Author Topic: Standard Shield settings-once again  (Read 6034 times)

0 Members and 1 Guest are viewing this topic.

curious

  • Guest
Standard Shield settings-once again
« on: January 31, 2005, 10:45:54 AM »
hi!

After searching the board and reading the help-files I am still confused about the following (I know this has been asked before, but I do not understand the answers):

I will try to be concrete:

1. Resident task, Scanner(Advanced), Scan files on open:
Which file-types are scanned by default? Nothing is fillled in and only scan wsh-files is checked. After this only jscript, vbscript etc should be scanned on open in addition to the files set in scanner(basic).

2. Resident task, Scanner(Basic)
I have everything checked in scanner(Basic). I suppose this means different executables like exe bat com.  What about doc? What about xls? Please clarify.

3. Resident task, Scanner Advanced , Scan created/modified files.
This is clear to me because you can choose between all files or a predefined set of files or type in your own set.

As you can see I find this unlogical but I think it is important to track what is scanned on open. By opening standard shield now and then I observe that in addition to exe and dll also html are scanned. Why?

I have looked on Technicals faq and seen his suggestions for what to put in scan on open. A lot of extensions(nearly like all *).

It suprises me that no extensions are checked by default on open(only wsh) in either normal or high settings for the standard shield. Please clarify!

Regards
Curious

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Standard Shield settings-once again
« Reply #1 on: January 31, 2005, 11:40:45 AM »
Quote
1. Resident task, Scanner(Advanced), Scan files on open:
Which file-types are scanned by default? Nothing is fillled in and only scan wsh-files is checked. After this only jscript, vbscript etc should be scanned on open in addition to the files set in scanner(basic).

Yes this is correct, only scripts are scanned by default thanks to this setting.

Quote
2. Resident task, Scanner(Basic)
I have everything checked in scanner(Basic). I suppose this means different executables like exe bat com.  What about doc? What about xls? Please clarify.

You see the setting "Scan OLE Documents on open"? That's it (office documents are so called OLE files)

Quote
As you can see I find this unlogical but I think it is important to track what is scanned on open. By opening standard shield now and then I observe that in addition to exe and dll also html are scanned. Why?

I doubt that. It's more likely that these files are actually being written (typically to the browser cache folder).

To sum up, by default, the following is being scanned on-open:

1. executables (exe, dll etc)
2. OLE files (doc, xls, ppt etc)
3. dos executables (com, exe) - on execute
4. floppy disk boot sectors


Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

curious

  • Guest
Re: Standard Shield settings-once again
« Reply #2 on: January 31, 2005, 12:02:50 PM »
Thanks Vlk for your quick response! Very clarifying.

One point: What do you recommend in addition to default settings on open  to be reasonably protected? I tried * and the a-ball really spins.!!

Thanks in advance
Curious

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Standard Shield settings-once again
« Reply #3 on: January 31, 2005, 12:18:22 PM »
Well I believe the default settings really provide a good balance between security and performance. Adding stuff like * to the list of extensions is indeed possible but doesn't give you much extra protection (IMHO).

One thing to note: if you're using WinXP, there's a nice feature in the Standard Shield that we call "fancy path caching". Basically, it means that files that have been already re-scanned are not scanned on next access, provded they're not changed in the meantime.

This can be easily seen by e.g. executing a program multiple times. Only the first access will trigger a scan.
Thanks to this advanced (and quite unique AFAIK) feature, the overall overhead of the Standard Shield is pretty low. :)

Cheers
Vlk
If at first you don't succeed, then skydiving's not for you.

StyleWarz

  • Guest
Re: Standard Shield settings-once again
« Reply #4 on: February 01, 2005, 10:50:34 PM »
One thing to note: if you're using WinXP, there's a nice feature in the Standard Shield that we call "fancy path caching". Basically, it means that files that have been already re-scanned are not scanned on next access, provded they're not changed in the meantime.

This can be easily seen by e.g. executing a program multiple times. Only the first access will trigger a scan.
Thanks to this advanced (and quite unique AFAIK) feature, the overall overhead of the Standard Shield is pretty low. :)
That's great indeed :) I assume it's enabled automatic when installed on a XP machine? (don't mind me if it's a dumb question :'()

Jorolat

  • Guest
Re: Standard Shield settings-once again
« Reply #5 on: June 06, 2005, 12:34:22 PM »
Well I believe the default settings really provide a good balance between security and performance. Adding stuff like * to the list of extensions is indeed possible but doesn't give you much extra protection (IMHO).

One thing to note: if you're using WinXP, there's a nice feature in the Standard Shield that we call "fancy path caching". Basically, it means that files that have been already re-scanned are not scanned on next access, provded they're not changed in the meantime.

This can be easily seen by e.g. executing a program multiple times. Only the first access will trigger a scan.
Thanks to this advanced (and quite unique AFAIK) feature, the overall overhead of the Standard Shield is pretty low. :)

Cheers
Vlk

I'm using XP & Avast! Home but I can't find "fancy path caching" anywhere - is it only available on the Pro version?

Jorolat

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Standard Shield settings-once again
« Reply #6 on: June 06, 2005, 12:36:14 PM »
You don't have to look for it anywhere... it's just there and doing its job ;) ;D
If at first you don't succeed, then skydiving's not for you.

Jorolat

  • Guest
Re: Standard Shield settings-once again
« Reply #7 on: June 06, 2005, 07:57:22 PM »
Oh right Vlk - ty! :)

Jorolat

stevejrc

  • Guest
Re: Standard Shield settings-once again
« Reply #8 on: June 06, 2005, 10:28:19 PM »
I have XP home and every time I start Ad-aware the scanned count goes up by 1, ball spins and last scanned is adaware.exe, so its not caching?    (using normal setting in standard shield)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Standard Shield settings-once again
« Reply #9 on: June 06, 2005, 11:33:21 PM »
Something must be changing in AdAware (the same happened to me, but the scan count goes up by 2-3). However doing the same check starting Spybot S&D, closing and starting again doesn't cause a second scan of the SpybotSD.exe file.

There are other files that the smart scan, scans again, however checked windows event log, scans first time but not subsequent times.

So something must be happening to warrant being scanned, better safe than sorry.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security