Specifying application actions and setting the protection level

The default protection level for Kaspersky Anti-Virus is Recommended. This level denies access to all infected objects, malware (worms, Trojan programs) and suspicious objects that are being accessed for reading, writing or execution, and displays a message prompting the user for action.

Note that archives, email databases, and plain text mail files ARE NOT SCANNED in real-time protection mode! An exception is self-extracting archives, which are scanned if the Maximum Protection level is selected.
While real-time protection is on, you can select both the level of computer protection and the type of action to be performed if a suspicious or infected object is detected.

To configure application actions upon detection of a malicious object:
  1. Click Configure Real-Time Protection in the left section of the Settings tab or modify settings in the status area of the Protection tab.
  2. When the Real-Time Protection settings dialog box opens, select the protection level using a slider. By changing the protection level, you change the balance between the speed of the scan and the number of objects to be scanned. The fewer objects scanned, the faster the scan will be.

Note that archives are not scanned or disinfected in real-time protection mode! To scan and disinfect archives use a full computer scan.
Real-time protection configuration

Kaspersky Anti-Virus allows the user to select one of three protection levels:

The table below contains a list of all objects that may be subject to an anti-virus scan. The + sign indicates that the object will be scanned if the corresponding level is selected, while the - sign indicates that the object will not be scanned.

 

Maximum Protection

Recommended
High Speed
Files that potentially can be infected
+
+
+
Disk boot sectors
+
+
+
Packed files
+
+
+
OLE objects
+
+
+
Incoming email messages
+
+
+
Outgoing email messages
+
-
-
Self-extracting archives
+
-
-
Email databases and messages
-
-
-

You can specify files to be excluded from the scan scope at each level of real-time protection, or disable real-time protection.

  1. Specify types of action to be performed on detection of an infected or suspicious object:
    • Block access and prompt user for action - deny access to the object and display a message prompting the user to choose which action is to be performed on the object. This is the default mode.

If you do not specify the action within 30 seconds after the message is displayed, the recommended action will be performed on this object. Each type of detected object has its own recommended action. For example, for infected objects the recommended action is Disinfect. Beside the name of recommended action the text (recommended) is always displayed.

The list of possible recommended actions is as follows (a subset of these actions is available for each different type of object):

In some situations no action can be performed on an object, for instance, if an infected object is being used by another program at the time of detection and therefore cannot be processed. In this case, a message will be displayed with a suggestion that you:


Kaspersky Lab

WWW: http://www.kaspersky.com

E-mail: support@kaspersky.com