Kaspersky AV v Nod32

Discussion in 'other anti-virus software' started by Badcompany, Apr 17, 2006.

Thread Status:
Not open for further replies.
  1. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    Also bet on BitDefender. They've decreased response times significantly in last few months. Quiet impressive.
     
  2. storm119

    storm119 Registered Member

    Joined:
    Apr 11, 2004
    Posts:
    39
    Location:
    `Land Below The Wind'
    I think what SSK meant is before enable/disable, just check if both (KAV or ProcessGuard) offerring the same lavel of protection to avoid any over-lap functions which will lead some conflict rather than solid protection. Just enable one that one not availabe or which are you thing suit/comfortable to your protection need.

    Imho....you can enable all features in PG and for KAV "Proactive Defense" enable only for selective modules. ie:

    1). Enable Application Activity Analyzer ( under setting -> checked only -> Hidden Processes (rootkit), Suspicious values in registry and Suspicious system activities, unchecked others).
    2). Enable Registry Guard (checked all under setting).
    3). Enable Office Guard (checked all), and
    4). Disable the AIC (like SSK mentioned some reported its will caused some High CPU usage...but i don't see it in my machine). On the other note, I believed PG offer much better solutions/protections in this area/scope, so just disable the "AIC" and you're just fine....;)

    I might be wrong... just add my $2 (couldn't find cents symbol ..LoL!!).

    Good luck :D
     
  3. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Thanks storm, I try it that way. I know that the way I had it, Avant browser would set out an alert from KAV every time I used Avant browser. LOL
     
  4. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven

    Detox I was not reffering to this. I don't need a reply to my e-mail. Just to add faster the signature for it..... that was the quick answer I was reffering to. ;)

    I know their prior to base etc, etc...answer but when KAV adds a virus in 3-4 hours and they add it in 2-3 weeks it's a difference.
     
  5. storm119

    storm119 Registered Member

    Joined:
    Apr 11, 2004
    Posts:
    39
    Location:
    `Land Below The Wind'
    Yay...too noisy sometimes very annoying..LoL!!! :D

    Anyway,i'm glad its help you...a little ;)
     
  6. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Yeah I still get KAV warnings when I start avant browser. I tried setting rules for them but KAV nver keeps the rules for them for some odd reason.
     
  7. storm119

    storm119 Registered Member

    Joined:
    Apr 11, 2004
    Posts:
    39
    Location:
    `Land Below The Wind'
    Well i never use Avant browser and not sure what alert you get (can you give some "SS").

    Anyway, I only can assumed its PD's alarmed you. Next time if PD (KAV) alert you again just create a rule by clicking the pop-up at the bottom ---> add to Trusted Zone ---> Exlcusion Masks (no.1) --> create the rule ---> checking task = select --> Proactive Defense (no.3). (see the "SS" attached)
    http://img422.imageshack.us/img422/9637/pd2zo.gif
    http://img223.imageshack.us/img223/2449/pd12sr.gif

    Or you can manually add Avant (or any object/task etc) to the exclusion masks. Go to Settings ---> Trusted Zone ---> Exclusion Masks (no.1) ---> Add (no.2) ---> Object Name : click --> specify (no.4) . Next ---> browse to where the Avant exe file stored --> click ok ---> Checking Task: Selected task : click --> File Anti-Virus (no.5), in new pop-up (important) check only the Proactive Defense and try launch Avant again..?

    This also valid to exclude any tasks (file,exe,folder etc) that you wish to excluded from being scanned (manual or real time) or monitor by PD.

    Hope i'm not confuse you .... LoL!!!

    ps: let me know if this works for you ;)
     
  8. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Process is trying to create value in system registry key that belongs to group Internet Explorer Plugins. These keys control Internet Explorer.add-ons settings.

    You are advised to grant access to these settings only if you are sure you want to allow this module to be registered as an Internet Explorer add-on. Otherwise it is better to deny access.

    Key: HKEY_USERS\S-1-5-21-1454471165-484061587-725345543-1003\Software\Microsoft\Internet Explorer\MenuExt\Add to AD Black List

    Value:

    New data(Unicode null-terminated string):
    C:\Program Files\Avant Browser\AddToADBlackList.htm

    Thanks what it says when I click detail. It's a registry access. Every time I try ti creat a rule for it, I get an alert again even though I allow it in a rule.
     
  9. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Here's one of many PD alerts.
     

    Attached Files:

  10. storm119

    storm119 Registered Member

    Joined:
    Apr 11, 2004
    Posts:
    39
    Location:
    `Land Below The Wind'
    Ahhhh..i see. My mistake. Ok...I'm refferring to the alert above --> dont click "Allow" button but check the box --> "create rule" next click "Add to Trusted Applications..." new pop-up check the "Do not control registry access" --> click Ok. Or you can manually add Avant.exe to trusted application via the browse button point to avant.exe and check "do not control registry access".

    http://img508.imageshack.us/img508/5250/rg1qh.gif
     
    Last edited: Apr 19, 2006
  11. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Thanks, that didn't work. I still have to create rules everytime I start Avant.
     
  12. storm119

    storm119 Registered Member

    Joined:
    Apr 11, 2004
    Posts:
    39
    Location:
    `Land Below The Wind'
    After reading (again) your post #33, i think Avant try to modify the IE Plugin registry which a monitor by Registry Guard in PDM. Since you trust Avant you can always give full access to Avant to modify/add to this registry. To do that try this :

    Under the "Registry Guard" --> settings --> "Internet Explorer Plugins" --> Click Edit button --> Rules tab --> New --> at the bottom --> click "any" and specify the application --> browse to point Avant.exe. [important tricky part] Rules for Modify: Change it to Allow + Log (incase you want inspect later via the Events (report) or you just set it to do not log) other rules just leave to default setting next click ok and try launch Avant ... ?. Try this first if fail you need to create a new rule for Avant in the "Internet Explorer Settings" via the "Registry Guard PD", follow the same steps as mentioned.

    http://img65.imageshack.us/img65/1272/ge26go.gif

    If the issue still exist....i got no more idea (LoL!!!). My suggestion just post this issue to Kaspersky forum, hopely someone using Avant browser could give you better suggestion.

    Good luck ;)
     
    Last edited: Apr 19, 2006
  13. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    None of that helped. Thanks for the help though. I just turned off the registry guard in KAV. I get like 10 alerts and they get annoying so I can't keep the registry guard. I have the paid version of ProcessGuard and I feel safe with that and the other parts of the KAV PD running.
     
  14. storm119

    storm119 Registered Member

    Joined:
    Apr 11, 2004
    Posts:
    39
    Location:
    `Land Below The Wind'
    Roger that ........ :D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.