All advice

Security · 5 min read

Your antivirus quarantined a file. What happens next?

A threat notification is alarming to read. In most cases it is the system telling you it worked.

Laptop on a dark desk beside a glowing blue padlock and shield, representing an antivirus threat quarantined on a device

Every so often a user forwards me a security popup with a subject line along the lines of "am I hacked?". Almost always, the answer is no. The protection did its job. But the wording of these alerts is designed by security vendors, not by people who have to read them at 9am on a Tuesday.

Here is how to read one.

Quarantined means contained

Quarantine is not the same as infected. It means the file was identified as a threat and moved into an isolated area where it cannot run, be opened or spread. Nothing further is required from you. Your files, email and passwords are unaffected.

The three outcomes you might see:

  • Quarantined or blocked. Contained before it ran. This is the normal, good outcome.
  • Removed. Deleted outright. Also fine.
  • Detected, active. The threat ran before it was caught. This one needs investigation, and if you are a monitored client I will already be looking at it.

What the risk levels mean

I classify detections into three bands on your reports:

  • Low. Adware, tracking cookies, browser toolbars. Nuisance rather than danger, usually picked up alongside a free download or an ad-heavy website.
  • Medium. Generic or heuristic detections, potentially unwanted programs, and anything the scanner flagged on behaviour rather than a known signature. Contained, but worth knowing about.
  • High. Trojans, ransomware, backdoors, keyloggers, credential stealers. Contained or not, these get treated as an incident: I check where it came from, whether anything else on the network saw it, and whether any credentials need changing.

A high-risk detection that was quarantined is still good news. It means the layer worked. It just deserves a follow-up conversation about how it arrived.

What you should do

1. Do not try to restore the file. If you genuinely need it, tell me and I will check it properly first. 2. Note what you were doing. An email attachment, a download, a USB stick, a website. That context tells me whether this was a one-off or a pattern. 3. Do not forward the file to anyone, including me, to "have a look". Send me the alert text or a screenshot instead. 4. If it was an email attachment, tell your colleagues. If one person received it, others probably did too. 5. If you entered a password anywhere unusual beforehand, change it, and tell me so I can check sign-in activity.

When it is more serious

Escalate straight away, by phone rather than email, if you see any of these:

  • Files renamed with an unfamiliar extension, or a note demanding payment.
  • Documents opening as gibberish.
  • Your mouse moving on its own, or software you did not install.
  • Colleagues receiving emails from you that you did not send.

Those are not routine detections and speed matters. Disconnect the device from the network, leave it powered on, and call.

What I do at my end

Every detection on a monitored device comes through to me with the threat name, the file, the device and whether it was contained. I classify the risk, check whether anything else was affected, and it appears on your monthly report with a plain-English summary rather than a vendor code.

Worried about a detection you have seen? Get in touch and I will take a look.

Need a hand with this?

I help small organisations across the UK with exactly this kind of work. Honest advice, plain English, no pressure.

Get in touch