Description
Starting from KES Windows version 12.6, it can parse third-party mail base files, but still can't re-assemble them. Malware scan tasks runs in folders where mail base files for Thunderbird or TheBat! are located and finds threats in old mail items.
Diagnostics
After choosing Resolve or setting "Disinfect, delete if disinfection fails" in the KSC task, nothing changes, and another malware scan task anyway finds the same threats.
Workaround and solution
Sinc
Scenario
Enable Network Threat Protection
Connect another Mac via a thunderbolt cable
Try to send any data from one computer to another
Connection times out
Workaround & Solution
Connect computers by other means or disable NTP when using Thunderbolt bridge.
RCA
This issue is caused by a bug in macOS' built-in packet filter and was reported to apple.
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
Version: KES 11.*
Scenario:
You're unable to boot into encrypted machine after FDE applied due to some problems with preboot agent or operating system.
The the safest and one of the most trivial options to restore the data from encrypted hdd or decrypt it 'in place' is going through KES related ‘challenge-response’ procedure using another (i.e. proxy) machine with KES and FDE installed.
Problem Description, Symptoms & Impact
Local installation from a standalone package fails
Diagnostics
Check installation logs of the product. We are looking for the following string:
09.02.2022 17:06:19.453 00000374.000028B4 L1 KLSTD: #1, Error was caught in KLERR_throwError, c:\a\b\a_6vlf7p9h\s\csadminkit\development2\klri\pkginst\klpkinst.cpp@1061. Error params: (1187/0x0 ("Bad parameter "VerifyCertDate""), "KLSTD", c:\a\b\a_6vlf7p9h\s\csadminkit\development2\klri\pkgi
Symptoms
OS hang, sometimes with open file errors in journals
Customer application degrades with errors "unable to open file", "too many open files"
Hangs and third-party (compatibility) issues often require advanced data collection and are sophisticated to investigate. However, a quick check is possible:
On a system where KESL has worked for some time (not immediately after reboot/restart), validate the output of the following command, ran as root, for numerous r
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
Problem
When KES installation fails with error message "Failed to access local group policy. Error 0x80004005", installation log should be checked. If it contains something similar, follow the steps below.
MSI (s) (F4:94) [11:27:28:103]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MS
Problem
kesl-control --app-info outputs the following error:
en
File Threat Protection: Unavailable due to file interceptor driver error
One of the most common root causes is Fanotify is disabled (or KESL could not access it) and kernel module compilation also failed.
A special utility can be used for this directly on the affected mac
Problem
On Windows 10 v1903 and Windows Server v1903 after applying GPO Enable svchost.exe mitigation options, in System\Service Control Manager Settings\Security Settings, high CPU consumption by the following processes may be observed (avp.exe, klnagent.exe, kavfs.exe, kavfswp.exe). When checking if any resource consuming tasks are running, there are no ODS tasks running in KES or KSWS and no patch management related tasks are running too.
This is happening because MS security config
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
This informational message does not mean that Self-Defense accuses any process of being under malware attack, it proactively blocks certain operations that could pose a potential threat to processes.
The number of events depends on the activity of applications that inhabit the system, especially from their periodic acti
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
Version: any KES11.* on any OS
Scenario:
The following error appears during the installation:
Error 27310. Failed to install the directory file for the digital signature
Solution:
1. Run kavremover utility as administrator.
2. Delete KES drivers (if they were not deleted by kavremover) located
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
In cases when Bitlocker encryption of a certain volume is started using KES Bitlocker management, and the product returns the following error:
Event type: The policy can not be applied.
Action: Encryption
Reason: The system drive is not compatible with the Microsoft BitLocker encryption.
Type of encryption: dis
This article describes what is considered a Full Scan, which affects the KSC status "Virus Scan has not been performed for a long time".
Scan task area settings
There are two ways to set areas for a Scan task. Tasks started with any other settings (including Quick Scan and Critical Area Scan with default settings) will not be considered as a Full Scan.
Primary
Kernel Memory
Running processes and Startup Objects
Disk boot sectors
Local disk (logical di
Issue
Sometimes Device Control errors in KES may occur. For example, hard drives are wrongly blocked when USB device blocking is enabled, or flash drive blocking is not happening although the policies require to do so.
In some cases, the reason for erroneous blocking is that the operating system (OS) is incorrectly identifying the device type.
Solution
As an example, if the policies prohibit access to flash drives, but this rule does not always work, you can check the followi
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
This article covering the specific effect brought by any PF installation for the following versions:
KES 11 and higher
Private fix installation on host with KES has a side effect: the HIPS (Host Intrusion Prevention System) configuration will be reset back to defaults and, since Firewall is the part of
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
Problem
HIPS (Host Intrusion Prevention System) unexpectedly blocks data stream (audio, video) in trusted communication software such as MS Teams, Skype, Skype for Business etc.
Solution
The root cause is in KUsrInit.exe (parent process for many processes in the OS where it exists) which in some cases can be f
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article might be useful in the following cases:
If you want to configure multi-vendor security on endpoints, keeping both Kaspersky and Microsoft technologies;
If you don't know how to properly configure a Microsoft solution after installing KES;
If you're having some issues with the product and the OS after configuring KES and Defender.
The differences between the Defender
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
Problem
When KES installation fails with error message "Failed to access local group policy. Error 0x80004005", installation log should be checked. If it contains something similar, follow the steps below.
MSI (s) (F4:94) [11:27:28:103]: Invoking remote custom action. DLL: C:\WINDOWS\Installer\MS
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
Same info can be found here: https://support.kaspersky.com/16010
Starting from version 11.5, some file versions, registry and file system paths may differ from the release version and refer to the product line version.
Release full build version
Product line version
GUID
1
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
Problem Description, Symptoms & Impact
KES File Threat Protection sometimes can't check Microsoft office documents from mounted Google Drive shares, therefore generating Processing error events. This issue is caused by an incompatibility between Google Drive VFS driver and KES. There are no plans on making KES compatible with Google Drive.
Workaround & Solution
As a workaround, add fil
Problem Description
While installing KES for Windows via KSC installation package the following error appears and interferes with installation.
Possible causes:
KES components installed already before installation.
Required driver files were not found.
Workaround & Solution
Use kavremover and reinstall KES with the latest patch.
In case kavremover will not help, please collect procmon and KES installation logs, actual GSI with e
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.
This article is about Kaspersky Endpoint Security for Windows (KES for Windows)
This is a rough guide for testing FDE prior to implementation in production.
Make sure that the encrypted hosts will be serviced by a healthy KSC infrastructure (backups are performed regularly, no errors in Kaspersky Event log that need to be addressed, healthy database with plenty room for growth, no clo
The KESMac 12 and the KESMac 11.3 patch C allows adding particular processes into the trusted section named Trusted Applications.
The both filesystem and network activity of which can be ignored by the product increasing performance.
Please, however, note that this could be potentially risky.
https://support.kaspersky.com/KESMac/11.3_adminguide/en-US/194142.htm
Problem
This article will describe a few ways to configure KES for Mac to exclude some of the software from th
This error message means that KSWS KSN-Client was unable to reach KSN Cloud servers (in most cases if KSN Proxy is used).
Possible causes of the issue:
Various transport-level issues
KSC Server has been moved to another host with new DNS-name and IP-address
Troubleshooting steps:
Check that KSC is accessible via both its IP address and its hostname
Check that option "Bypass proxy for local addresses" is enabled (KSC server properties > Advanced > C
Description
VMWare guest using Kaspersky products hanging or crashing due to driver conflicts between drivers used by VMWare NSX (vnetWFP.sys, previously vnetflt.sys) and Network Threat Protection component.
This problem is known to happen with following versions of KES and VMware Tools:
KES 11.6 with VMWare Tools 10.0.9
KES 11.6 and 11.7 with VMWare Tools 11.3.5
KES 12 with VMWare Tools 10.1.7
Troubleshooting steps
Update VMWare Tools
Somet
Problem Description, Symptoms & Impact
In KES 12.0, the way Device Control component works has been changed. See changelog: https://support.kaspersky.com/help/KESWin/12.0/en-US/127969.htm
Due to these changes, you may notice that printing order becomes slow after you have upgraded KES to version 12.0 or higher. This delay may be around 30-60s or even 10-15 minutes. When you disable KES, it becomes instant. In some exceptional cases, the delay may be so big that it's impossible to p