Question/Issue:
You recently updated your virus definitions. When a manual or scheduled scan is run, various files are flagged as infected and sent to the Quarantine Bin. These may be system files, various program files or different file types from any source.
Solution:
When you see a lot of files being quarantined, a likely problem is that the virus definitions you are using (or the definition set you recently applied), was damaged or corrupted during the transfer. This does not occur often. However, a particular definition set will occasionally cause false detections.
If you are using Symantec AntiVirus Corporate Edition 8.x, you should update your virus definitions by completely replacing your old virus definitions manually. This is most easily done with a new XDB file. Go to the Symantec Web site. Download and roll out the latest XDB file. For help obtaining and using the latest XDB file read the section titled "Copying an .xdb file" in the document How to update virus definitions for Symantec AntiVirus Corporate Edition.
If you are using Norton AntiVirus Corporate Edition 7.x, update the definitions using the Intelligent Updater. For information on how to use the Intelligent Updater, read the document How to update virus definitions for Norton AntiVirus Corporate Edition.
Unquarantine the files that were flagged as being infected by a virus that you suspect to be false positives (incorrectly detected as being virus infected), Rescan the files once you have replaced your old virus definitions. If the files are no longer labeled infected, then your prior virus definitions were giving a false positive, and your files are not infected. It is safe to leave these files unquarantined. However, if the files are still found to be infected, send the files to Symantec Security Response using the procedure below.
To submit a virus sample to Symantec Security Response
Document ID: 2001101213393148
Last Modified: 03/17/2004
Date Created: 10/12/2001
Operating System(s): Windows 2000
Product(s): Norton AntiVirus Corporate Edition 7.0, Symantec AntiVirus Corporate Edition 8.0
Release(s): NAVCE 7.5x [All Releases], NAVCE 7.6 [All Releases], SAV 8.0 [All Releases], SAV 8.1.1