Scanner for Workstations

Dr.Web Scanner runs an express or full scan of the entire file system or scans critical files and directories only.

Dr.Web Scanner settings for computers running GNU/Linux operating systems are available in the Scanner for workstations section. This section allows to adjust the settings of the GUI version of Dr.Web Scanner. Console Scanner settings are managed locally on the station.

General

On the General tab, you can configure general parameters of Dr.Web Scanner operation.

•In the Scanning time of one element field, specify the time limit for scanning a file. Default value: 0 (the time period to scan one file is unlimited).

warning

Scanning the contents of archives and email files and increasing the time limit for scanning a single file may slow down the system and increase the overall scanning time.

Actions

In this section, you can configure actions that will be applied to threats detected by Dr.Web Scanner. The actions are set separately for each type of malicious and suspicious objects. These actions vary for different object types.

Scanner can react to the threats of the following types:

•Malicious—the scanned file contains a known threat;

•Suspicious—the scanned file has been marked as suspicious;

•Adware—the scanned file contains adware;

•Dialers—the scanned file contains a dialer;

•Jokes—the scanned file contains a joke program;

•Riskware—the scanned file contains riskware;

•Hacktools—the scanned file contains a hacktool.

Available actions:

•Cure, move to quarantine if not cured—restore the state of the object before the infection. If the object is incurable or the attempt of curing fails, the object is quarantined.

This action is available only for the objects infected with a known virus that can be cured except for trojans and infected files within compound objects (archives, email files or file containers).

•Cure, delete if not cured—restore the state of the object before the infection. If the object is incurable or the attempt of curing fails, the object is deleted.

This action is available only for the objects infected with a known virus that can be cured except for trojans and infected files within compound objects (archives, email files or file containers).

•Delete—delete the object that poses a threat.

This is the most effective way to remove all types of threats.

•Move to quarantine—move a detected threat to a special directory isolated from the rest of the system.

•Report—notify of a threat without performing other actions.

info

Default settings are optimal in most cases. Do not change them unless necessary.

Choose Automatically apply actions to threats to automatically apply actions indicated above to threats detected during scanning. If this option is disabled, the user will be notified about a detected threat, but no actions to neutralize it will be taken.

You can also disable scanning archives and email files. This option is enabled by default.

Actions applied to threats detected by Dr.Web Scanner

Object

Action

Cure, move to quarantine incurable

Cure, delete incurable

Delete

Move to quarantine

Report

Malicious

+/*

+

+

+

 

Suspicious

 

 

+

+/*

+

Adware

 

 

+

+/*

+

Dialers

 

 

+

+/*

+

Jokes

 

 

+

+

+/*

Riskware

 

 

+

+

+/*

Hacktools

 

 

+

+

+/*

Conventions

Excluded paths

In this area, specify paths to files and directories that will be excluded from scanning by Dr.Web Scanner.