I want to send my files for checking by email to McAfee Labs.
Now they are (files) available in quarantine of my Antivirus.
I cannot find them in the specified addresses - they are blocked!
I want to know a folder of accommodation of all infected files. I should send them in archive, but where this folder?
I want to know where the antivirus places the infected files and as I should take them for sending to McAfee Labs.
Solved! Go to Solution.
Once they are quarantined they are encrypted and cannot be accessed by anything, that way they can't harm anything.
You would have to temporarily disable VirusScan, reinstate them and submit via email as per these instructions: https://community.mcafee.com/thread/2016
You can't open those files and I don't suggest you try.
Thanks for the help in this question!
I have sent files on check and have quickly received the answer.
I correctly understand, that files are not infected also I should have them on my computer?
Please look the report.
McAfee Labs - Beaverton
Current Scan Engine Version:5400.1158
Current DAT Version:6349.0000
Thank you for your submission.
Analysis ID: 6633151
File Name Findings Detection Type Extra
_ex-68.exe |current detection |generic fakealert.ama |Trojan |no
~39247624 |current detection |fakealert!grb |Trojan |no
~39247624r |current detection |fakealert!grb |Trojan |no
~39313160 |current detection |fakealert!grb |Trojan |no
~39313160r |current detection |fakealert!grb |Trojan |no
~39771912 |current detection |fakealert!grb |Trojan |no
~39771912r |current detection |fakealert!grb |Trojan |no
~40886024 |current detection |fakealert!grb |Trojan |no
~40886024r |current detection |fakealert!grb |Trojan |no
5b37310-7d249bc8 |current detection |generic fakealert.ama |Trojan |no
5b37310-7d249bc8.idx|inconclusive | | |no
setd0fa.tmp |current detection |generic.bfr!ba |Trojan |no
swv.exe |current detection |generic fakealert.bh |Trojan |no
update.exe |current detection |generic fakealert.bh |Trojan |no
Automated analysis was not able to determine that this file is malware. This file is
being sent for further processing and the DAT files will potentially be updated if
detection of this sample is warranted.
current detection [_ex-68.exe ~39247624 ~39247624r ~39313160 ~39313160r ~39771912 ~39771912r ~40886024
~40886024r 5b37310-7d249bc8 setd0fa.tmp swv.exe update.exe]
The file submitted is malware that can be detected with curred DAT files. It is
recommended that you update your DAT and engine files and scan your computer again.
It appears that they aren't malware. If you feel that the detection is wrong follow the instructions in that link I posted, otherwise you can delete them from quarantine,
Double-click the taskbar icon to open SecurityCenter
Click Virus and Spyware Protection
Then click Navigation (top right)
Click Quarantined and Trusted Items (below) highlight the item(s) and click Delete or restore.
However, I would have replied to the email adding the word False in front of the header as instsructed in that link if VirusScan still quarantines them.
Message was edited by: Ex_Brit on 17/05/11 3:30:21 EDT PM
If these files are not infected, it is possible to add them in reliable and they will not work?
I have understood that it is necessary to lead new check and if the antivirus will be determined their infected I must answer the letter wiht word False in front of the header.
I have now lead fast check but have not found out these viruses. It probably is necessary to lead full check, but for this purpose some hours are necessary.
Just follow the instructions in that link I posted earlier. Sorry it isn't possible to simply trust them with the current software version.
Tell me pl, I have established DAT:6348, but in the received letter recommend to install DAT: 6349.
I should wait for automatic updating or make it manually from page http://www.mcafee.com/apps/downloads/security-updates/security-updates.aspx ?
Here I see two kinds DAT File and SuperDat - I ask to give the information about the most suitable file for me?