Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: avaaaaaaaaast on January 30, 2012, 11:32:17 AM

Title: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on January 30, 2012, 11:32:17 AM
I want all applications(except a few) blocked from connecting to internet.

Before avast was updated this was possible via win7 firewall since not every application connected via avastsvc.exe . But now after the avast update all applications that were blocked started connecting via avast.

Now I cannot block avast totally from connecting as that would block the allowed applications too.

Please release an update in avastsvc.exe that allows only a few said applications while blocking all others.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Asyn on January 30, 2012, 11:50:36 AM
But now after the avast update all applications that were blocked started connecting via avast.

avast! GUI -> Web Shield -> Expert Settings -> Main Settings
Enable: Scan traffic from well-known browser processes only
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Lisandro on January 31, 2012, 01:32:24 AM
I want all applications(except a few) blocked from connecting to internet.
This is not possible yet. Maybe future versions of avast! 7 could have this feature.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: DavidR on January 31, 2012, 02:33:26 AM
Sounds like the win7 firewall is pathetic as it can't handle localhost proxies, e.g. it can't detect what is the parent application passing through the proxy.

Most 3rd party firewalls are able to detect what application is using the web shield proxy and act on that and not allow it through the proxy.

Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 03:07:42 PM
Sounds like the win7 firewall is pathetic as it can't handle localhost proxies, e.g. it can't detect what is the parent application passing through the proxy.

Most 3rd party firewalls are able to detect what application is using the web shield proxy and act on that and not allow it through the proxy.



which firewall do you recommend that allows only a few applications via avast to connect while blocking all others? the firewall should be free for home personal use and should make the internet invisible to other applications.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Asyn on February 02, 2012, 03:09:13 PM
Did you try the suggestion in Reply #1 yet..??
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 03:15:59 PM
But now after the avast update all applications that were blocked started connecting via avast.

avast! GUI -> Web Shield -> Expert Settings -> Main Settings
Enable: Scan traffic from well-known browser processes only

And one more thing. I want avast to stop scanning/interfering with ssl connections. Please explain how can i do that?
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 03:17:57 PM
Did you try the suggestion in Reply #1 yet..??

wow that was a fast reply. I will try and tell.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Asyn on February 02, 2012, 03:19:06 PM
I want avast to stop scanning/interfering with ssl connections.

Sorry, not sure what you mean..??
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 03:30:51 PM
Did you try the suggestion in Reply #1 yet..??

Yes i tried. I tested it with ping.exe . It can see the internet even though it is not allowed by a windows firewall outbound rule.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Hermite15 on February 02, 2012, 03:34:52 PM
But now after the avast update all applications that were blocked started connecting via avast.

avast! GUI -> Web Shield -> Expert Settings -> Main Settings
Enable: Scan traffic from well-known browser processes only

+1 that's the answer ;)
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Asyn on February 02, 2012, 03:37:01 PM
Did you try the suggestion in Reply #1 yet..??

Yes i tried. I tested it with ping.exe . It can see the internet even though it is not allowed by a windows firewall outbound rule.

Ping is usually allowed in any Windows FW. ;)

Some basic questions:
Which avast!..?? (Free/Pro/IS)
Which version..??
OS..?? (32/64 Bit - which SP)
Other security related software installed..??
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 03:42:13 PM
I want avast to stop scanning/interfering with ssl connections.

Sorry, not sure what you mean..??

what i mean is the problem with the https connections that stop working or work very slowly when avast intercepts them for scanning. Example is with a few online brokerage websites whose tickers/quotes disappear/freeze/delay when avast intercepts them while making an https connection.

These sites are mostly secure and trusted and mostly do not require scanning.
So i want that avast should stop scanning https connections that have a valid trusted certificate.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Asyn on February 02, 2012, 03:50:46 PM
These sites are mostly secure and trusted and mostly do not require scanning.
So i want that avast should stop scanning https connections that have a valid trusted certificate.

You can exclude them in the settings, if needed.
I may add that I've never had any slowdowns with any https connection(s).
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 04:03:50 PM
Did you try the suggestion in Reply #1 yet..??

Yes i tried. I tested it with ping.exe . It can see the internet even though it is not allowed by a windows firewall outbound rule.

Ping is usually allowed in any Windows FW. ;)

Some basic questions:
Which avast!..?? (Free/Pro/IS)
Which version..??
OS..?? (32/64 Bit - which SP)
Other security related software installed..??

no windows 7 firewall use to block pinging too since i had not created an outbound rule to allow it. that was before avast update.

Win 7 firewall is not that bad. Its very different from win xp firewall.With manually tweaked settings it gives essential security thats sufficient for home personal use.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 04:06:53 PM
These sites are mostly secure and trusted and mostly do not require scanning.
So i want that avast should stop scanning https connections that have a valid trusted certificate.

You can exclude them in the settings, if needed.
I may add that I've never had any slowdowns with any https connection(s).

How can i exclude all https connections while making all http connections scanned before entering my system?
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Asyn on February 02, 2012, 04:07:41 PM
Win 7 firewall is not that bad.

I know that. ;)
Btw, you didn't answer the questions...
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 04:30:38 PM
Which avast!..?? (Free/Pro/IS)
free
Which version..??
6.0.1289
OS..?? (32/64 Bit - which SP)
win7_64
Other security related software installed..??
no
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: Asyn on February 02, 2012, 04:43:25 PM
Which version..??
6.0.1289

Please update to 6.0.1367...!!
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: DavidR on February 02, 2012, 05:49:59 PM
<snip>
what i mean is the problem with the https connections that stop working or work very slowly when avast intercepts them for scanning. Example is with a few online brokerage websites whose tickers/quotes disappear/freeze/delay when avast intercepts them while making an https connection.

That isn't the problem as avast doesn't intercept/monitor https traffic.

These sites are mostly secure and trusted and mostly do not require scanning.
So i want that avast should stop scanning https connections that have a valid trusted certificate.

I suspect that there is more going on than just https traffic at these sites, typically they may well be using http ports and aren't using strict http protocol. If this is the case then the web shield would have a problem with the non-http protocol data, I have seen this in lots of sites like live streaming of stock info, etc.

Try this - In the avastUI, Settings, Troubleshooting, Redirect Settings, WEB, Ignored addresses: and enter the IP address of the ticker site.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: avaaaaaaaaast on February 02, 2012, 06:18:19 PM
<snip>
what i mean is the problem with the https connections that stop working or work very slowly when avast intercepts them for scanning. Example is with a few online brokerage websites whose tickers/quotes disappear/freeze/delay when avast intercepts them while making an https connection.

That isn't the problem as avast doesn't intercept/monitor https traffic.

These sites are mostly secure and trusted and mostly do not require scanning.
So i want that avast should stop scanning https connections that have a valid trusted certificate.

I suspect that there is more going on than just https traffic at these sites, typically they may well be using http ports and aren't using strict http protocol. If this is the case then the web shield would have a problem with the non-http protocol data, I have seen this in lots of sites like live streaming of stock info, etc.

Try this - In the avastUI, Settings, Troubleshooting, Redirect Settings, WEB, Ignored addresses: and enter the IP address of the ticker site.

Thanks man you are the best.
Title: Re: Allowing avastsvc.exe through win7 firewall allows all blocked applications too
Post by: DavidR on February 02, 2012, 06:37:14 PM
You're welcome, I take it it worked ;D