This document will guide you on how to operate and process Trojan files in the CWP console.
File Scan Settings
- Log in to the CWPP tenant-side console. In the left sidebar, select Intrusion Detection > Malicious File Scan.
- In malicious file scan, click Detection Setting in the upper right corner. The detection setting page pops up on the right. Scanning mode can be set.
Note:
- The following two are common Trojan file detections:
- Webshell detection: Provide detection of common Web script Trojan backdoors, including scripting languages such as ASP/PHP/JSP/Python.
- Binary detection: Provides virus and Trojan detection for binary executable files, such as DDoS trojans, remote control software, mining software, etc. File types include exe, dll, bin, etc., and alarm users.
- The following two are common Trojan file detections:
- In Detection Setting, scheduled scan, real-time monitoring and automatic isolation settings are supported.
- Scheduled scan: click to enable Scheduled detection, set the detection mode, cycle and range, and then click Save to regularly scan host Trojan virus files and enhance security.
Field Description:
- Detection mode: includes quick detection mode and full-disk detection mode, which can detect running processes, critical directories, driver loading, etc. Among them, the duration of full-disk detection is related to the number of server disk files. It is recommended to choose more than 4 hours to avoid incomplete scanning or timeout.
- Detection cycle: available every day, every 3 days or every 7 days.
- Detection range: support selecting all Ultimate Edition servers, selected servers.
- Real-time monitoring: click to enable Real-time Monitoring, select the monitoring mode, and then click Save to monitor Web directories and key system directories in real time and detect and kill Trojan virus files.
Field Description:
- Monitoring mode
- Standard: monitor and scan to detect incremental files in common directories.
- Depth: monitor and scan to detect incremental files in all directories.
- Monitoring mode
- Automatic isolation: click to enable Automatic isolation > Save, and detected malicious files will be automatically isolated. Manual confirmation of isolation is still required for some malicious files. It is recommended to check all security events in the file detection list and ensure all processed.
Note:
If a file is misisolated, please restore it in the isolated list. Turning on or off automatic isolation requires configuration, and there is a several minutes delay before taking effect.
Inspection Setup Overview
- Log in to the CWPP tenant console. In the left sidebar, select Intrusion Detection > Malicious File Scan.
- On the file detection page, click one-click detection to start setting manual detection mode.
- In the one-click detection setting pop-up window, after confirming the detection mode, engine mode, and host range, you can also configure the timeout period (detection may result in longer execution time due to too many files or directories).
- After clicking Start Detection, detection will be carried out according to the detection settings. Click View Detail to view detection details.
List field description for detection details- Affect the server: the IP and name of the server.
- Operating system: the operating system of the server.
- Detection status: detection complete, detecting, detection failure (reason: might be detection timeout failure. It is recommended to increase timeout and recheck; might be client offline. It is recommended to restart or reinstall the client and recheck).
- Pending risks: the number of pending risk files detected on the server.
- Detection start time: the start time of this detection.
- Detection end time: the time when server detection is complete.
- Perform operations
- Recheck: If you want to recheck a server whose detection status is detection completed, detection stopped, or detection failure, you can click Recheck.
- Stop the detection: If you want to stop detecting a server whose detection status is in detection, you can click Stop the detection. The server will not be detected. Operate with caution due to possible risks.
- View detail: If you want to view the detection result of the target server, you can click View detail.
View Alarm List
- Log in to the CWPP tenant console. In the left sidebar, select Intrusion Detection > Malicious File Scan.
- On the file detection page, you can view the detection status of Trojan files in the currently protected servers, as shown in the figure below:
List field description for Alarm List
- Host name/instance ID: the server name and instance ID under detection.
- IP address: the server IP address under detection.
- Path: Risk file path.
- Virus name/detection engine: The virus name of the intrusion risk file.
- First detected time: the time when this risk file was first detected.
- Latest detection time: the latest time when this risk file was detected.
- Processing status: the processing status of the risk file. For events in the pending status, a prompt will display the existence of files and processes during the most recent detection of this file.
- Perform operations
- Details: view malicious file details.
- Isolate: isolate this virus file to prevent hackers from starting it again, making it convenient for you to locate the virus file and scan and disinfect it. (Note: on a windows system, if the file is running, isolation will fail.) Support isolating and terminating related processes of this file. Recommend checking.
- Mark as processed: It is recommended that you handle the issue by referring to the "Repair advice" in the alarm details. After processing, you can mark the alarm as processed.
- Add to allowlist: If you confirm that the process execution is normal behavior, you can add the process to the whitelist exemption rules. Subsequently, when this process runs again, it will be directly released without interception or Alarm.
- Ignore: Only ignore this alarm. If the same situation occurs again, an alarm will still be triggered.
- Delete a record: Delete this alarm record. The console will no longer display it. Deleted records cannot be restored. Proceed with caution.
FAQs
Why Does a Trojan File Fail to Be Isolated?
Failure to isolate Trojan files is generally caused by Trojan files fighting against security software. It is recommended to delete the alarm file in the server first. If the issue still cannot be resolved, please contact us for processing. For Windows systems, you can also try using PC manager to scan and disinfect.
Next Steps
- Linux intrusion issue troubleshooting guide.
- Windows intrusion issue troubleshooting guide.