Author Topic: suspicious program, avast popup, not excluded and prog still runs  (Read 3559 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I'm trying to get an understanding of what should happen when I run a suspicious program (i.e. one that avast is not aware of or it thinks it is suspicious for other reasons).

The program in question is a freeware app to show USB connected devices - http://www.nirsoft.net/utils/usb_devices_view.html and I'm running the latest (2.45) version on Windows Server 2003 R2.

I have hardened mode set to aggressive, I'm not checking for PUPs and the program has not been excluded in any AVAST exclude lists.

When I run it I get an AVAST pop-up which says "AVAST hardened mode prevented a program from starting". It then goes on to say if I want to run the program I should add an exclusion by clicking the link below and the program will run. So far so good.

If I leave the AVAST pop-up to time out or click X or click close (i.e. I don't click to add an exclusion), the pop-up disappears.

Now what happens next varies....

1) Occasionally the program will not actually run
2) More often than not the program will run as normal

Now, having not added an exception for the program I would have expected 1) to happen every time I try to run it, but I almost always get 2) to happen. I don't know why 1) only happens sometimes

Is my understanding of the action AVAST takes correct in that not adding an exception means the program will not be allowed to run. If so, then something is clearly wrong either in my config or in the AVAST program itself.

Or if I do nothing it is allowed to run anyway - which seems to contradict the comments in the AVAST pop-up box?

Or AVAST does some additional checks after the pop-up is gone and decides the prog is ok to run anyway?

- Peter



REDACTED

  • Guest
Re: suspicious program, avast popup, not excluded and prog still runs
« Reply #1 on: August 13, 2015, 06:45:13 PM »
What is the OS? I am testing on a Windows 7 x64 and XP. On the XP, I get the popup and if I close it or let it time out the programs runs. This is happening every time. On my windows 7 machine, it always blocks the program from running.

REDACTED

  • Guest
Re: suspicious program, avast popup, not excluded and prog still runs
« Reply #2 on: August 13, 2015, 09:15:51 PM »
Sorry, I didn't notice that you said you were running Server 2003. It shares the same code base as XP. I did install Avast on another XP machine with the same results. I did find that if I ran a file that would cause the popup from a network share, it would run when I closed the popup. If I copied the file to the local C: drive and ran it, it would block the program from running.

REDACTED

  • Guest
Re: suspicious program, avast popup, not excluded and prog still runs
« Reply #3 on: August 14, 2015, 10:41:06 AM »
Interesting.....

If I run the same program on Windows 2012 it always produces a pop-up and blocks running the program every time (if no exclusion is added) whether it is run from a network share or locally.

Doing the same on 2003 I sometimes get a pop-up but it always seems to run now whether it is local or from a network share.

I'm guessing it should always block on XP/2003 like it does on 2012 so something may be broken in avast when running on XP/2003. As avast say they support 2003 this may need to be investigated.

REDACTED

  • Guest
Re: suspicious program, avast popup, not excluded and prog still runs
« Reply #4 on: August 14, 2015, 11:25:45 AM »
I can't help test for XP, but I wonder if you still had access to an earlier installer, say 2015.10.0.2504? 

I found 2015.10.2.2505 was no small upgrade behind the scenes and maybe something did break for XP.  If you can test an older version and it works you'll have some extra firepower to take to a support ticket, which I would say is a must if it is reproducable. 

Also maybe check your drivers are current as I found the latest version to be temperamental with out of date network drivers on Win 7.  Maybe the news version it is not playing nice with some of the older XP low level drivers.

Hope that's helpful.

REDACTED

  • Guest
Re: suspicious program, avast popup, not excluded and prog still runs
« Reply #5 on: August 14, 2015, 06:49:01 PM »
I also noticed on the XP machines, just opening the folder containing the file would cause the hardened mode popup. Without attempting to open it. Does not happen on the Windows 7 machine.