Kaspersky Standard antivirus is an entry-level cybersecurity solution designed to protect devices from viruses, malware, ransomware, and other online threats.
Kaspersky antivirus version 18
Kaspersky Standard for Windows offers core antivirus and security features, including:
- Real-time protection: Scans files, apps, and websites to block viruses, ransomware, trojans, and other malware.
- Web protection: Prevents access to malicious or phishing sites.
- Safe Money: Secures online banking and shopping with a protected browser mode.
- Performance optimization: Includes tools like PC Cleaner to remove junk files and optimize startup.
- Firewall: Blocks unauthorized network access.
- Anti-phishing: Detects and blocks fraudulent links and emails.
The overall security model of Kaspersky makes it user friendly and easy to use.
Application Manager: The assignment of applications to trust groups is primarily driven by Kaspersky Security Network (KSN). This makes it easier to manage the application activity in the computer and its network traffic.
Safe Browsing setting
For a faster web browsing experience, set the Security level to Low.
Firewall Settings
Application rules
Kaspersky Standard antivirus includes a robust firewall component that categorizes applications into trust groups under Application network rules: Trusted, Low Restricted, High Restricted, and Untrusted. This categorization determines the level of network access each application is granted, balancing security and functionality.
Trust Group Categories and Their Network Rules
Kaspersky Endpoint Security assigns applications to one of four trust groups, which dictate their network activity permissions across different network types (Trusted, Local, Public). The firewall uses these groups to control application behavior, with rules applied automatically or customized by the user.
1. Trusted:
- Description: Applications in this group are considered safe and pose minimal risk to the system. They are typically well-known, verified applications or those explicitly marked as trusted by the user or Kaspersky Security Network (KSN).
- Network Access: All network activity is allowed by default in Trusted, Local, and Public networks. This includes unrestricted access to network resources, such as file sharing, internet access, and communication with other devices.
- Example Use Case: Trusted applications like web browsers (e.g., Chrome, Firefox) or system utilities may be placed here to ensure seamless operation without firewall restrictions.
2. Low Restricted:
- Description: Applications with a low risk level, often identified as safe by KSN or user settings but with slightly more scrutiny than Trusted apps. These may include less critical software or apps with moderate network activity.
- Network Access: All network activity is allowed by default in Trusted, Local, and Public networks, similar to the Trusted group. However, Low Restricted apps may face additional monitoring by the Host Intrusion Prevention component.
- Example Use Case: Productivity software or media players that require network access but aren’t critical system components might fall into this category.
3. High Restricted:
- Description: Applications deemed potentially risky, either due to unknown status in KSN, suspicious behavior, or manual user assignment. These apps are subject to stricter control to prevent unauthorized access or data leaks.
- Network Access: All network activity is blocked by default in Trusted, Local, and Public networks. No network connections are allowed unless specific rules are created to permit certain activities.
- Example Use Case: Unknown or unverified applications, such as newly installed software from an untrusted source, are placed here to limit their network access until verified.
4. Untrusted:
- Description: Applications explicitly marked as unsafe by the user or not recorded in KSN’s trusted applications database. These are considered high-risk and are heavily restricted to protect the system.
- Network Access: All network activity is blocked by default in Trusted, Local, and Public networks, similar to High Restricted. Additionally, these apps face high restrictions on accessing operating system resources, making them the most controlled group.
- Example Use Case: Suspicious executables or apps flagged as potential malware are placed in this group to prevent any network or system interaction.
Determination of Trust Groups
The assignment of applications to trust groups is primarily driven by Kaspersky Security Network (KSN), a cloud-based intelligence system that leverages global threat data to categorize applications. Research suggests that KSN participation enhances the firewall’s effectiveness by providing real-time reputation data, placing applications into appropriate trust groups based on digital signatures, vendor trust, and historical behavior.
If KSN is not utilized—due to user preference or lack of network connectivity—Kaspersky Endpoint Security falls back to the settings of the Host Intrusion Prevention component. This component analyzes application behavior locally, determining trust groups based on predefined criteria, such as file integrity and system impact.
How Application Network Rules Work
- Default Rules: Kaspersky’s firewall automatically creates network rules for each application based on its trust group. For Trusted and Low Restricted groups, all network activity is allowed across all network types (Trusted, Local, Public). For High Restricted and Untrusted groups, all network activity is blocked by default. These predefined rules cannot be edited or deleted but can be supplemented with custom rules.
- Network Types:
- Custom Rules: You can create specific network rules for individual applications, which take priority over group rules. For example, you can allow a High Restricted app to access specific ports or protocols while keeping other restrictions intact. Custom rules can be enabled, disabled, or modified, and their priority can be adjusted (higher in the list = higher priority).
- Child Processes: If an application (parent process) has a specific network rule, its child processes inherit those rules. If no specific rule exists, child processes follow the trust group’s default rules. For example, if a Trusted app (like a browser) launches an installer, the installer may inherit the browser’s network access permissions.
- Priority: Network packet rules (specific to protocols or ports) take precedence over application network rules. Within application rules, higher-listed rules have higher priority.
A. Manually change the trust group of the application
Right click on any application and select Restrictions menu. Here user can manually change the application Trust group.
The app RGB Gaming Mouse trust group has been manually changed to Trusted.
B. Manually change the Network rules of the application
In Kaspersky Endpoint Security, network rules within the firewall settings determine how applications interact with networks, using specific actions like Inherit, Allow, Perform action automatically, and Block. These actions are applied to application network rules to control network access based on the application’s trust group (Trusted, Low Restricted, High Restricted, Untrusted) and network type (Trusted, Local, Public).
Network Rule Actions
These actions define how the firewall handles network activity for an application when a rule is triggered:
- Inherit:
- Description: The application inherits the network access permissions defined by its trust group’s default rules or any higher-priority rules. This action ensures that the application follows the default behavior of its assigned trust group (e.g., Trusted, Low Restricted) unless overridden by a more specific rule.
- Behavior:
- For Trusted or Low Restricted groups, network activity is typically allowed across Trusted, Local, and Public networks.
- For High Restricted or Untrusted groups, network activity is blocked by default in all network types.
- If a parent process has a specific rule, child processes may inherit it unless a higher-priority rule applies.
- Use Case: Useful when you want an application to follow the default trust group settings without creating custom rules. For example, a Trusted browser like Chrome inherits full network access without needing manual configuration.
- Example: A new application categorized as Low Restricted inherits the group’s default rule to allow all network activity unless you specify otherwise.
- Allow:
- Description: Explicitly permits the application to perform the specified network activity (e.g., accessing a particular port, protocol, or network type). This action overrides any restrictive default rules for the application’s trust group.
- Behavior: The application can connect to the specified network resources (e.g., internet, local servers) based on the rule’s parameters, such as protocol (TCP/UDP), port, or network type (Trusted/Local/Public).
- Use Case: Ideal for granting specific access to an application that might otherwise be restricted. For instance, allowing a High Restricted game to use TCP port 443 for online play while keeping other restrictions.
- Example: You create a rule to allow a video conferencing app in the High Restricted group to access UDP ports for video streaming, overriding the default block.
- Perform Action Automatically:
- Description: The firewall decides whether to allow or block the application’s network activity based on predefined criteria, such as Kaspersky Security Network (KSN) data, Host Intrusion Prevention settings, or application behavior analysis. This action automates decision-making without requiring user intervention.
- Behavior:
- If KSN identifies the application as safe, network activity is typically allowed.
- If the application is unknown or suspicious, it may be blocked or restricted, depending on the trust group and firewall settings.
- The action may prompt the user for input if Prompt for action is enabled in the firewall settings (not default).
- Use Case: Suitable for users who want Kaspersky to handle decisions dynamically, especially for unknown applications or in environments with frequent software updates. For example, an unverified app might be allowed limited access if KSN deems it low-risk.
- Example: A newly installed utility in the High Restricted group attempts to connect to the internet; Kaspersky automatically allows or blocks it based on KSN reputation data.
- Block:
- Description: Explicitly prevents the application from performing the specified network activity. This action overrides any default permissions, ensuring the application cannot access the network for the defined parameters (e.g., specific ports, protocols, or network types).
- Behavior: All network activity matching the rule’s criteria is blocked, regardless of the application’s trust group or other rules. For example, a rule can block an application from accessing Public networks while allowing access to Trusted networks.
- Use Case: Useful for restricting potentially risky applications or limiting access to specific network resources. For instance, blocking a Low Restricted app from accessing Public Wi-Fi to prevent data leaks.
- Example: You create a rule to block a chat application in the Trusted group from using UDP ports on Public networks to enhance security in untrusted environments.
How These Actions Are Applied
- Priority: Rules are processed in order of priority (higher in the list = higher priority). For example, an Allow rule for a specific port takes precedence over an Inherit rule for the same application. You can adjust rule order using Up/Down buttons.
- Default Rules: Each trust group has predefined rules:
- Trusted/Low Restricted: Default to Allow for all network activity in all network types.
- High Restricted/Untrusted: Default to Block for all network activity in all network types.
- The Inherit action ensures applications follow these defaults unless a custom rule overrides them.
- Child Processes: If an application (parent process) has a specific rule with one of these actions, its child processes inherit that rule unless a higher-priority rule applies. For example, a child process of a Trusted app with an Allow rule will also be allowed unless blocked by a specific rule.
- Network Types:
- Trusted Network: Secure networks (e.g., home Wi-Fi) where all activity is typically allowed for Trusted/Low Restricted apps.
- Local Network: Restricted networks (e.g., corporate LAN) with limited access to resources like file sharing.
- Public Network: Unsecure networks (e.g., public Wi-Fi) where restrictions are stricter, especially for High Restricted/Untrusted apps.
User have option to manually set the Network rules of an application.
To set the Network rules of an application, right click on the application and select an option from the Network rules menu.
The application WiFiman Desktop network rule set to Allow.
Performance
A. Quick Startup
- Description: Quick Startup optimizes the system’s boot process by managing startup programs and services. It identifies and delays or disables non-essential applications that launch during system startup, reducing boot time and freeing up system resources.
- How It Works:
- Scans for programs and services that automatically start with Windows.
- Provides recommendations to disable or delay low-priority startup items (e.g., non-critical apps like media players).
- Allows users to customize which programs run at startup via an intuitive interface.
- Key Features:
- Startup Time Reduction: Decreases the time it takes for the system to become fully operational after powering on.
- Resource Management: Frees up CPU and memory by limiting unnecessary startup processes.
- User Control: Offers options to enable, disable, or delay startup items, with details on each program’s impact (e.g., high, medium, low).
- Benefits:
- Improves boot speed, especially on older devices or systems with many startup programs.
- Reduces background resource usage, enhancing overall performance.
- Limitations:
- May require user input to decide which programs to disable, as some apps (e.g., cloud sync tools) may be needed at startup.
B. PC Speedup
- Description: PC Speed-Up is a suite of optimization tools that cleans up system clutter to improve device responsiveness. It targets temporary files, cache, and other data that slow down the system.
- How It Works:
- Scans for junk files (e.g., temporary files, browser cache, recycle bin contents) and Windows registry issues.
- Provides a one-click cleanup option or detailed manual control over what to remove or optimize.
- Key Features:
- Junk File Removal: Deletes temporary files, logs, and cached data to free up disk space (e.g., can reclaim 1–5 GB on heavily used systems).
- Benefits:
- Enhances system responsiveness, particularly for tasks like browsing or gaming.
- Frees up storage space, which can improve performance on low-disk-space systems.
- Limitations:
- May not significantly impact high-end systems with ample resources.
Unused system files
Windows registry issues
C. App Updater
- Description: App Updater ensures that installed applications are kept up to date by identifying outdated software and facilitating updates. Outdated apps can pose security risks (e.g., vulnerabilities) and may run less efficiently.
- How It Works:
- Scans the system for installed applications and checks their versions against a database (often linked to Kaspersky Security Network).
- Notifies users of available updates for supported software (e.g., browsers, PDF readers, media players).
- Provides options to update apps automatically or manually, with links to download the latest versions.
- Key Features:
- Security Enhancement: Updates close vulnerabilities that could be exploited by malware (e.g., outdated Adobe Reader versions).
- Automatic Updates: Can be configured to update apps in the background (if supported by the app).
- Customizable Scans: Allows users to schedule scans or exclude certain apps from updates.
- Benefits:
- Reduces security risks by keeping software current (e.g., patching known exploits in apps like Firefox).
- Improves app performance, as updates often include bug fixes and optimizations.
- Simplifies software maintenance with a centralized update interface.
Privacy
Private Browsing
Purpose: Prevents websites from collecting data about your online activities (e.g., browsing habits, preferences) to limit targeted ads and protect privacy.
Availability: Available on Windows via supported browsers (Chrome, Firefox, Edge, Yandex) with the Kaspersky Protection browser extension.
Functionality:
- Detection Mode: Default setting; detects and counts tracking attempts without blocking them, logging details in a report.
- Blocking Mode: Actively blocks data collection attempts on most websites, except those where blocking might break functionality (e.g., social networks when on their sites) or sites explicitly allowed by the user.
To enable the feature select Block data collection.
Anti-Banner
Purpose: Blocks online advertisements (e.g., banners, pop-ups, interstitials, video ads) to reduce distractions, improve page load times, and limit ad-related tracking that collects user data for targeted advertising.
Availability: Available on Windows primarily through the Kaspersky Protection browser extension for supported browsers (Chrome, Firefox, Edge, Yandex) on Windows.
Functionality:
- Ad Blocking: Automatically blocks most types of online ads using a database of known ad patterns and scripts, updated via Kaspersky Security Network (KSN).
- Privacy Protection: Reduces tracking by ad networks, as many ads include scripts that monitor browsing behavior (complements the Private Browsing feature).
- Customizable Filters: Allows users to block or allow ads on specific websites or for specific ad types.
Exclusions:
- By default, allows “non-intrusive” ads (e.g., small, static banners) as defined by Kaspersky’s criteria, though this can be disabled for stricter blocking.
- Permits ads on websites where blocking might disrupt functionality (e.g., ad-supported services) unless manually overridden.
- Does not block ads served by Kaspersky or its partners unless explicitly configured.
Unwanted App Installation Blocker
Purpose: Protects your device by automatically blocking the installation of unwanted applications, such as toolbars, adware, or other software bundled with legitimate programs. These are often included in installers for free software and can be installed if users overlook checkboxes during setup.
Availability: Included in Kaspersky Standard, Plus, and Premium plans, but not in Kaspersky Free. Available primarily on Windows, as it integrates with the Application Manager component.
Functionality:
- Automatic Checkbox Clearing: Automatically unchecks boxes for additional software during installation processes to prevent unintended installations.
- Warnings: Alerts users to attempts by installers to add extra programs, allowing manual intervention if desired.
- Supported Applications: Works with a growing list of installers recognized by Kaspersky’s database, updated via Kaspersky Security Network (KSN).
How It Works
- Detection: The feature monitors software installation processes in real-time, identifying attempts to install additional applications (e.g., browser extensions, promotional apps) that are often pre-selected in installer wizards.
- Action:
- Automatically clears checkboxes for unwanted software to prevent installation without user interaction.
- Optionally notifies users of attempted installations, depending on settings, allowing them to review and confirm actions.
- Integration: Part of the Application Manager component, which oversees application installations and categorizes software based on trust levels (e.g., Trusted, Low Restricted, High Restricted, Untrusted).
- KSN Dependency: Relies on Kaspersky’s cloud-based KSN for up-to-date information on installers and bundled software. Without KSN access, effectiveness may be reduced.
Privacy Cleaner
The Privacy Cleaner feature cleans up traces of user activity in the operating system to prevent unauthorized access to sensitive information, such as search queries, visited websites, recently opened applications, and saved files. These traces could be exploited by intruders to compromise your privacy.
The Privacy Cleaner Wizard scans the operating system for traces of user activity, including:
- Browser history and cookies (e.g., search queries, visited websites).
- Lists of recently opened applications and files.
- System logs, such as Windows event logs or temporary files.
- Other activity traces, like clipboard contents or cached data.
Kaspersky Settings
Security Settings
1. Intrusion Prevention
The Intrusion Prevention component prevents applications from performing actions that may be dangerous for the operating system, and controls access to operating system resources (including file resources located on remote computers) and your personal data
A. Manage Applications
The Manage Applications feature in Kaspersky Standard is part of the Application Manager component, designed to control and monitor applications on your device to enhance security, performance, and privacy. It allows you to manage application permissions, categorize apps based on trust levels, and prevent unwanted software installations.
Purpose: Provides centralized control over installed applications, enabling users to:
- Categorize applications into trust groups (Trusted, Low Restricted, High Restricted, Untrusted) to define their access to system resources and networks.
- Monitor and restrict application behavior to prevent unauthorized actions (e.g., accessing sensitive data or networks).
Application Control:
- Trust Groups: Applications are automatically categorized into one of four trust groups based on Kaspersky Security Network (KSN) data, digital signatures, or user-defined settings:
- Trusted: Safe apps (e.g., verified software like Chrome) with full access to system resources and networks.
- Low Restricted: Low-risk apps with broad access but monitored for suspicious behavior.
- High Restricted: Potentially risky apps with restricted access to resources and networks unless explicitly allowed.
- Untrusted: High-risk or unknown apps with severe restrictions, blocking most actions unless manually overridden.
- Behavior Monitoring: Uses the Host Intrusion Prevention component to monitor app activity and enforce restrictions (e.g., blocking unauthorized registry changes or network access).
- Rules: Custom rules can override default trust group settings to allow or block specific actions (e.g., file access, network connections).
Start / Restrictions
- Clicking the Start link sorts applications in the list into two groups: Blocked and Allowed.
- Clicking the Restrictions link sorts applications in the list by trust groups. For example, trusted applications are listed in the Trusted group.
Clean up
Clicking this link causes Kaspersky application to remove applications that no longer exist from the list.
View
In the drop-down list, you can select a display mode for applications and processes.
- Expand all. Selecting this item shows all applications installed on the computer in the list.
- Collapse all. Selecting this item shows trust groups in the list.
In the drop-down list, you can select a display mode for applications and processes:
- View as list. If you select this option, applications and processes are displayed as a list.
- View as tree. If you select this option, applications and processes are displayed hierarchically, based on the order in which the processes were called.
B. Manage resources
The Manage Resources feature is part of the Application Manager component, specifically within the Application Control functionality. It allows users to control and restrict applications’ access to critical system resources, such as files, folders, registry keys, and resources of the operating system, to enhance security and prevent unauthorized actions by potentially risky software.
Purpose: Enables fine-grained control over which applications can access sensitive system resources, reducing the risk of unauthorized data access, system modifications, or privacy breaches by malicious or untrusted apps.
Functionality:
- Resource Categories: Manages access to resources like operating system files, user data, registry keys, webcam, microphone, and network services.
- Trust-Based Restrictions: Leverages Kaspersky’s trust groups (Trusted, Low Restricted, High Restricted, Untrusted) to enforce resource access rules.
- Custom Rules: Allows users to create specific rules to allow or block access to particular resources for individual applications or trust groups.
- Integration with KSN: Uses Kaspersky Security Network (KSN) to categorize apps and assess their risk, aiding in automatic resource access decisions.
How Manage Resources Works
- Resource Monitoring:
- The Host Intrusion Prevention component monitors application attempts to access protected resources, such as:
- Operating System Resources: System files, registry keys, and services critical to Windows stability.
- User Data: Personal files (e.g., documents, photos), browser data, and credentials.
- Hardware: Webcam, microphone, and other peripherals.
- Network Resources: Specific protocols, ports, or network services.
- Access is granted or denied based on the application’s trust group or custom rules.
- The Host Intrusion Prevention component monitors application attempts to access protected resources, such as:
- Trust Groups:
- Trusted: Apps have full access to all resources unless restricted by custom rules (e.g., verified apps like Microsoft Word).
- Low Restricted: Apps have broad access but are monitored for suspicious behavior (e.g., minor restrictions on registry writes).
- High Restricted: Apps have limited access, blocked from most sensitive resources unless explicitly allowed (e.g., unknown apps).
- Untrusted: Apps are heavily restricted, blocked from accessing nearly all resources (e.g., suspected malware).
- Default Rules:
- Predefined rules are applied based on trust groups:
- Trusted/Low Restricted: Allowed to access most resources.
- High Restricted/Untrusted: Blocked from accessing critical resources (e.g., webcam, system files).
- These rules cannot be edited but can be overridden with custom rules.
- Predefined rules are applied based on trust groups:
- Custom Rules:
- Users can create rules to allow or block specific resource access (e.g., allow a High Restricted app to access a specific folder but not the webcam).
- Actions include Allow, Block, Inherit (follow trust group defaults), or Prompt for action (user decides in real-time).
- Child Processes: Child processes inherit the resource access rules of their parent process unless a specific rule overrides them.
User have option to manually add important files and documents, to the manged resources.
- To add important files or folder, select the Personal data > User files.
- Click on Add button.
- Click on Select button and select the path of the personal file or folder.
- Click on Add button.
In this case, the D:\Documents folder added to Managed resources.
2. Exclusions and actions on object detection
A. Specify trusted applications
Method_1
To add an application in the list of Trusted applications, click on Add button.
Select the location of the application and click on Select button.
Enable the Do not monitor application activity.
Click on OK button.
Click on OK button.
Click on Save button.
Method 2
Another way to add the application to the Trusted application list is by using Manage applications.
- Open Manage applications window.
- Select an application and right click on it.
- Select the option Details and rules.
- Select Exclusion tab.
- Enable the option Do not monitor application activity.
B. Manage exclusions
Method 1
User have option to add files and folders into Exclusion list.
- To add a file or folder to the Exclusion list, click on Add button.
- Select the file and folder.
To exclude the scanning by all components, select All components and click on Add button.
Click on OK button.
Method 2
Another way to add files in exclusion list is to
To exclude the scanning by all components, select All components and click on Add button.







































