Working with Kaspersky Anti-Virus
5.3.3. Moving objects to a separate
directory (quarantine)
You can set up Kaspersky Anti-Virus
the server's file system to a special directory.
Such an approach can be used, for example, if during the antiviral scanning of a
directory an infected file is found that contains important data. Part of the data
can get lost during disinfection. A suitable approach in this situation may be to
isolate the infected object in a special directory for subsequent sending to
Kaspersky Labs for analysis. The experts will probably be able to disinfect the file
and retain its data integrity.
If you intend to keep the Quarantine directory within the server's file system, we
advise that you exclude it from the scanning area for subsequent checking by
specifying its full path in the ExcludeDir parameter of the configuration file.
The object: scan for viruses all the objects listed in the file
/tmp/download.lst, move any infected objects that are detected with
their full paths to the directory /tmp/infected. Use heuristic checker.
Disable recursive scanning. Output information about infected,
suspicious, and corrupted objects to the report file.
The solution: in order to accomplish the above objective do the
following:
1.
Set the program to move the objects to quarantine. To do so enter
the line provided below in the On infected parameter input field in
the sections Object action and Container action on the
Kasperksy Anti-Virus Scanner tab of the Webmin program (see
Figure 18):
2.
Enable the heuristic checker, but disable recursive scanning and
object disinfection. For this purpose make the following settings in
the Scan settings section:
Cure – Disable cleaning of infected objects.
Use heuristic – Enable heuristic code analyzer.
Recursion – Disable recursive scan of directories.
3.
In the command line type:
#kavscanner –@/tmp/download.lst
or:
movePath /tmp/infected
®
so that it will move all infected objects on
68
Need help?
Do you have a question about the ANTI-VIRUS 5.0 - FOR LINUX FREEBSD-OPENBSD MAIL SERVER and is the answer not in the manual?