File Threat Protection

When you open or launch a file whose contents are stored in the OneDrive cloud, Kaspersky Endpoint Security downloads and scans the file contents.

The File Threat Protection component lets you prevent infection of the file system of the computer. By default, the File Threat Protection component starts together with Kaspersky Endpoint Security, continuously resides in the computer's RAM, and scans files that are opened or run on the computer and on its attached drives to find viruses and other threats. The scan is performed according to the application settings.

On detecting a threat in a file, Kaspersky Endpoint Security performs the following:

  1. Detects the type of object detected in the file (such as a virus or Trojan).
  2. The application displays a notification about the malicious object detected in the file (if notifications are configured), and processes the file by taking the action specified in the File Threat Protection component settings.

    File Threat Protection component settings

    Parameter

    Description

    Protection scope

    Contains objects that are scanned by the File Threat Protection component. A scan object may be a hard drive or network drive, folder, file, or file name mask.

    By default, the File Threat Protection component scans files that are started on any hard drives, removable drives, or network drives. Objects that are in the Protection scope list by default cannot be edited or removed.

    If the check box next to the name of a scan object is selected, the File Threat Protection component scans it.

    Action on threat detection

    • Disinfect; delete if disinfection fails. If this option is selected, Kaspersky Endpoint Security automatically attempts to disinfect all infected files that are detected. If disinfection fails, Kaspersky Endpoint Security deletes the files.
    • Disinfect; block if disinfection fails. If this option is selected, the File Threat Protection component automatically attempts to disinfect all infected files that are detected. If disinfection fails, the File Threat Protection component blocks these files.
    • Block. If this option is selected, the File Threat Protection component automatically blocks all infected files without attempting to disinfect them.

    Before attempting to disinfect or delete an infected file, the File Threat Protection component creates a backup copy in case it becomes necessary to restore the file or it becomes possible to disinfect the file at a later time.

    Scan only new and changed files

    This check box enables / disables the mode of scanning only new files and files that have been modified since the previous scan. The File Threat Protection component scans both simple and compound files.

    Scan archives

    This check box enables / disables scanning of RAR, ARJ, ZIP, CAB, LHA, JAR, and ICE archives.

    Scan distribution packages

    The check box enables or disables scanning of distribution packages.

    Scan Office formats

    This check box enables or disables the function that the File Threat Protection component uses during a virus scan to scan DOC, DOCX, XLS, PPT and other Office format files. Office format files include OLE objects as well.

    Do not unpack large compound files

    If this check box is selected, Kaspersky Endpoint Security does not scan compound files whose size exceeds the value that is specified in the Maximum file size field.

    If this check box is cleared, Kaspersky Endpoint Security scans compound files of all sizes.

    Kaspersky Endpoint Security scans large files that are extracted from archives, regardless of whether the Do not unpack large compound files check box is selected.

    Unpack compound files in the background

    If the check box is selected, Kaspersky Endpoint Security unpacks compound files whose size exceeds the value that is specified in the Minimum file size field in the background and with a delay after their detection. Such files can be available for use while they are being scanned. Compound files with a size that is less than the value that is specified in the Minimum file size field are available for use only after they are unpacked and scanned.

    If the check box is cleared, Kaspersky Endpoint Security unpacks all compound files. Compound files are available for use only after they are unpacked and their contents are scanned.

See also: Managing the application via the local interface

Enabling and disabling File Threat Protection

Automatic pausing of File Threat Protection

File Threat Protection settings

Page top