Author Topic: Question on the resident protection.  (Read 3415 times)

0 Members and 1 Guest are viewing this topic.

mamba2007

  • Guest
Question on the resident protection.
« on: July 17, 2006, 12:03:03 PM »
I'm using the home/free edition Avast & it serves my purpose just fine, but I've ran into this problem/bug. I was recently infected by the annoying Brontok virus/spyware & using the manual scanner it managed to detect & remove Brontok from my system but unfortunately the resident protection fails to keep the virus out as Brontok still manages to plant itself back into my HDD even after I set the resident protection to HIGH. Anybody can help me please?
« Last Edit: July 17, 2006, 12:13:56 PM by mamba2007 »

ardvark

  • Guest
Re: Question on the resident protection.
« Reply #1 on: July 17, 2006, 12:53:39 PM »
Hi mamba2007...

If you are running Windows ME, 2000 or XP, you should turn off "System Restore."

Try also running a couple online scans here...

http://housecall.trendmicro.com/

http://www.ewido.net/en/onlinescan/

If this doesn't work or it fails to eliminate the virus's processes, try downloading a copy of BrontokWasher here...

http://www.softpedia.com/get/Antivirus/Brontok-Washer.shtml

Please let us know the results...

Best Regards...

mamba2007

  • Guest
Re: Question on the resident protection.
« Reply #2 on: July 18, 2006, 02:09:16 PM »
What I'm trying to say is, the resident protection doesn't monitor newly created files constantly. And when it does, it just tells me the filename & location but doesn't actually clean the file!!! what must I do to make Avast auto clean the infected files that its resident protection finds? If it doesn't clean the infected files that it finds then it defeats the purpose of it being a resident scanner rite?
« Last Edit: July 18, 2006, 02:19:11 PM by mamba2007 »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89394
  • No support PMs thanks
Re: Question on the resident protection.
« Reply #3 on: July 18, 2006, 03:24:49 PM »
If avast's standard shield can detect it then so too should the web shield, which is also true if it is coming via P2P or Instant Messaging, assuming your P2P and IM programs are supported. These scanners provide an earlier detection before it arrives on your HDD this makes it easier to deal with than if it gets established on your HDD. Your IM and P2P program may also allow for the direct scanning of downloads, if so then this is the file to use, C:\Program Files\Alwil Software\Avast4\ashQuick.exe.

Do you have a firewall, if so what is it ?
It could be possible that there is a trojan on your system that is downloading this or creating a backdoor to allow access.

Not all files can be cleaned, Trojans generally can't be repaired (either by the VRDB or avast virus cleaner), because the entire content of the file is malware, so it is either move to chest or delete, move to the chest being the best option (first do no harm). When a file is in the chest it can't do any harm and you can investigate the infected warning.

The VRDB only protects certain files, .exe, dll and other system files, it doesn't protect data files or all files, it is not a back-up program, so there are going to be many occasions where repair won't be an option.

Only true virus infection can be repaired, e.g. when a virus infects a file it adds a small part to it, provided that file is one that avast's VRDB would monitor and you have run the VRDB, then it may be possible to repair the file to its uninfected state.

However, for the most part so called viruses, trojans (adware/spyware/malware, etc.) can't be repaired because the complete content of the file is malicious.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

mamba2007

  • Guest
Re: Question on the resident protection.
« Reply #4 on: July 19, 2006, 05:16:29 AM »
Can u please tell me where i should change the settings to make Avast throw these files straight into the chest if it detects an infected file but can't clean it?

ardvark

  • Guest
Re: Question on the resident protection.
« Reply #5 on: July 19, 2006, 05:54:44 AM »
Can u please tell me where i should change the settings to make Avast throw these files straight into the chest if it detects an infected file but can't clean it?

You would need to purchase the professional version to be able to use that feature.

Best Regards...

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89394
  • No support PMs thanks
Re: Question on the resident protection.
« Reply #6 on: July 19, 2006, 01:20:07 PM »
These advanced automated options are only available in the Pro version.

You only have a limited option in the Home (free) version, to send the infected file to the virus Chest (silent mode, with general answer no, see below).

My own feeling on this is you should use the default interactive action. This way you know exactly what is going on with your system. If you are getting so many warnings, that you want to automate this process, I believe you should review your security practice - filter emails at source, delete from server rather than download them, sites they visit, etc.

See the avast help file, Resident Protection: Standard Shield Provider Settings - "Advanced" Page.
Click on Standard Shield and then on Customize.
Go to Advanced tab and select Silent Mode and the General answer No.

Leave the file in the chest for a week or two (it can do no harm from there) to ensure no adverse effect from being moved to the chest. Then scan the file again in the chest to ensure it is still detected as infected and if so delete it from the chest.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.6.6121 (build 24.6.9241.848) UI 1.0.809/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security