4.
Keep safe: the integrated, password protected quarantine
You can reach the new quarantine management version 7 through the TAB quarantine.
The quarantine management is used to integrate and to later process files, which are classified as suspicious or possibly as infected through the on demand scanner or the on access scanner (Guard). It is furthermore also possible to add files manually to the quarantine.
You can either move the files manually (interactive) to the quarantine through the on demand scanner or automatically through the on access scanner. The corresponding settings can be performed by configuring the scanner or the Guard.
If the option “automatically” is chosen when configuring the scanner and the Guard in the area of “action in case of virus detection”, you can determine to move the corresponding file to the quarantine as a primary action for this option. If another action is chosen, it is still possible to additionally determine that a copy of the relevant file can be moved to the quarantine.
Files that are moved to the quarantine are encrypted and receive the file extension ”.qua”. Important data is saved in the header of the file to identify the file and the existing infection. Those are, among others.
- The original file name
- The time indication, when a file was moved to the quarantine
- The status of the file (in the quarantine, disinfected, transmission etc.)
- The name of the user, the access of the virus
- The computer name of the affected computer
- The IP address of the affected computer
- The used operating system
- Additional information of the operating system
-
- The version of the search engine
- The version of the virus definition file
- The version of other files such as Packlib, program files etc.
Files that are in the quarantine can’t be started directly anymore. But they can be handled in different ways. The following alternatives are possible:
- Examine again
- Display extended settings
- Reestablish object
- Reestablish object in another place
- Add suspicious files manually to the quarantine
- Send object
- Delete object from the quarantine
As the quarantine is an area, which is very sensitive to security, the rights a user has in this area can be determined separately in the configuration (area general/password). You can secure the following rights by allocating a password against unauthorized access:
- Restoring relevant objects
- Repairing relevant objects
- Display setting of the relevant objects
- Delete relevant objects
- Send emails