Managing quarantined files

Prev Next

When malware protection and malware remediation (quarantine) are enabled, the infected files are copied to a quarantine area automatically. You can acquire these files for analysis.

In addition to quarantining the infected file, attempts to clean the file in its original location may be made.

  • If the infection appended infected code to user files, an attempt is made to clean the infection from the files. If the attempt to clean the files fails, an attempt is made to delete the file on the endpoint.

  • If the infection introduced new files to the endpoint, an attempt is made to delete them. If the infected files are locked and cannot be deleted without rebooting the endpoint, a notification message appears on the endpoint.

Quarantined files are stored in the quarantine area on the host endpoint until you manually delete them or they exceed the quarantine file aging period. The quarantine file aging period is specified per policy. The default is 90 days. For complete information on specifying malware protection settings, see the Endpoint Security Agent (HX) Administration Guide.

This section describes how to manage quarantined files in the quarantine area.

Prerequisites
  • Admin, Analyst, Senior Analyst, or Investigator access