Quarantined Files

A Quarantined File is a file that has been found to be or to contain malware and has therefore been encrypted and moved to a special folder. ("Quarantine" is a scan action that you can specify when creating a Malware Scan Configuration.) Once the file has been identified and quarantined, you can choose to download it to your computer in an encrypted and compressed format. Whether or not an infected file is quarantined depends on the Anti-Malware Configuration that was in effect when the file was scanned.

After the quarantined file has been downloaded to your computer, the Quarantined File wizard will display a link to an Administration Utility which you can use to decrypt, examine, and restore the file.

A limited amount of disk space is set aside for storing quarantined files. The amount of space can be configured in Policy/Computer Editor > Anti-Malware > Advanced > Quarantined Files. Alerts are raised when there is not enough disk space to quarantine a suspicious file.

If you are using a Deep Security Virtual Appliance to provide protection to virtual machines, all quarantined files from the Agentless VMs will be stored on the Virtual Appliance. As a result, you should increase the amount of disk space for quarantined files on the Virtual Appliance.

Quarantined files will be automatically deleted from a Virtual Appliance under the following circumstances:

The Anti-Malware Quarantined Files page allows you to manage quarantine tasks. Using the menu bar or the right-click context menu, you can:

Details

The Quarantined File Details window displays more information about the file and lets you download the quarantined file to your computer or delete it where it is.

Filter the List and/or Search for a Quarantined File

The Period tool bar allows you to filter the list to display only those files quarantined within a specific time frame.

The Computers tool bar allows you to organize the display of quarantined file entries by Computer Groups or Computer Policies.

Selecting "Open Advanced Search" from the "Search" drop-down menu toggles the display of the advanced search options:

Advanced Search functions (searches are not case sensitive):

Pressing the "plus" button (+) to the right of the search bar will display an additional search bar so you can apply multiple parameters to your search. When you are ready, press the submit button (at the right of the tool bars with the right-arrow on it).

Manually Restoring Quarantined Files

To manually restore a quarantined file, you must use the quarantined file decryption utility to decrypt the file and then move it back to its original location. The decryption utility is in a zip file, QFAdminUtil_win32.zip, located in the "util" folder under the Vulnerability ProtectionDeep Security Manager root directory. The zipped file contains two utilities which perform the same function: QDecrypt.exe and QDecrypt.com. Running QDecrypt.exe invokes an open file dialog that lets you select the file for decryption. QDecrypt.com is a command-line utility with the following options:

This utility is supported only on Windows 32-bit systems.