PDA

View Full Version : Question about deleting viruses in quarantine


psychopomp1
August 12th, 2009, 03:22 AM
Hi

Sorry if this sounds a stoopid question but when you delete (using delete button) viruses from quarantine in ESS v4.0.437 are you actually removing them permanently from your hard disk or only removing them from quarantine display and thus restoring the file?

I ask this because it seems my USB flash drive became infected with a couple of viruses. Each time i plugged my usb drive in, ESET detected 2 viruses and quarantined; i then manually deleted these 2 viruses from quarantine using delete button on keyboard. However when i plugged by usb drive again, the same viruses popped up again in quarantine, which makes me think i was restoring the viruses by pressing the delete button on previous attempts! I have now got rid of these viruses by right clicking on my flash drive in explorer and selecting ADVANCED OPTIONS>CLEAN.

Marcos
August 12th, 2009, 03:27 AM
If a threat is detected, the malicious file is quarantined (in other words, moved to quarantine) where it's stored in an encrypted form. If you flush the quarantine content, you permanently delete the encrypted files so they cannot be restored by you in the future any more.

psychopomp1
August 12th, 2009, 03:35 AM
Thanks for clearing that up Marcos, but may i ask why after i deleted the files from quarantine they kept re-appearing each time i plugged the USB drive? Both infected files were system files and one of them was called auto_run.inf (i think).

Cheers :)

stackz
August 12th, 2009, 04:10 AM
-{ Quote: "I have now got rid of these viruses by right clicking on my flash drive in explorer and selecting ADVANCED OPTIONS>CLEAN." }-

You answered your question already, the flash drive was infected.

Marcos
August 12th, 2009, 04:21 AM
I'd suggest looking into autorun.inf and scanning the exe file it triggers. If it's not detected, email it to ESET per the instructions here (http://kb.eset.com/esetkb/index?page=content&id=SOLN141&actp=search&viewlocale=en_US&searchid=1250065251766).