred choice ? Link to comment Share on other sites More sharing options...
Frank H Posted February 9, 2021 Report Share Posted February 9, 2021 14 hours ago, stapp said: s it expected behaviour for 'copy' to quarantine something even when I just have 'alert' as my preferred choice ? Nope, an alert should popup if you have set that ,see screenshot. why that didn't happen? no idea. maybe you could try again. Link to comment Share on other sites More sharing options...
stapp Posted February 10, 2021 Author Report Share Posted February 10, 2021 I'll have another look when I next do a backup copy of all my data again to usb. I rely on Macrium so the backup is just for extra insurance. Link to comment Share on other sites More sharing options...
Recommended Posts