Kaspersky application control question?

Kasperksy Product Talk: Antivirus , Internet Security Suite , Pure and other related products.

If this topic has helped you then please...



 

Kaspersky application control question?

Postby ieattacos » Sat Dec 18, 2010 9:39 pm

What do you guys think is a better setting for application control? Move unknown applications to high restricted or untrusted?
User avatar
ieattacos
Regular Contributor
 
Posts: 402
Joined: Thu Jul 15, 2010 9:55 am
Has thanked: 27 times
Have thanks: 8 times

Kaspersky application control question?

Advertisement

Advertisement
 

Re: Kaspersky application control question?

Postby gusthebus » Sat Dec 18, 2010 9:43 pm

Yes I think they should be moved to Untrusted personally. I found in my tests that Kaspersky assigned a lot of malware to "low restricted" where it was allowed to cause a lot of damage. You may have to assign a few applications manually to "trusted" that aren't on Kaspersky's whitelist, however.

More manual work = Untrusted setting
Less manual work = Let App control decide
KIS 2012
gusthebus
Global Moderator
 
Posts: 750
Joined: Fri Aug 13, 2010 10:47 pm
Location: St. Louis, Missouri
Has thanked: 70 times
Have thanks: 22 times
OS: Windows 7 Ultimate
Architecture: 64bit

Re: Kaspersky application control question?

Postby ieattacos » Sat Dec 18, 2010 9:47 pm

Well I mean should I chose high restricted or untrusted?
User avatar
ieattacos
Regular Contributor
 
Posts: 402
Joined: Thu Jul 15, 2010 9:55 am
Has thanked: 27 times
Have thanks: 8 times

Re: Kaspersky application control question?

Postby gusthebus » Sat Dec 18, 2010 9:53 pm

My mistake, I misread the question. I personally would go with Untrusted. If a legitimate process is set to high restricted, you will likely have to adjust it for the process to run properly anyway. With the untrusted mode, malware won't even get a chance to run.
KIS 2012

For this message the author gusthebus has received thanks:
ieattacos (Sat Dec 18, 2010 9:54 pm)
Rating: 12.5%
gusthebus
Global Moderator
 
Posts: 750
Joined: Fri Aug 13, 2010 10:47 pm
Location: St. Louis, Missouri
Has thanked: 70 times
Have thanks: 22 times
OS: Windows 7 Ultimate
Architecture: 64bit

Re: Kaspersky application control question?

Postby ieattacos » Sat Dec 18, 2010 9:55 pm

Thanks. :) I would also like some others opinions when they log on.
User avatar
ieattacos
Regular Contributor
 
Posts: 402
Joined: Thu Jul 15, 2010 9:55 am
Has thanked: 27 times
Have thanks: 8 times

Re: Kaspersky application control question?

Postby virtu » Sun Dec 19, 2010 12:28 am

Depends on your web-browsing behavior. Do you watch porn, warez,free wallpapers from unknown places, test malware on your host, etc. Then go with the most restrictive settings shown by gusthebus above and you will block unknown malware that could slip and infect your PC.
A fool with an antivirus tool is still a fool.
If you can't convince them, confuse them.
The last thing I want to do is insult you. But it IS on the list.

For this message the author virtu has received thanks:
pranaygtr (Sun Dec 19, 2010 7:26 am)
Rating: 12.5%
User avatar
virtu
Master Contributor
 
Posts: 2605
Joined: Sat Dec 27, 2008 4:37 am
Location: Earth...maybe
Has thanked: 5 times
Have thanks: 25 times
OS: Windows 7 Home
Architecture: 32bit

Re: Kaspersky application control question?

Postby ieattacos » Sun Dec 19, 2010 9:01 am

Well maybe everyonce in a while a wallpaper from unknown places. I do test malware in a virtual machine sometimes. Other then that not really anything you said.
User avatar
ieattacos
Regular Contributor
 
Posts: 402
Joined: Thu Jul 15, 2010 9:55 am
Has thanked: 27 times
Have thanks: 8 times

Re: Kaspersky application control question?

Postby sss20 » Sun Dec 19, 2010 9:59 am

High Restricted - The applications of this group require the user's permission for most actions which affect the system: some actions are not allowed for such applications.
Image
Rules.Please note that all the applications have the right to start.But you can change this rule to "Promt for action"
Image

Untrusted - Application Control blocks any actions performed by the applications in this group
Image
Rules.Please note that all the actions are blocked by default
Image


But if you really want to be in control you can do this steps :

1. Advance Settings > Notifications - > Minor Notifications > Check : Applications Placed in Restricted Group > Ok

2.Enable Interactive Mode
Interactive. Kaspersky Internet Security informs the user about all malicious and suspicious events. In this mode the user will manually select actions: allow or block activities.You will get someKIS alets (to answer) sometime when installing applications but is a pretty powerful barrier against unknown applications and threats because it allows us to control its execution strongly.
How to enable Interactive Mode - http://support.kaspersky.com/kis2011/tech?qid=208281922

3. Enable "Block dangerous web sites "
Block dangerous websites

If the box is checked, Web Anti-Virus blocks access to the websites which have been considered as suspicious or phishing ones by Kaspersky URL Advisor. If Web Anti-Virus cannot return a clear verdict on safety of the website to which a link directs, you will be offered to load this website in Safe Run. When activated in Safe Run, malicious objects do not impose any threat to your computer.

Web Anti-Virus allows to download websites in the safe environment for Microsoft Internet Explorer, Mozilla Firefox and Google Chrome.

If the box is unchecked, Web Anti-Virus does not block access to known suspicious websites automatically.

How to enable "Block dangerous web sites " - http://support.kaspersky.com/faq/?qid=208281828


4. Go to Advance Settings > Threats and Exclusions ->Threats -> Settings -> Enable Other.

5.Increase Maximum time to define the application group
Maximum time to define the application group

Time period required for Application Control to scan applications being run, using heuristic analysis. Time period is set in seconds.

By default, Application Control analyzes an application for 30 seconds. If, when this time period expires, Application Control cannot clearly define threat rating of the application, the component moves it to the Low Restricted group. Application Control continues scanning the application in background mode, after which it is included into a trust group.

Go to Settings > Application Control > Maximum time to define the application group > 60 Seconds.


All this settings should make an awesome program like KIS more awesome for an Advance user. ;)
Or you can just put everything in Untrusted...or High Restricted and tweak the rules. :D

For this message the author sss20 has received thanks: 2
ieattacos (Sun Dec 19, 2010 1:12 pm), virtu (Mon Dec 20, 2010 2:57 pm)
Rating: 25%
sss20
Master Contributor
 
Posts: 3358
Joined: Thu Jul 30, 2009 6:43 am
Has thanked: 132 times
Have thanks: 151 times
OS: Windows 7 Professional
Architecture: 64bit

Re: Kaspersky application control question?

Postby sss20 » Sun Dec 19, 2010 2:39 pm

ieattacos for this measures to really work you should also do this step :

Settings -> Application Control -> Applications -> select Low Restricted group line, and rightclick mouse button -> Group rule
and make Kaspersky ask you when an application from Low Restricted wants to start.You just need to change the "Start" Rule to "Promt for action.
Here is how my rules for the Low Restricted Group looks.Thi settings will make your pc very secure but you will have some alets from the unknown programs...but Kaspersky has a really big whitelist so this shound't be a real problem if you aren't installing everyday less known apps and programs. :D
Image


In my eyes setting every unkwon app to untrusted is a measure for the less experienced .... :roll:
sss20
Master Contributor
 
Posts: 3358
Joined: Thu Jul 30, 2009 6:43 am
Has thanked: 132 times
Have thanks: 151 times
OS: Windows 7 Professional
Architecture: 64bit

Re: Kaspersky application control question?

Postby ieattacos » Mon Dec 20, 2010 2:49 pm

I decided for it to put everything unknown in untrusted. The reason is because if one of my programs aren't running I will know why. One time when I had kaspersky set one of my applications to high restricted it made the application work weird and I had to reinstall that application. It seems easier if it would just block it from running then break the application. Since I can easily unblock it. Also I don't really want to many pop ups lol.

I am still thinking about it though.
User avatar
ieattacos
Regular Contributor
 
Posts: 402
Joined: Thu Jul 15, 2010 9:55 am
Has thanked: 27 times
Have thanks: 8 times

Next

Return to Kaspersky Talk

Who is online

Users browsing this forum: No registered users and 1 guest

cron