Changing the action on detected objects

As a result of scanning, File Anti-Virus assigns one of the following statuses to found objects:

  • status of one of the malware (for example, virus, Trojan horse).
  • possibly infected, when as a result of the scan it is impossible to clearly determine whether an object is infected or not. This means that a code sequence of an unknown virus or a modified code of a known virus was detected in the file.

If, as a result of scanning a file for viruses, Kaspersky Anti-Virus finds infected or possibly infected objects, further operations of File Anti-Virus depend on the status of the object and the selected action.

By default, all infected files are disinfected, and all possibly infected files are quarantined.

All possible actions are shown in the table below.

If your action is

When a dangerous object is detected

Request action

File Anti-Virus displays a warning message containing information about what kind of malicious object the file is/may be infected with, and offers a choice of one of the further actions. Depending on the status of the object, actions may be different.

Block access

File Anti-Virus blocks access to the object. Information about this is recorded in report. Later you can try to cure this object.

Block access

Treat

File Anti-Virus blocks access to the object and tries to disinfect it. If the object was successfully cured, it is made available for work. If it was not possible to disinfect an object, it is either blocked (if it is impossible to disinfect the object), or it is assigned the status possibly infected(if the object is considered suspicious) and it is placed on quarantine. Information about this is recorded in report. Later you can try to cure this object.

Block access

Treat

Delete if treatment is not possible

File Anti-Virus blocks access to the object and tries to disinfect it. If the object was successfully cured, it is made available for work. If the object cannot be disinfected, it is deleted. In this case, a copy of the object is saved in backup storage.

Block access

Treat

Delete

File Anti-Virus blocks access to the object and deletes it.

Before disinfecting or deleting an object, Kaspersky Anti-Virus creates a backup copy of it and places it in backup storage in case you subsequently need to restore the object or it becomes possible to cure it.

To change the set action for detected objects, follow these steps:

  1. Open the main program window.
  2. On the left side of the window, select the Protection section.
  3. IN context menu component File Anti-Virus select Settings.
  4. In the window that opens, select the desired action.

USER GUIDELINES



or restarting the program, as well as the time it takes to complete the virus scan task from the moment it is launched until
completion.

IT IS IMPOSSIBLE TO READ THE OBJECT

In some cases, disinfection of a malicious object is impossible. For example, if the file is so damaged
what to remove from it malicious code and integrity cannot be restored. In addition, the treatment procedure is not
applicable to some types of malicious objects, for example, Trojan programs.

In these cases, a special notification is displayed on the screen, which contains:

Type of threat (for example, virus, Trojan horse) and the name of the malicious object as represented
in the Kaspersky Lab Virus Encyclopedia. The name of the malicious object is formatted as
links to the resource www.viruslist.ru, where you can get detailed information about the threat
kind was detected on your computer.

The full name of the malicious object and its path.

You are asked to choose one of the following actions on the object:

Delete– remove the malicious object. Before deletion it is formed backup copy object on
in case there is a need to restore it or the picture of its infection.

Skip– block access to an object, but do not perform any actions on it, only
record information about it in the report.

Later you can return to processing missed malicious objects from the report window
(the deferred processing feature is not available only for objects found in electronic
messages).

To apply the selected action to all objects with the same status found in current session
operation of a protection component or task, select the checkbox

Apply in all similar cases.

The current work session is considered to be the operating time of the component from the moment it is started until the moment it is turned off.
or restarting the program, as well as the time it takes for the virus scan task to complete from the moment it is launched until
completion.

SPECIAL TREATMENT PROCEDURE REQUIRED

If a threat is detected that this moment active on the system (for example, a malicious process in
random access memory or autorun objects), a request to carry out a special
extended treatment procedure.

Kaspersky Lab specialists strongly recommend agreeing to conduct an extended
treatment procedures. To do this, click on the button OK. However, please note that upon completion there will be
The computer has restarted, so it is recommended to save before performing the procedure.
results of current work and close all programs.

While the treatment procedure is in progress, it is not allowed to run email clients and edit the registry
operating system. After restarting the computer, it is recommended to run full check for viruses.

DANGEROUS OBJECT DETECTED ON TRAFFIC

When Web Anti-Virus detects a dangerous object in traffic, a special message opens on the screen.
notification.

If Kaspersky Virus Removal Tool detected malicious objects, then in the "" notification window, select actions for all objects in the drop-down list on the right and click on the button Continue.

If you want to assign a single action to all objects, refer to the second point.

Note: If there are still objects in the list for which no action has been selected, a window will appear with the error message " Select an action for all detected objects". Click on the button OK and for objects highlighted in red, select an action and then click on the button Continue.

2. Selecting a common action for all objects

At the top of the list of detected objects there are buttons for group selection of actions.

Copy everything to quarantine Copy to quarantine, the original files will remain intact.

Process everything - objects will be assigned an active action:

  • If the object is curable - Treat.
  • If treatment is impossible, but there is a backup copy of the object - Restore.
  • In all other cases, an action will be assigned to the object Delete.

Skip all- all objects from the list will be assigned an action Skip.

Default- window " Select an action for detected objects" is restored to its original condition.

3. Treatment of active infection

When an active infection is detected, a notification appears " Malicious detected software ". At the bottom of the window there is a countdown for making a decision. Treatment of the computer with a reboot will start automatically after the countdown ends, if the user does not select the type of treatment. If to save the data and shut down running programs There are not enough allocated 120 seconds, click on the counter The window will close in... seconds, the counter will be stopped.

Treatment with reboot

For treatment with reboot, click on the button Treat with restarting the computer.

Note: During treatment with a reboot, the ability to create new files, write to disk/registry, and so on will be blocked. It is recommended to first save all changes and close all active programs. After the computer is locked, it is disinfected and rebooted. Then it starts automatically Kaspersky Virus Removal Tool and rescanning is performed.

Treatment without reboot

If rebooting is not possible, click on the link Try to cure without rebooting.

Selecting this option does not guarantee successful treatment.