Use Quarantine to its Full Potential

H

hjlbx

Thread author
This method minimizes risk... simple , yet effective, way to deal with new malicious files that vendors have not added to signature database - yet.

If your AV has the capability to manually add a file to Quarantine and it can re-scan quarantined objects:

1. Add file to Quarantine

2. Keep it there for two weeks

3. If after quarantine period there is no signature detection, it is probably safe to restore the file

Few people use it... perceived inconvenience and impatient.

In my experience it does work...
 
  • Like
Reactions: viktik

Alexstrasza

Level 4
Verified
Mar 18, 2015
151
The most important use of Quarantine is that the malware material can be of use to researchers later (especially in the case of ransomware - see PClock).

Emsisoft products automatically rescan Quarantine when you update it, so it's not necessary if you use EAM/EIS.

Also in the case of #3: If you think it's malware, submit it to the vendor instead of just let it sit there. Malware potential won't change regardless of how long you let it sit there, you know :D
 
Last edited:

tallorder

Level 6
Verified
Jan 15, 2015
267
Hmmmmm, I didn't know that a quarantined item can be returned. I thought once it jailed, always jailed...
 

Alexstrasza

Level 4
Verified
Mar 18, 2015
151
Hmmmmm, I didn't know that a quarantined item can be returned. I thought once it jailed, always jailed...
That's not the case - Quarantine only stores the file in a special format to isolate it. If the file is checked later and found to be clean, then you can restore it :)
 
H

hjlbx

Thread author
Hmmmmm, I didn't know that a quarantined item can be returned. I thought once it jailed, always jailed...

Most all AV allow you to restore a detected file.

Not all AV allow you to manually add a file to quarantine. Kaspersky, for example, user cannot add file to quarantine manually.
 
D

Deleted member 2913

Thread author
Eset gives the option to manually quarantine.
Eset rescans the quarantine after update & restores fps.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Quarantine is a better option because some viruses/malware can turned out to be FP and we need that vital file in order to determine if its fully safe and can return to the normal operation.

Its just same in real life, when a person jailed he/she finish the imprisonment term then that's the time to get out on the jail.
 

Atlas147

Level 30
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 28, 2014
1,990
Personally I think that the best way is still to send the file itself to the AV vendors for analysis, rather than keeping it in quarantine for 2 weeks because it might be that the vendors do not add the signature because of low prevalence so in the end you might still get infected. I think if you do not run the suspicious file there is no way for the malware to infect your system.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top