Kaspersky Endpoint Security 11 for Windows

Forming the protection scope of the File Threat Protection component

April 25, 2024

ID 123504

The protection scope refers to the objects that the component scans when enabled. The protection scopes of different components have different properties. The location and type of files to be scanned are properties of the protection scope of the File Threat Protection component. By default, the File Threat Protection component scans only potentially infectable files that are run from hard drives, removable drives and network drives.

When selecting the type of files to scan, consider the following:

  1. There is a low probability of introducing malicious code into files of certain formats and its subsequent activation (for example, TXT format). At the same time, there are file formats that contain executable code (such as .exe, .dll). The executable code may also be contained in files of formats that are not intended for this purpose (for example, the DOC format). The risk of intrusion and activation of malicious code in such files is high.
  2. An intruder may send a virus or another malicious application to your computer in an executable file that has been renamed with the .txt extension. If you select scanning of files by extension, the application skips this file during scanning. If scanning of files by format is selected, Kaspersky Endpoint Security analyzes the file header regardless of its extension. If this analysis reveals that the file has the format of an executable file (for example, EXE), the application scans it.

To create the protection scope:

  1. In the main application window, click the icon_settings button.
  2. In the application settings window, select Essential Threat ProtectionFile Threat Protection.
  3. Click Advanced Settings.
  4. In the File types block, specify the type of files that you want the File Threat Protection component to scan:
    • All files. If this setting is enabled, Kaspersky Endpoint Security checks all files without exception (all formats and extensions).
    • Files scanned by format. If this setting is enabled, the application scans infectable files only. Before scanning a file for malicious code, the internal header of the file is analyzed to determine the format of the file (for example, .txt, .doc, or .exe). The scan also looks for files with particular file extensions.
    • Files scanned by extension. If this setting is enabled, the application scans infectable files only. The file format is then determined based on the file's extension.
  5. Click the Edit protection scope link.
  6. In the window that opens, select the objects that you want to add to the protection scope or exclude from it.

    You cannot remove or edit objects that are included in the default protection scope.

  7. If you want to add a new object to the protection scope:
    1. Click Add.

      The folder tree opens.

    2. Select an object to add to the protection scope.

    You can exclude an object from scans without deleting it from the list of objects in the scan scope. To do so, clear the check box next to the object.

  8. Save your changes.

     

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.