Kaspersky Embedded Systems Security 3.x

About Real-Time File Protection task

March 10, 2023

ID 146659

When the Real-Time File Protection task is running, Kaspersky Embedded Systems Security scans the following protected device objects when they are accessed:

  • Files.
  • NTFS alternate data streams.
  • Master boot records and boot sectors on local hard drives and external devices.

When any application writes a file to the protected device or reads a file from it, Kaspersky Embedded Systems Security intercepts the file, scans it for threats, and, if a threat is detected, performs a default action or an action you have specified: try to disinfect, move to Quarantine, or delete it. Before disinfection or deletion, Kaspersky Embedded Systems Security saves an encrypted copy of the source file to the Backup folder.

Kaspersky Embedded Systems Security also detects malware for processes running under Windows Subsystem for Linux®. For such processes, the Real-Time File Protection task applies the action defined by the current configuration.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.