Is RU7 MP2 really going to fix this issue?
Your problem statement, that Symantec has taken several runs at this issue already, has been noted by engineering as well. Achitecturally, this is a difficult issue to address in a CRT release because of API changes required in our core components. The best fix would be to rescan the threat in memory rather than temporarily writing to disk. The temporary file will always be vulnerable to redetection by auto protect depending on the system configuration and other software running.
RU7 MP2 contains 2 improvements:
1) "Fixed some scan issues, making the scan faster". Engineering estimated the scan performance improvements reduce the chances of AP redetection by 90%. Since this is not a 100% solution, engineering added the second aspect for customers still suffering with this issue.
2) "Created a separate folder to rescan Quarantine items that can be used to create exceptions." This option provides another 100% effective solution to the problem by allowing a scan exception to be created on the SEPM. The new folder is used only for the temp rescan files.
The other two workarounds already mentioned in the thread should also be 100% effective:
1) Turn off the quarantine rescan feature, which provides limited value for most threats in the wild today.
2) Avoid use of "quarantine" action.
The architectural improvement to enable an in memory scan is tracked in our formal requirements management system and under discussion by product management for prioritization into a core team release.