Configuring virtual machine scan settings in a scan task
You can configure the virtual machine scan settings while creating the task (the Configure scan settings step) or in the task properties after its creation (the Scan settings section).
To configure the virtual machine scan settings:
Select the security level at which Kaspersky Security scans virtual machines. To do so, in the Security level section, perform one of the following actions:
If you want to install one of the pre-installed security levels (High, Recommended, or Low), use the slider to select one.
To change the security level to Recommended, click the Default button.
If you want to configure the security level on your own, click the Settings button. In the Security level settings window that opens:
In the Scanning archives and compound files section, specify the values of the following settings:
Enable / disable the feature of deleting archives that could not be disinfected.
If this check box is selected, Kaspersky Security deletes archives that could not be disinfected.
If this check box is cleared, the application does not delete archives that could not be disinfected. Kaspersky Security relays information that the infected file has not been deleted to the Administration Server of Kaspersky Security Center.
This check box is available when the Scan archives check box is selected.
If this check box is set, Kaspersky Security does not scan compound files whose size exceeds the value that is specified in the Maximum size of a scanned compound file is N MB field.
If this check box is cleared, Kaspersky Security scans compound files of all sizes.
Kaspersky Security scans large files that are extracted from archives, regardless of whether the Do not unpack large compound files check box is selected.
Maximum size of compound files that are subject to scanning (in megabytes). Kaspersky Security does not unpack and scan objects whose size is larger than the specified value.
This setting can be edited if the Do not unpack large compound files check box is selected.
You can specify a value in the range of 1 to 999999 in this field. The default value is 8 MB.
In the Performance section, specify the values of the following settings:
If this check box is selected, Kaspersky Security stops scanning a file when the scan duration reaches the value that is specified in the Scan files for no longer than N second(s) field and skips this file.
If this check box is cleared, Kaspersky Security does not limit the duration of file scanning.
By default, this check box is selected for protection profiles and cleared for scan tasks.
Enables/disables protection against malicious tools.
Malicious tools do not perform their actions right after they are started. Instead, they can be stealthily stored and run on the virtual machine. Intruders often use the features of malicious tools to create viruses, worms, and Trojans, perpetrate network attacks on remote servers, or perform other malicious actions.
If this check box is set, protection against malicious tools is enabled.
If this check box is cleared, protection against malicious tools is disabled.
The function of adware is to display advertising information to the user. For example, it displays banner ads in the interfaces of other programs and redirects search queries to advertising websites. Some varieties of adware collect marketing information about the user and send it to the developer: this information may include the names of the websites that are visited by the user or the content of the user's search queries. Unlike Trojan-Spy–type programs, adware sends this information to the developer with the user's permission.
If this check box is set, protection against adware is enabled.
If this check box is cleared, protection against adware is disabled.
Enables / disables protection against legitimate software that could be exploited by criminals to harm a virtual machine or user data.
Most of these programs are useful, so many users run them. These programs include IRC clients, file downloaders, remote administration programs, user activity monitoring programs, password utilities, and Internet servers for FTP, HTTP, and Telnet. However, if criminals gain access to these programs, some program features could be used to harm a virtual machine or user data.
Selecting this check box enables protection against legitimate software that could be used by criminals to harm a virtual machine or user data.
If this check box is cleared, protection against such software is disabled.
Enables/disables scanning of files that have been packed using one or several packers three or more times.
If a file was packed by one or several packers three or more times, the file probably contains malware or legitimate software that can be used by criminals to damage your computer or personal data.
If this check box is selected, protection against multi-packed files is enabled, and the scanning of such files is allowed.
If this check box is cleared, protection against multi-packed files is disabled.
This check box is set by default.
Kaspersky Security always scans virtual machine files for viruses, worms, and Trojans. That is why the Viruses and worms and Trojans settings in the Malware section cannot be changed.
In the Objects to detect window, click OK.
In the Security level settings window, click OK.
If you have changed security level settings, the application creates a custom security level. The name of the security level in the Security level section changes to Custom.
In the Scan powered-on virtual machines section, configure the settings for scanning virtual machines that are powered on while a task is running:
This drop-down list contains the actions that can be taken by Kaspersky Security when it detects infected files on powered-on virtual machines:
Disinfect. Block if disinfection fails. Kaspersky Security automatically attempts to disinfect infected files. If disinfection fails, Kaspersky Security blocks such files.
Disinfect. Delete if disinfection fails. Kaspersky Security automatically attempts to disinfect infected files. If disinfection fails, the application deletes such files. If deletion fails, Kaspersky Security blocks the infected files.
This action is selected by default.
Kaspersky Security deletes infected archives that could not be disinfected only if the Delete archives if disinfection fails check box is selected in the security level settings.
Delete. Block if deletion fails. Kaspersky Security automatically deletes infected files without attempting to disinfect them. If deletion fails, Kaspersky Security blocks such files.
Block. Kaspersky Security automatically blocks infected files without attempting to disinfect them.
If the check box is selected, Kaspersky Security scans files on optical drives (CD, DVD, Blu-Ray) while performing the scan task on virtual machines running Windows operating systems.
If the check box is cleared, Kaspersky Security does not scan files on optical drives.
If the check box is selected but the scan task has a defined scan scope that does not include a path to the optical drive, Kaspersky Security does not scan files on the optical drive.
Kaspersky Security does not scan files on optical drives when scanning powered-off virtual machines, virtual machine templates, or virtual machines running Linux operating systems.
This check box is cleared by default.
In the Scan powered-off virtual machines and virtual machine templates section, configure the settings for scanning virtual machines that are powered off or paused while a task is running, as well as for scanning virtual machine templates:
Enables / disables scanning of powered-off virtual machines.
If the check box is selected, when performing a scan task Kaspersky Security scans files on powered-off virtual machines (with an NTFS, FAT32, EXT2, EXT3, EXT4, XFS, or BTRFS file system) that are within the task scope. Files on powered-off virtual machines with other file systems are not scanned.
While a powered off virtual machine is being scanned, it is impossible to turn on or migrate the virtual machine.
If this check box is cleared, Kaspersky Security does not scan files on the powered-off virtual machines.
This drop-down list contains the actions that can be taken by Kaspersky Security when it detects infected files on powered-off virtual machines or virtual machine templates:
Disinfect. Block if disinfection fails. Kaspersky Security automatically attempts to disinfect infected files. If disinfection fails, Kaspersky Security blocks such files.
Disinfect. Delete if disinfection fails. Kaspersky Security automatically attempts to disinfect infected files. If disinfection fails, the application deletes such files. If deletion fails, Kaspersky Security blocks the infected files.
Kaspersky Security deletes infected archives that could not be disinfected only if the Delete archives if disinfection fails check box is selected in the security level settings.
Delete. Block if deletion fails. Kaspersky Security automatically deletes infected files without attempting to disinfect them. If deletion fails, Kaspersky Security blocks such files.
Block. Kaspersky Security automatically blocks infected files without attempting to disinfect them.
This action is selected by default.
You can select an action if the Scan powered-off virtual machines check box is selected.
In the Stop scan section, choose one of the following options: