Short answer: Prefer Remove; use Quarantine if unsure.
How to decide
Remove when the item is clearly malicious or unwanted (adware, trojan, SMS fraud, etc.).
Quarantine if you are not sure what the file is, or it belongs to an app you still use.
After you choose
Remove: The item is deleted. If it returns, update definitions and run Deep scan.
Quarantine: The item is isolated and can’t run. Review later via Quarantine.
Special cases
Preinstalled or device-admin apps: Android may block removal. Go to App info → Disable or Remove admin first.
System locations: Some files are read-only; the app will recommend quarantine or manual steps.
Good practice
Keep Quarantine cleanup at 2–4 weeks.
Avoid Ignore unless you know the exact file and trust its source.
Before restoring or deleting a file
Check the full file path, detection name, digital signature, and where the file came from. If it belongs to work software or contains irreplaceable data, quarantine it first and keep a copy of the detection details. Do not restore a file merely because an application stops working after cleanup.
If you think the detection is wrong
Update the threat database and scan the file again. Then follow the false-positive submission guide. Restore only after you trust the source or receive confirmation. Add an ignore rule only for the exact verified file; a broad folder exclusion can hide a later infection. If the same item returns after removal, check the updater, scheduled tasks, and startup entries that may be recreating it.