Views:

Scenario

The detected file maybe locked by another process.

Solution

Restart the machine to clear the memory. This should release the detected file from the process which may have locked it. Afterwards, run a full scan and verify if the malicious file has been cleaned, deleted, or quarantined.

Scenario

The infected file may be contained in a compressed file (e.g. *.7zip, *Zip, *.RAR, etc.).

Solution

Enable the "Clean/Delete infected files within compressed files" option:

  1. Log on to the OfficeScan web console.
  2. Click Agents > Global Agent Settings > Security Settings tab.
  3. Under Virus/Malware Scan Settings Only, put a check on Clean/Delete infected files within compressed files.
  4. Click the Save button.
  5. Perform another manual scan to verify if the compressed file has been successfully cleaned or deleted.

When enabled, OfficeScan decompresses a compressed file, cleans/deletes infected files within the compressed file, and then re-compresses the file.

If the problem persists, do the following:

Submit the ATTK output together with the Virus/Malware logs to Trend Micro Technical Support for analysis.