Jump to content

Kaspersky Security 10.1.2 scan


Go to solution Solved by Oleg Bykov,

Recommended Posts

I am currently using CommVault v11.19 together with Kaspersky Security 10.1.2 for windows server & Kaspersky Security Center 11 Network Agent. During our weekly Kaspersky scan we've used procmon to determine that process is changing both the timestamps and attributes on scanned files. Unfortunately, this results in CommVault's File Activity Anomaly Alert triggering as it detects Ransomware like activities plus the subsequent backup takes considerably longer as more changed files are obviously detected. Is there any way of preventing the Kaspersky scan from changing both the timestamps and attributes of the files? 

Thanks in anticipation

Link to comment
Share on other sites

I also posted on the CommVault Forum and almost immediately received the following kind reply “I don’t think this is the right way for an antivirus to change the timestamps on a file. This will affect the backups as well since backups depend on modifications time of a file and if that changes, there is a chance that we could skip files from backup or backup extra data. The anomaly report is also pointing to the same that there is some anomaly happening on the machine. I don’t think CommVault can do anything here unless the antivirus fixes itself to not modify the timestamp.”

Link to comment
Share on other sites

  • 2 weeks later...
  • Solution

To instruct KSWS to not mess with file times when doing the On-Demand scanning, add this value to the registry:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\KasperskyLab\WSEE\10.1\Environment]
"DontRestoreFileTimes"=dword:00000001

 

Link to comment
Share on other sites

This key completely resolves my issue with thanks Oleg. I only wish I’d been aware of it three years ago when Kaspersky was originally installed and configured. It appears to be very strange that there is any particular ‘out-of-the-box’ requirement to amend time-stamps? Do the installation/configuration instructions make specific reference to this requirement (and ‘fix’) anywhere (obviously I’m disappointed that I missed it) - a weblink or ‘cut-and-paste’ would be very much appreciated.  

Link to comment
Share on other sites

I don't think we have it somewhere in the documentation - the timestamp restoration was done initially to avoid problems with Backup systems (and as far as I’m aware it helps with some). What we failed to do was to document it properly and also to make it easier to configure. Both of which will hopefully be addressed with the next release (KSWS 11).

 

Link to comment
Share on other sites

  • 4 months later...

Hello,

 

I haven’t tried this registry fix yet on KS 10.1 but thank you for the info.

 

I’ve installed version KS 11.0 on a server recently and I still can’t find the option to preserve the last accessed time stamp, so will the registry work the same for 11??

 

Apparently, the option is on the workstation version but not the server versions, which seems a bit daft in my opinion.

 

Regards,

James

Link to comment
Share on other sites

Hello James,

You are right - there’s still no option to not restore filetime in the KSWS 11.0 UI. Sorry about that! Daft probably sounds appropriate in this case.

This is what we’ll do - we’ll prepare a Knowledge Base article about how to avoid these problems via the “registry hack”, and meanwhile we’ll strive to add this option to the UI in the next release (11.1 or whatever).

Thank you for using KSWS!

Link to comment
Share on other sites

Hi Oleg,

 

Thank you for your reply, yeah seems like a daft thing but it’s causing myself issues when trying to archiving files with our Redstor cloud backup.

 

An article would be great thank you :-), where will this article will be available when its done?

 

Can I use the same registry file for Version 11?

 

Regards,

James

 

Link to comment
Share on other sites

Hi Again Oleg,

 

I’ve tested the registry fix on a version 10.1 server and it hasn’t worked for me 😞, it has still been accessed the same day by Kaspersky’s on-demand scan I assume.

 

No one has accessed it for a while but so I’m stumped!

 

Regards,

James

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...