From eScan Wiki
Contents |
File Anti-Virus
File Anti-Virus module prevents infection of the computer's file system. This module is starts on the startup of the operating system and continuously monitors and scans all the files that opened, saved, or launched along with all the connected devices. The Proactive Behavior Monitoring system blocks any application that behaves maliciously or might be malicious.
eScan offers Block Files feature, which allows to block or quarantine the file from being accessed. It also comprises of Folder Protection function that prevents user from creating, updating, or deleting files/subfolders within the specified folder.
Configure settings for File Anti-virus using the following tabs:
- Objects
- Options
- Block Files
- Folder Protection
- File Rights
- TSPM
- Advanced Settings
Objects
This tab will provide various option for fine tuning the settings available under File Anti-Virus. It provides options such as scanning a specific storage devices or excluding given file from scanning.</span>
Actions in case of virus definition
Displays the different actions that can be performed in case of any infection. The actions are:
- Report only: Reports to you on a popup without taking any action on the file in case of virus detection.
- Disinfect: Automatically disinfect any infected file on detection. Under this action, following two options are available:
- Make backup file before disinfection: This check box allows to make backup file before disinfection.
- If disinfection is impossible: You can configure from the following options:
- Report Only: This option reports if it is not able to disinfect any particular virus.
- Quarantine object: This option quarantines the infected object (isolate the objects) if it is not able to disinfect a virus.
- Delete object: This option deletes the object if it is not able to disinfection a virus.
By default the Disinfect option is selected.
- Quarantine object: Quarantines the file whenever an infection is detected (isolate the file). You can restore the Quarantine/Backup file by using the below procedure:
- Click View Quarantine Objects option present on the main interface of File Anti-virus. You will be forwarded to the Quarantine window, click object name that you wish to restore. Now click Restore button to restore. File will be restored instantly.
- Delete object: Automatically delete the file whenever an infected file is detected.
The following are the options that allows to scan specific disk or drive:
- Scan local removable disk drives: This check box allows to monitor the real-time scanning of all the local removable drives attached to the computer. This option is enabled by default.
- Scan local hard disk drives: This check box allows to monitor the real-time scanning of all the local hard drives installed on the computer. This option is enabled by default.
- Scan network drives: This check box allows to monitor the real-time scanning of all the network drives including mapped folders and drives that are connected to the computer. This option is enabled by default.
Scan files of following types
This check box allows to choose the type of file to monitor while real-time scanning. It have 3 options to select files for scanning, whether All infectable, All, or By mask. The files listed in By mask option are the default file extensions that are defined by eScan. To add or delete files by mask, select and double-click Add/Delete option, and then add or delete files as required.
Exclude by mask
This check box allows to monitors all the excluded object in the Exclude by mask list during real-time monitoring or scanning. You can add or delete a file or a particular file extension by double-clicking the Add/Delete option. This option is enabled by default.
Not a Virus List
File Anti-Virus is able to detect the riskware. Riskware are legitimate program that are not strictly malicious, but pose some sort of risk for the user in another way. You can add the names of riskware, such as remote admin software to the riskware list in the Not a Virus List dialog box by double-clicking the Add / Delete option, if you are certain that they are not malicious. This option is enabled by default and the riskware list is empty by default.
Exclude Files/Folders
This option excludes the listed files, folders, and subfolders, while monitoring or scanning the folders. You can add or delete folders from the existing list of folders by double-clicking the Add / Delete option. This option is enabled by default.
Scan compound objects
This option allows to scan the archives and packed files during the scan. The Archive check box allows to scan archive files. The depth level of an archived file up to which you want to scan can be defined in Archive Depth Level field. By default, value is 16, but you can change it by double-clicking the arrow icon, and then type value in the size box. By default, Packed is selected. This option is enabled by default.
Enable code analyser
This option uses heuristic analyzer during the real-time scan of the computer for suspicious objects or unknown infections. It not only scans and detects infected objects by using the definitions or updates, but it also checks for suspicious files stored on the computer.
Options
This tab will allow to configure the basic settings such as the maximum size of log files and path of the destination folder for storing log files, quarantined objects, and report files.
It provides the following options for configuration:
Save report file
This option allows to save the generated reports. The generates report consist of logs information about the scanned files and the action taken when an infected file is detected. This option is enabled by default and it also allows to configure following settings:
- Show pack info in the report (Monvir.log): This option is enabled by default and it allows to add details about the scanned compressed files, such as .ZIP and .RAR files to the Monvir.log file.
- Show clean object info in the report (Monvir.log): This option allows to add details about uninfected files found during a scan operation to the Monvir.log file. This option helps to find out which files are not infected.
- Limit size to (KB) (avpM.rpt): This option helps to set the size limit of the avpM.rpt file. To specify the size of the log file, double-click the size box and define the size. The default value is 50 KB.
For quarantining of infected objects
This option helps to specify the destination for storing quarantined objects. By default, the quarantined objects are stored in the C:\Program Files\eScan\INFECTED [32-bit] OR C:\Program Files (x86)\ eScan\ INFECTED [64-bit] folder. You can change the location of the destination folder if required.
Enable Auto backup / Restore
This option allows to takes automatic backup of critical files of the Windows® operating system installed on the computer and to restore the clean files when it finds an infection in any of the system files, which cannot be disinfected. This option allows to configure the following settings:
- For backup of clean objects: eScan allows to backs up uninfected objects and store them in a given folder. By default, these objects are stored in a folder named Fbackup on the drive that has maximum free space. You can change the path of the destination folder if desired.
- Do not backup files above size (KB): This option is enabled by default and helps to prevent File Anti-Virus from creating backup of files that is larger than the defined file size. The default value is set to 32768 KB.
- Minimum disk space (MB): This option is enabled by default and enables to set the minimum free hard disk space up to which you want eScan to take backup of files. By default, value is 1 MB, but you can change it by double-clicking the arrow icon, and then type value in the size box.
Use sound effects for the following events
This check box option allows to configure eScan to play a sound file and show the details regarding the infection within a message box when any malicious software is detected. However, you need to ensure that the computer speakers are switched on.
Display attention messages
This option allow to displays an alert, which consist the path, name of the infected object, and the action taken. This option is enabled by default.
Enable Malware URL Filter
This option is blocks the access to malicious websites/URL.
Proactive Behavior Monitor
This option allows to monitor the executable files that are running on your system. In case, if eScan finds any executable files suspicious that may cause any harm to your system, it alerts the user with a pop-up message. To access the suspicious file, you can White list them anytime.
It also allows to view the list of files that are blocked from executing on the system. You can add a File to White list or Block List using this option.
Enable Ransomware Protection
This check box enables the protection against ransomware and enabled by default.
Block Files
The Block Files tab lets you configure settings for preventing executables and files, such as autorun.inf, on network drives, USB drives, and fixed drives from accessing your computer.
You can configure the following settings:
Disable AutoPlay on USB and Fixed Drives [Default]
Selecting this option will disable AutoPlay when a USB/Fixed Drive is connected.
Deny access of executables on USB Drives
Select this check box if you want eScan to prevent executables stored on USB drives from being accessed.
Deny access of executable from Network
Select this check box if you want eScan to prevent executables on the client computer from being accessed from the network.
User defined whitelist
This option is enabled after selecting the Deny access of executable from Network check
box. You can use this option to enter the folders that need to be whitelisted so that executables can be accessed in the network from the folders mentioned under this list. To add files, click Add.
Enter the complete path of the folder to be whitelisted on the client systems. You can either whitelist the parent folder only or select the Include subfolder option to whitelist the subfolders as well.
Deny Access of following files [Default]
Select this check box if you want eScan to prevent the files in the list from running on the computers.
Quarantine Access-denied files
Select this check box if you want eScan to quarantine files to which access is denied.
- You can prevent specific files from running on the eScan client computer by adding them to the Block Files list. By default, this list contains the value %sysdir%\\*.EXE@. Click Add.
- Enter the full name of the file to be blocked from execution on the client systems.

