File Threat Protection component prevents infection of the device file system. The component is enabled automatically with the default settings when the Kaspersky application starts. It resides in the device operating memory and scans all files that are opened, saved, and executed in real time.
Upon detecting malware, the Kaspersky application can remove the infected file and terminate the malware process started from this file.
The operation of the component is affected by the file operation interception mode, which you can select in the general settings of the application. By default, access to the file is blocked for the duration of the scan.
On the command line, you can manage File Threat Protection using the File Threat Protection predefined task (File_Threat_Protection).
The File Threat Protection task is started by default. You can start and stop this task, as well as modify its settings manually.
To start and stop the File Threat Protection task on the command line, you need the privileges of the Administrator role.
By modifying the settings of the File Threat Protection predefined task, you can:
On the command line, you can view information about detected threats and check the current status of the task.
To optimize the File Threat Protection component, you can exclude from scans any files being copied from network directories. Files are scanned only after the process of copying to a local directory is finished. To exclude files located in network directories from scans, configure exclusion based on processes for the utility used for copying from network directories (for example, for the cp
utility). You can configure an exclusion by process by adding an [ExcludedForProgram.item_#]
section to the settings of the OAS task.
In the application interface, you can manage File Threat Protection using the File Threat Protection component.
The application interface allows you to:
The statistics of the File Threat Protection component are displayed in the report in the Statistics section.