Skip to content

Rationale behind clearing Quarantined items? #481

Answered by HotCakeX
ghost asked this question in Q&A
Discussion options

You must be logged in to vote

Microsoft Defender knows what you have is malware via file hash and other characteristics, they are communicated back to the cloud too if necessary, so it doesn't need the actual file to exist. Quarantine means keeping something dangerous/potentially dangerous in a non-executable part of your system. Removing quarantined files after 1 day instead of keeping them forever because they might still pose a danger and somehow find a way to exploit an unknown vulnerability that we don't know about yet, so not taking any chances.

It definitely doesn't prevent reinfection. If that was the case, then we'd have to keep a copy of every malware in the world in our computers so we wouldn't get infected…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant