The detected file object cannot be disinfected. Disinfection of the object is not possible, Special disinfection procedure is required, Dangerous object detected in traffic – KASPERSKY LAB KAV2010- Kaspersky Anti-Virus User Manual

Changing the Action on Detected Objects

As a result of the scan, File Anti-Virus assigns one of the following statuses to the found objects:

  • the status of one of the malicious programs (for example, virus, Trojan).
  • possibly infected when, as a result of the scan, it is unambiguously impossible to determine whether the object is infected or not. This means that a code sequence of an unknown virus or a modified code of a known virus has been found in the file.

If, as a result of scanning a file for viruses, Kaspersky Anti-Virus finds infected or possibly infected objects, further File Anti-Virus operations depend on the status of the object and the selected action.

By default, all infected files are disinfected, and all possibly infected files are quarantined.

All possible actions are listed in the table below.

If you chose as the action

When a dangerous object is detected

Request action

File Anti-Virus displays a warning message on the screen containing information about what kind of malicious object the file is/possibly infected with, and offers a choice of one of the further actions. Depending on the status of the object, actions can be different.

block access

File Anti-Virus blocks access to the object. This information is recorded in report. Later you can try to cure this object.

block access

Treat

File Anti-Virus blocks access to the object and tries to disinfect it. If the object was successfully disinfected, it is provided for work. If the object cannot be disinfected, it is either blocked (if it is impossible to disinfect the object), or it is assigned the status possibly infected(if the object is considered suspicious), and it is placed on quarantine. This information is recorded in report. Later you can try to cure this object.

block access

Treat

Remove if treatment is not possible

File Anti-Virus blocks access to the object and tries to disinfect it. If the object was successfully disinfected, it is provided for work. If the object cannot be disinfected, it is deleted. In this case, a copy of the object is stored in backup storage.

block access

Treat

Delete

File Anti-Virus blocks access to the object and deletes it.

Before disinfecting or deleting an object, Kaspersky Anti-Virus creates its backup copy and places it in backup storage in case you later need to restore the object or it becomes possible to cure it.

To change the set action on detected objects, do the following:

  1. Open the main program window.
  2. In the left part of the window, select the Protection section.
  3. AT context menu component File Anti-Virus select Settings .
  4. In the window that opens, select the desired action.

USER GUIDE



or restarting the application, as well as the duration of the virus scan task from the moment of launch to
completion.

THE OBJECT IS NOT POSSIBLE

In some cases, curing a malicious object is not possible. For example, if the file is damaged so
what to remove from it malicious code and cannot be restored. In addition, the treatment procedure
applicable to certain types of malicious objects, such as Trojans.

In these cases, a special notification is displayed on the screen, which contains:

The type of threat (for example, virus, Trojan) and the name of the malicious object as it is represented
in the Virus Encyclopedia of Kaspersky Lab. The name of the malicious object is formatted as
links to the www.viruslist.ru resource, where you can get detailed information about the threat
kind detected on your computer.

The full name of the malicious object and the path to it.

You are prompted to choose one of the following actions on the object:

Delete– remove the malicious object. Before deletion, it is formed backup copy object on
that case, if there is a need to restore it or a picture of its infection.

Skip– block access to the object, but do not perform any actions on it, only
record information about it in the report.

Later, you can return to processing missed malicious objects from the report window
(the possibility of deferred processing is not available only for objects found in electronic
messages).

To apply the selected action to all objects with the same status found in the current session
operation of a protection component or task, select the checkbox

Apply in all such cases.

The current session is the time the component is running from the moment it is started until the moment it is turned off.
or restarting the application, as well as the run time of the virus scan task from the moment of launch to
completion.

SPECIAL TREATMENT REQUIRED

When a threat is detected, which this moment active on the system (for example, a malicious process in
random access memory or startup objects), the screen displays a request to conduct a special
extended treatment.

Kaspersky Lab experts strongly recommend that you agree to an extended
treatment procedures. To do this, click on the button OK. However, please note that at the end of it there will be
the computer has been restarted, so before performing the procedure, it is recommended to save
the results of the current work and close all programs.

During the course of the treatment procedure, it is not allowed to start mail clients and edit registry
operating system. It is recommended that you run a full virus scan after restarting your computer.

DANGEROUS OBJECT DETECTED IN TRAFFIC

When Web Anti-Virus detects a dangerous object in traffic, a special window opens on the screen.
notification.

If a Kaspersky Virus Removal Tool detected malicious objects, then in the window with the "" notification, select actions for all objects in the drop-down list on the right and click the button Proceed.

If you want to assign a single action to all objects, refer to the second point.

Note: if there are objects in the list for which no action is selected, a window will appear with the error message " Select an action for all detected objects". Click on the button OK and for objects highlighted in red, select an action, and then click on the button Proceed.

2. Selecting a common action for all objects

In the upper part of the list of detected objects there are buttons for group selection of actions.

Copy everything to quarantine Copy to quarantine, the original files will remain intact.

Process all - objects will be assigned an active action:

  • If the object is curable - Treat.
  • If disinfection is not possible, but there is a backup copy of the object - Reestablish.
  • In all other cases, an action will be assigned to the object Delete.

Skip all- all objects from the list will be assigned an action Skip.

Default- window " Select an action for detected objects" is restored to its original state.

3. Treatment of active infection

When an active infection is detected, a notification is displayed " Malware detected software ". In the lower part of the window, there is a countdown time for making a decision. The treatment of the computer with a reboot will be launched automatically after the end of the countdown, if the type of treatment is not selected by the user. If to save data and exit running programs not enough allocated 120 seconds, click on the counter The window will close in... seconds, the counter will stop.

reboot treatment

For treatment with reboot, click on the button Cure with a computer restart.

Note: during disinfection with a reboot, the ability to create new files, write to disk / registry, and so on will be blocked. It is recommended that you first save all changes and close all active programs. After the computer is locked, it is disinfected and rebooted. Then automatically starts Kaspersky Virus Removal Tool and rescan is performed.

Treatment without reboot

If it is not possible to restart, click on the link Try to cure without reboot.

The choice of this item does not guarantee the success of the treatment.