Clicking Ignore after discovering risky behavior has no effect.
-
<p><strong>Reproduction steps:</strong></p>
<p><span>The reproduced video and trace are placed in the network disk.</span></p>
<p><strong>Actual result:</strong></p>
<p><span>The "Ignore" button doesn't work.</span></p>
<p><strong>Expected Result:</strong></p>
<p><span>The "Ignore" button works.</span></p> -
<p>Behavior description:</p>
<p>This is a game accelerator, but it will modify the hosts file to set the resolution of some specific addresses to fixed IPs, and then redirect these IPs through the game accelerator. It is modified in a special way. It will first rename the hosts file to hostvk. Then add a hosts file, this behavior will be recognized as dangerous behavior by Kaspersky.</p>
<p><span style="text-decoration: underline;"><em>This behavior can be ignored by clicking the "Ignore" button in 21MR3, which should be a bug in the Beta version.</em></span></p> -
<p>Hello! Let me explain. It's particularity of our "curing" process: when a threat is founded, two parallel process start: 1) AV starts to "cure" threat, it locks file and has highest priority 2) notification is shown in notification center. Its a "backup" action to solve minor threats (like an official apps, which can be used to harm you), or if first auto-AV process has failed. Our release-state app should do both process "almost simultaneously", so user won't see a notification and can click several times button without effect. </p>
<p></p> -
<p>@dmitriy-pisarets</p>
<p>I think the choice of how to handle this threat should be left to the user, as it could be a false positive by the program.</p>