Actions When a Virus Is Detected

Actions When a Virus Is Detected

In case a known virus or a suspicious object is found, by default Dr.Web for workstations informs you about it in the report field located at the bottom of the window. Dr.Web for Windows Servers by default takes automatic action to prevent a virus threat.

There are four actions to prevent a detected virus threat:

Cure – to restore the object to the state before the infection. This action is available for known viruses, but not always. The action is impossible for viruses detected in archives.

Delete – to delete the infected object. The action is impossible, if a virus is detected in the boot sector.

Rename – to change the filename extension specified in the program's settings. The action is impossible, if a virus is detected in the boot sector.

Move – to move the infected file to a special folder (quarantine). The path to this folder is specified in the program's settings. The action is impossible if a virus is detected in the boot sector.

The report list table includes the data on infected or suspicious objects detected during the scanning, and actions made by the program. If these objects are detected in file archives, mail files or file containers, the table lists these infected objects and the archives containing them.

In the Object column the names of infected files or a boot sector are listed.

The Path column contains the path to an infected object.

In the Status column virus names (for files and boot sectors), or information on an infected archive are listed.

In the Action column information on the actions made (curing, deletion, renaming, removing of an object) is given.


If an infected or suspicious file used by another 32-bit Windows application is found, the action specified by you is not applied immediately. A line Will be cured after reboot or Will be deleted after reboot, i.e. depending on the action specified, will appear in the Action column of the Scanner’s report field. The necessary action will be taken after the next reboot. That is why, if such objects are found, it is recommended to reboot the system immediately after the scanning.


To assign the program’s reaction to a detected virus threat in the report list:

1. Right-click the line with the description of the infected object.
2. Select the action you want to enable in the context menu, or click the corresponding button under the report field. If the Cure option is selected, an additional context menu will open. Select a necessary action by the program, if the curing fails.


By default, when Delete is enabled for file archives, containers or mail boxes, the program generates a warning message that the data might be lost.


No actions are allowed for files inside archives. If the Delete action is selected for an archive, the whole archive will be deleted.


To select objects in the report list the following keys and key combinations can be helpful:

Insert - select an object and move the cursor to the next position

Ctrl+A - select all

the * key on the numeric keyboard - invert selection

Different windows, settings and actions can also be accessed by the hot keys.

For more details on the settings and actions specified in this pane click the corresponding area of the window in the picture.