In the light of this and Avast replacing certificates with its own on HTTPS scanning - this discussion is also being again to resurge:
http://www.thesafemac.com/avasts-man-in-the-middle/
It all comes back to one issue: can you trust what you installed. I personally say yes I know what I agreed to install or know why I have to trust what I trust.
When an AV like Kaspersky’s is using Open SSL libraries, when you use it for checking you have to make sure you have these fully updated (it is not done automatically!), the private key is also easilty detected without rocket technology required - unobfuscated and unprotected by NTFS permisions. Check your revokes: http://www.wilderssecurity.com/threads/revoked-certs-browsers-test.364438/ - check: “certsrv.msc /e” in the command prompt (minus “”).
polonus