|
Applies to Kaspersky PURE 2.0
Contents:
Your PC’s file system may contain viruses and other Malware. Malware may be stored in your file system for years, having intruded your computer from a removable drive or from the Internet and does not show itself. But as soon as you open an infected file or try to copy it on a disk, the virus starts to function.
What is File Anti-Virus
File Anti-Virus is a component of the Computer Protection functional module that controls computer file system. It scans OPEN, LAUNCHED and SAVED files on your computer and on all attached discs. Each file the user deals with is intercepted by the Kaspersky Lab product and scanned for viruses. The user can work with the file if the file is not infected or was successfully disinfected by File Anti-Virus. If the file cannot be disinfected by some reasons, it is either deleted or quarantined.
To the contents ↑
File Anti-Virus operation algorithm
By default, File Anti-Virus only scans new or modified files; in other words, files that have been added or modified since the previous scan.
Files are scanned according to the following algorithm:
- The component intercepts every attempt by the user or by any program to access any file.
- File Anti-Virus scans iChecker and iSwift databases for information about the intercepted file, and determines if it should scan the file, based on the information retrieved.
The following operations are performed when scanning:
- The file is scanned for viruses. Malicious objects are recognized based on the antivirus databases. The database contains descriptions of all malicious programs and threats currently known, and methods for processing them.
- After the analysis you have the following available courses of action for Kaspersky Internet Security:
- If malicious code is detected in the file, File Anti-Virus blocks the file, creates a backup copy and attempts to perform disinfection. If the file is successfully disinfected, it becomes available again. If disinfection fails, the file is deleted.
- If potentially malicious code is detected in the file (but the maliciousness is not absolutely guaranteed), the file proceeds to disinfection and then is sent to the special storage area called Quarantine.
- If no malicious code is discovered in the file, it is immediately restored.
If interactive mode is enabled, then if an infected or potentially infected object is detected, a notification with a request for further actions will be displayed on screen only.
You will be offered the following:
- quarantine the object, allowing the new threat to be scanned and processed later using updated databases;
- delete the object;
- skip the object if you are absolutely sure that it is not malicious.
To the contents ↑
How to configure File Anti-Virus
In Kaspersky PURE 2.0 you can configure the File Anti-Virus settings. You can:
To the contents ↑
|