Video Screencast Help

Folder.exe gets created and quarantined by Symantec time and again

Created: 04 Nov 2012 | 3 comments


One of the machines in our office always gets a pop up that folder.exe has been found and then quarintined. The symantec aantivirus is updated on that machine and it is showing secuirty status is good. Can you help me with this. The symantec version is 12.1.671....



Comments 3 CommentsJump to latest comment

Ashish-Sharma's picture


Update your system latest Defination.

If not, there are useful some tools that are provided by Symantec for help with finding those hard to detect threats.

1.       The Power Eraser Tool eliminates deeply embedded and difficult to remove threats that traditional virus scanning doesn't always detect.

2. The SERT (Symantec Endpoint Recovery Tool)is useful in situations where computers are too heavily infected for the Symantec Endpoint Protection client installed upon them to clean effectively.

3. The Load point Analysis Tool generates a detailed report of the programs loaded on your system. It is helpful in listing common loadpoints where threats can live.

Rapid Release Virus Definitions –

Power Eraser tool –

How To Use the Symantec Endpoint Recovery Tool with the Latest Virus Definitions

Support Tool with Power Eraser Tool included –

How to use the Load Point Analysis within the Symantec Support Tool to help locate suspicious files

If you are unable to remove the threat(s) from your systems, please submit the suspected files to Symantec or ThreatExpert for analysis. New signatures will be created and included in future definition sets for detection.

Check this thread

Check this thread Also

Thanks In Advance

Ashish Sharma

Mithun Sanghavi's picture


Are running the SEP 12.1 client with latest definitions and carry all the latest Microsoft updates and security patches on the machine?

The symptoms sounds like W32.SillyFDC to me.

Plan of Action:

1) Make sure you have Latest Microsoft updates and security patches on the machine.

2) Run a scan in safe mode with networking to remove the virus.

3) Disable System Restore before you do this as the virus alse creates entries in the System Restore Points store volumes.

4) Disable Autoplay for ALL DRIVES Via a GPO (If you're on a domain), and

5) Disable Simple File Sharing if it's enabled to prevent the infection from propogating itself by binding to files.

Secondly, Submit these files to the Symantec Security Response and they will get detected.

Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

Hope that helps!!

Mithun Sanghavi
Associate Security Architect


Don't forget to mark your thread as 'SOLVED' with the answer that best helped you.

Chetan Savade's picture


Check these articles as well:

How to Manage Quarantined files.

How to delete Quarantined items from the Symantec Endpoint Protection Manager.

Chetan Savade
Sr.Technical Support Engineer, Endpoint Security
Enterprise Technical Support

Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<