Kaspersky Endpoint Security for Windows 11.2.0

Working with active threats

Kaspersky Endpoint Security logs information about files that it has not processed for some reason. This information is recorded in the form of events in the list of active threats.

An infected file is considered processed if Kaspersky Endpoint Security performs one of the following actions on this file according to the specified application settings while scanning the computer for viruses and other threats:

  • Disinfect.
  • Remove.
  • Delete if disinfection fails.

Kaspersky Endpoint Security moves the file to the list of active threats if, for any reason, Kaspersky Endpoint Security failed to perform an action on this file according to the specified application settings while scanning the computer for viruses and other threats.

This situation is possible in the following cases:

  • The scanned file is unavailable (for example, it is located on a network drive or on a removable drive without write privileges).
  • The action that is selected in the Action on threat detection section for scan tasks is Inform, and the user selects the Skip action when a notification about the infected file is displayed.

You can do one of the following:

In this section:

Working with the list of active threats

Start custom scan task for files from the list of active threats

Deleting records from the list of active threats