Microsoft Forefront Security for SharePoint detects a large compressed file as CorruptedCompressedFile. When the Block/Delete Corrupted Compressed Files general option is selected, Forefront Security for SharePoint deletes the file. However, if you open the file, you find that it is not corrupted.
This problem occurs if one of the following conditions is true:
The file exceeds the maximum compressed file size.
The file exceeds the maximum uncompressed file size.
This issue occurs because the file is too large and cannot be scanned.
In Forefront Security for SharePoint with Service Pack 3 (SP3), a new feature allows large compressed files through if they cannot be scanned. By default, Forefront Security for SharePoint with SP3 still deletes large files that exceed the size limit. You must add a "SkipLargeCompressedFileDeletion" DWORD registry key entry to enable this feature. For more information about Forefront Security for SharePoint SP3, click the following article number to view the article in the Microsoft Knowledge Base:
967995 Description of Forefront Security for SharePoint with Service Pack 3
Steps to enable the feature
Install Forefront Security for SharePoint Service Pack 3.
Add the "SkipLargeCompressedFileDeletion" DWORD registry key entry and set the value to 1. To do this, follow these steps:
Click Start, click Run, type regedit in the Run box, and then press ENTER.
Locate and then click the following registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Forefront Server Security\Sharepoint
On the Edit menu, point to New, and then click DWORD Value.
Type SkipLargeCompressedFileDeletion, and then press ENTER.
Right-click SkipLargeCompressedFileDeletion for the name of the DWORD, and then click Modify.
In the Value data box, type 1, and then click OK.
Exit Registry Editor.
Activate the new settings. To do this, do one of the following:
In the Forefront Server Security Administrator client, click SETTINGS , and then click General Options. Change and save a general option setting. Then revert the setting to the original setting.
Note The registry settings are re-read when any of the general options is changed.
Restart the FSCController service from the Services panel. To do this, click Start, click Run, type services.msc, and then click OK. In the list of services, right-click FSCController, and then click Restart.
The SkipLargeCompressedFileDeletion registry value works together with the Block/Delete Corrupted Compressed Files general option.
If there is a large compressed file that exceeds either the maximum compressed file size or the maximum uncompressed file size, the following statements are true:
When both settings are enabled, the file will bypass scanning. It will be reported as either "Exceedingly Compressed Size" or "Large Uncompressed Size" respectively in Forefront Security for SharePoint logs and reports.
When the "SkipLargeCompressedFileDeletion" registry value is not enabled and the "Delete Corrupted Compressed Files" General Option is enabled, Forefront Security for SharePoint will detect the file as CorruptedCompressedFile and delete it.
When neither feature is enabled, no deletion will occur.
Note The maximum compressed file size and the maximum uncompressed file size are specified by the following registry values:
Maximum compressed file size:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Forefront Server Security\Sharepoint\MaxCompressedSize
Maximum uncompressed file size (not present by default, but hard-coded at 100MB):
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Forefront Server Security\Sharepoint\MaxUnCompressedFileSize