I am probably missing the obvious but I can’t find a place where I can look items found in the Antivirus scan history.
Normally with AV, I can always find the virus or malware info but googling the names does not show anything.
TrojWare.Win32.Dovs.MO@459817004
C:\VTRoot\HarddiskVolume2\Users\Public\992.exe
</td>
<td>Detected</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/10/01 08:32:09 AM
</td>
</tr>
Malware@#1je5p8xux9d6j
C:\ProgramData\5wmxD9yKu9gRq.exe
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:27 PM
</td>
</tr>
TrojWare.Win32.TrojanDropper.Blakamba.A@351510281
C:\CCE_Quarantine\{EA8BC6C2-C413-40F7-AA61-389C28CB9ACF}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:26 PM
</td>
</tr>
Application.Win32.InstallCore.DVC@351228785
C:\CCE_Quarantine\{F2809BD2-8C13-4C36-8A4B-2BF7594120AD}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:25 PM
</td>
</tr>
ApplicUnwnt@#2u4us7yz87xi8
C:\CCE_Quarantine\{FE227DC8-EA02-46CC-8CD1-D62283D2F924}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:25 PM
</td>
</tr>
Malware@#2w433wbgs04yu
C:\CCE_Quarantine\{E1E76056-7644-45D3-A416-52616A3B0478}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:24 PM
</td>
</tr>
Application.Win32.Optimizero.J@334626133
C:\CCE_Quarantine\{ACA68BAC-9FD5-4BA4-B5C4-BA269ECDA111}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:24 PM
</td>
</tr>
Application.Win32.MultiPlug.VF@345279376
C:\CCE_Quarantine\{EE4B5282-B2EC-4C20-AD67-348F4DA0C215}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:22 PM
</td>
</tr>
Malware@#30pgej685ynnq
C:\CCE_Quarantine\{E67AFA45-5703-477D-80DE-9B220AC05CEC}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:22 PM
</td>
</tr>
TrojWare.Win32.TrojanDropper.Blakamba.A@351510281
C:\CCE_Quarantine\{D50C2C3D-FCDF-4BA9-B070-18AEE720F0AA}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:22 PM
</td>
</tr>
Application.Win32.MultiPlug.VF@345279376
C:\CCE_Quarantine\{E0E103CE-13F2-4516-863B-BE256EFCD3A4}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:21 PM
</td>
</tr>
Malware@#3ib9aw2dmcosf
C:\CCE_Quarantine\{DE61EB1D-320F-483E-826C-C366E2A6B1B4}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:21 PM
</td>
</tr>
ApplicUnwnt@#106yvbvojtdd6
C:\CCE_Quarantine\{BA6CD661-276B-4062-AE0D-909163535F82}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:20 PM
</td>
</tr>
Malware@#pza7mnsl1itt
C:\CCE_Quarantine\{C8D543A4-D2F4-46CE-B25B-2525B446B65C}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:19 PM
</td>
</tr>
ApplicUnwnt@#2u4us7yz87xi8
C:\CCE_Quarantine\{BB880DDA-4DFB-4681-AB96-B2A5001E8EEE}
</td>
<td>Moved to quarantine</td>
<td>Success</td>
<td> {00000000-0000-0000-0000-000000000000}
</td>
<td> 2018/09/12 05:41:18 PM
</td>
</tr>
Jay
October 2, 2018, 8:21am
2
Hello @smartcloud ,
As we understood, you want to find what viruses were detected and quarantined.
In this case you should be able to see quarantined files via ITSM Portal -> Security Sub-Systems -> Antivirus -> quarantined Files.
-> find needed file and copy its hash.
After that go to https://valkyrie.comodo.com/ or https://www.virustotal.com
Paste the copied hash before
And check information about quarantined malware
Please tell us if this suffices your query.
KindRegards,
thats very helpful.
Can I put in a request to have a link from the quarantined files to automatically do the lookup?