Antivirus

View FortiClient engine and signature versions

You can view the current FortiClient version, engine, and signature information when FortiClient is in standalone or managed mode.

When FortiClient is connected to FortiGate for endpoint control, you can select to use a FortiManager device for client software and signature updates. When configuring the FortiClient profile, select Use FortiManagerforclient software/signature updates to enable the feature, and enter the IP address of your FortiManager device. You can select to failover to FDN when FortiManager is not available.

To view the current FortiClient version:

  1. Go to Help > About.

Schedule antivirus scanning

  1. Hover the mouse over the Status field to see the date and time that FortiClient last updated the selected item.
  2. Click Close.

Schedule antivirus scanning

This setting can only be configured when FortiClient is in standalone mode.

If you configure monthly scans to occur on the 31st of each month, the scan will occur on the first day of the month for those months with less than 31 days.

To schedule antivirus scanning:

  1. On the AntiVirus tab, click the Settings icon beside Realtime Protection.
  2. Click the Scheduled Scan
  3. Configure the following settings:
Schedule Type Select Daily, Weekly, or Monthly from the drop-down list.
Scan On For Weekly scheduled scan, select the day of the week in the drop-down list.

For Monthly scheduled scan, select the day of the month in the drop-down list.

Start Select the time of day that the scan starts. The time format uses a 24-hour clock.

Schedule antivirus scanning

Scan Type Select the scan type:

Quick system scan runs the rootkit detection engine to detect and remove rootkits. It only scans executable files, DLLs, drivers that are currently running for threats.

Full system scan runs the rootkit detection engine to detect and remove rootkits. It then performs a full system scan including all files, executable files, DLLs, and drivers for threats.

Custom scan runs the rootkit detection engine to detect and remove rootkits. It allows you to select a specific file folder on your local hard disk drive (HDD) to scan for threats.

You cannot schedule a removable media scan. A full scan will scan removable media.

Disable Scheduled Scan Select to disable scheduled scan.
  1. Click OK to save the setting and return to the main FortiClient console page.

Add files or folders to exclusion lists

This setting can only be configured when FortiClient is in standalone mode.

To add files/folders to the antivirus exclusion list:

  1. On the AntiVirus tab, click the Settings icon beside Realtime Protection.
  2. Click the Exclusion List
  3. Click the Add icon, and select Add file or Add folder from the drop-down list. Any files or folders in this exclusion list will not be scanned.
  4. Click the Minus icon to remove files or folders from the list.
  5. Click OK to save the setting and return to the FortiClient console page.

View scan results

View scan results

You can view quarantined threats, site violations, alerts, and realtime protection events when FortiClient is in standalone or managed mode.

View quarantined threats

To view quarantined threats:

  1. On the AntiVirus tab, click the X Threats Detected link
  2. Click the Quarantined Files

In this page you can view, restore, or delete the quarantined file. You can also view the original file location, the virus name, submit the suspicious file to FortiGuard, and view logs.

This page displays the following:

File Name The name of the file.
Date Quarantined The date and time that the file was quarantined by FortiClient.
Refresh Select to refresh the quarantined files list.
Details Select a file from the list to view detailed information including the file name, original location, date and time that the virus was quarantined, the submitted status, status, virus name, and quarantined file name.
Logs Select to view FortiClient log data.
Refresh Select to refresh the list.
Submit Select to submit the quarantined file to FortiGuard. Press and hold the control key to submit multiple entries.

View scan results

Restore Select to restore the quarantined file. A confirmation dialog box will be displayed. You can select Yes to add this file/folder to the exclusion list, No to restore the file, or

Cancel to exit the operation. Press and hold the control key to restore multiple entries.

Delete Select to delete the quarantined file. A confirmation dialog box will be displayed, select Yes to continue. Press and hold the control key to delete multiple entries.
Close Select to close the page and return to the FortiClient console.
  1. Click Close.

View site violations

On the Site Violations page, you can view site violations, and submit sites to be re-categorized.

To view site violations:

  1. On the AntiVirus tab, click the X Threats Detected
  2. Click the Site Violations

This Site Violations page displays the following options:

Website Displays the name of the website.
Time Displays the date and time of the site violation.
Refresh Select to refresh the site violation list.
Details Select an entry in the list to view site violation details including the website name, category, date and time, user name, and status.

Select the category link to request to have the site category re-evaluated.

  1. Click Close.

View scan results

This entry was posted in FortiClient and tagged , , on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.