Creating a file quarantine task

If you believe that an infected or probably infected file is on the computer with the Kaspersky Endpoint Agent program, you can isolate it by putting it into quarantine. The file is deleted from its folder on the computer and placed in Kaspersky Endpoint Agent quarantine on the same computer, in the quarantine directory that is configured in Kaspersky Endpoint Agent settings.

To create a file quarantine task:

  1. Select the Tasks section in the program web interface window.

    This opens the task table.

  2. Click Add and select Quarantine file.

    This opens the task creation window.

  3. Configure the following settings:
    1. In the File path field, enter the path to the file that you want to put in quarantine.
    2. In the MD5/SHA256 field, enter the MD5 or SHA256 hash of the file that you want to place in quarantine. This field is optional.
    3. In the Description field, enter the task description. This field is optional.
    4. In the Hosts field, type characters to search for the name of the host where the file you want to quarantine is located, and select the host name from the list. Repeat the steps for each host you want to add.

      Selected hosts are added to the list.

    5. Click Add.

    The file quarantine task is created. The task runs automatically after it is created.

    As a result of the task:

    • The file is deleted from its folder on the computer with the Kaspersky Endpoint Agent program and placed in Kaspersky Endpoint Agent quarantine on the same workstation, in the quarantine directory that is configured in Kaspersky Endpoint Agent settings.
    • In the task list of the Tasks section of the program web interface, execution information about the task is displayed.
    • In the file list in the Storage section, Quarantine subsection, information about the quarantined file is displayed.

If the file has been blocked by another process, the task is displayed with the Completed status but the file is placed in Quarantine only after the host is restarted. It is recommended to check whether the task was successfully completed after the host is restarted.

The file quarantine task can finish with the Access denied error if you are trying to quarantine an executable file and it is currently running.

To solve this problem, create a process termination task for this file, and then try creating the file quarantine task again.

Users with the Security auditor role cannot create file quarantine tasks.

Users with the Security officer role do not have access to tasks.

See also

Managing tasks

Viewing the task table

Viewing information about a task

Creating a process termination task

Creating a data collection task

Creating a task to scan hosts using YARA rules

Creating a service management task

Creating a program execution task

Creating a file download task

Creating a file deletion task

Creating a quarantined file recovery task

Creating a copy of a task

Deleting tasks

Filtering tasks by creation time

Filtering tasks by type

Filtering tasks by name

Filtering tasks by file name and path

Filtering tasks by description

Filtering tasks by server name

Filtering tasks based on the name of the user that created the task

Filtering tasks by processing status

Clearing a task filter

Page top