Fortinet Document Library

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:

Version:


Table of Contents

Administration Guide

Viewing quarantined threats

  1. On the Malware Protection tab, click X Threats Detected.

    You can view the original file location, virus name, and logs, and submit the suspicious file to FortiGuard. If using FortiClient in standalone mode or FortiClient in managed mode with FortiGate only, you can also view, restore, or delete the quarantined file in this page. If FortiClient is connected to EMS, you cannot restore or delete the quarantined file.

  2. The following information displays:

    Filename

    Lists the names of the quarantined files.

    Date Quarantined

    Lists the dates and time the files were quarantined.

  3. Select a file from the list to view detailed information about the file and click Details.

    Submit

    Click submit for FortiGuard analysis.

    Restore

    Click to remove the selected file from quarantine.

    Delete

    Click to delete the selected file from the device.

    Filename

    Name of the quarantined file.

    Original Location

    Location of the file before scanning.

    Date Quarantined

    Date and time the file was quarantined.

    Submitted

    Displays Not Submitted when the selected file has not been submitted to FortiGuard for analysis by clicking the Submit button. Displays Submitted after clicking the Submit button.

    Status

    Status of the file, such as Quarantined.

    Virus Name

    Name of the detected virus.

    Quarantined File Name

    Name of the file after it was quarantined.

    Log File Location

    Location of the log file for the scan.

    Quarantined By

    FortiClient feature that quarantined the file.

    Close

    Click to close the details dialog.

  4. Click Close.

When EMS manages FortiClient, FortiClient sends quarantined file information to EMS. If the EMS administrator whitelists the file (in the case of a false positive), EMS sends the whitelist information to FortiClient. After FortiClient receives the whitelist information, it releases the file from quarantine. See the FortiClient EMS Administration Guide for details.

Viewing quarantined threats

  1. On the Malware Protection tab, click X Threats Detected.

    You can view the original file location, virus name, and logs, and submit the suspicious file to FortiGuard. If using FortiClient in standalone mode or FortiClient in managed mode with FortiGate only, you can also view, restore, or delete the quarantined file in this page. If FortiClient is connected to EMS, you cannot restore or delete the quarantined file.

  2. The following information displays:

    Filename

    Lists the names of the quarantined files.

    Date Quarantined

    Lists the dates and time the files were quarantined.

  3. Select a file from the list to view detailed information about the file and click Details.

    Submit

    Click submit for FortiGuard analysis.

    Restore

    Click to remove the selected file from quarantine.

    Delete

    Click to delete the selected file from the device.

    Filename

    Name of the quarantined file.

    Original Location

    Location of the file before scanning.

    Date Quarantined

    Date and time the file was quarantined.

    Submitted

    Displays Not Submitted when the selected file has not been submitted to FortiGuard for analysis by clicking the Submit button. Displays Submitted after clicking the Submit button.

    Status

    Status of the file, such as Quarantined.

    Virus Name

    Name of the detected virus.

    Quarantined File Name

    Name of the file after it was quarantined.

    Log File Location

    Location of the log file for the scan.

    Quarantined By

    FortiClient feature that quarantined the file.

    Close

    Click to close the details dialog.

  4. Click Close.

When EMS manages FortiClient, FortiClient sends quarantined file information to EMS. If the EMS administrator whitelists the file (in the case of a false positive), EMS sends the whitelist information to FortiClient. After FortiClient receives the whitelist information, it releases the file from quarantine. See the FortiClient EMS Administration Guide for details.