#4420 Clicking Ignore after discovering risky behavior has no effect.


  • Information provided

    , last edited by Jarvis

    Reproduction steps:

    The reproduced video and trace are placed in the network disk.

    Actual result:

    The "Ignore" button doesn't work.

    Expected Result:

    The "Ignore" button works.

    System Settings

    Operating system: Win 11, x64

    System: Intel Core i7 10700k, Samsung 970 EVO Plus

    Product: PLUS

    Product Version: 21.7.7.305

    Language: zh-CN

    Product Logs: https://pan.huang1111.cn/s/ygebt6

  • Behavior description:

    This is a game accelerator, but it will modify the hosts file to set the resolution of some specific addresses to fixed IPs, and then redirect these IPs through the game accelerator. It is modified in a special way. It will first rename the hosts file to hostvk. Then add a hosts file, this behavior will be recognized as dangerous behavior by Kaspersky.

    This behavior can be ignored by clicking the "Ignore" button in 21MR3, which should be a bug in the Beta version.

  • Hello! text in notification center will be shown till alert (at the right-bottom corner will be closed)
  • Hello! Let me explain. It's particularity of our "curing" process: when a threat is founded, two parallel process start: 1) AV starts to "cure" threat, it locks file and has highest priority 2) notification is shown in notification center. Its a "backup" action to solve minor threats (like an official apps, which can be used to harm you), or if first auto-AV process has failed. Our release-state app should do both process "almost simultaneously", so user won't see a notification and can click several times button without effect. 

  • @dmitriy-pisarets

    I think the choice of how to handle this threat should be left to the user, as it could be a false positive by the program.



Looks like your connection to Beta Testing was lost, please wait while we try to reconnect.