I went with the same, except for the crucial last option and chose delete instead of move. Two reasons for that I suppose: 1. I'm prepared to risk losing a file and resorting to restoring a backup for the peace of mind I get from knowing any risky file is off my network. 2. I don't have the administration time to fully assess the accuracy of each identified threat so it would be left sitting in some toxic folder somewhere and, as I said in 1., I want this stuff off my network ASAP!