- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-10-2023 02:13 PM
Hello dear community,
what happens with quarantined files, which have 300 MB?
I can't download it from the action center like I am used to.
Yes, I saw they are moved to %PROGRAMDATA%\Cyvera\Quarantine
), but can I get it from there?
Would you hunt big files, which are executed by users?
BR
Rob
09-11-2023 12:08 PM
Yes, if you need the files at the moment, it needs to be online. If it is not, the task is hold as "Pending" until the client connects again with the console.
I tried to retrieve files with the route %PROGRAMDATA%\Cyvera\QuarantineV2\*.* and all came encrypted.
Thanks!
JM
09-11-2023 06:51 AM
Hi @RFeyertag, thanks for contacting us in the Live Community.
I'll do some checks and I'll be back with more information about retrieving files from quarantine (without restoring them).
Is really hard to find a 300MB malware file, maybe a zipped one containing it. Is a size that is really hard to manage on any solution.
09-11-2023 10:07 AM
@RFeyertag, I did some tests, and the files retrieved from the Qarantine folder, comes encrypted with a .qtn extension.
The option that comes to my mind, is:
- Restore the file to the original location.
- Retrieve it using the Action Center as you usually do.
The max size of the files is 500MB.
Please, le me know if it works for you, and mark the answer as the solution.
Thanks!
09-11-2023 12:03 PM
Thank you so much for your attention to this question.
In my mind I was able to get the file from quarantine. But I think in this case it is too big or the isolated endpoint didn't allow it. Maybe the client also wasn't online anymore.
So, if I retreive files from quarantaine, the client needs to be online, right?
I will try your suggestion, thank you!
BR
Rob
09-11-2023 12:08 PM
Yes, if you need the files at the moment, it needs to be online. If it is not, the task is hold as "Pending" until the client connects again with the console.
I tried to retrieve files with the route %PROGRAMDATA%\Cyvera\QuarantineV2\*.* and all came encrypted.
Thanks!
JM
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!