Author Topic: What triggers Hardened Mode (Aggressive)?  (Read 6133 times)

0 Members and 1 Guest are viewing this topic.

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
What triggers Hardened Mode (Aggressive)?
« on: August 25, 2015, 12:05:42 PM »
An Avast Hardened Mode pop-up let me know it prevented an .EXE file from starting.
The thing is, it's a file I had just downloaded but I did not try to run it.
I didn't set any browser settings to auto-execute anything, either.
I only noticed the issue with that file, not with other files.
The file comes from the developer's site, and Virus Total says it's clean.
I guess the file is safe but still unknown to Hardened Mode.
What I don't get, though, is why Avast "prevented it from starting", while I did not try to start it.
Happens both in Chrome and Firefox.
« Last Edit: August 25, 2015, 04:22:35 PM by 1234ava »

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: What triggers Hardened Mode (Advanced)?
« Reply #1 on: August 25, 2015, 02:18:06 PM »
That's weird... can you tell us what file is that? (i.e. where you downloaded it from)
Yes, normally only execution should trigger the Hardened mode.

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: What triggers Hardened Mode (Aggressive)?
« Reply #2 on: August 25, 2015, 02:28:37 PM »
KVRT.exe from hXXp://www.kaspersky.com/antivirus-removal-tool
« Last Edit: August 25, 2015, 04:22:50 PM by 1234ava »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89056
  • No support PMs thanks
Re: What triggers Hardened Mode (Advanced)?
« Reply #3 on: August 25, 2015, 02:45:42 PM »
That's weird... can you tell us what file is that? (i.e. where you downloaded it from)
Yes, normally only execution should trigger the Hardened mode.

Not sure if the Hardened Mode (Aggressive), when enabled is triggered by the File System Shield (FSS), as the downloaded file is a new creation that triggers the FSS and subsequently .

If so is it possible that Hardened Mode (Aggressive) would then check the file against the cloud whitelist ?

I don't see anything in the avast help file that limits Hardened Mode (Aggressive) scanning to execution only.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: What triggers Hardened Mode (Aggressive)?
« Reply #4 on: August 25, 2015, 04:22:17 PM »
Even weirder, detection happens randomly. Sometimes yes, sometimes no. I've been downloading that same file a number of times in Chrome. Same in FF. Now it triggers the warning, now it doesn't.
I also tried to disable the Avast extension in Chrome, but the Hardened Mode (Aggressive) pop-up is triggered while the web extension off, too.
« Last Edit: August 25, 2015, 04:31:08 PM by 1234ava »

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: What triggers Hardened Mode (Aggressive)?
« Reply #5 on: August 25, 2015, 05:49:12 PM »
I can not reproduce your issue with Hardened mode in Aggressive.
I tried 3 times downloading the file in both Firefox and Opera ( I don't use Chrome ) and no warning.

Greetz, Red.

OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: What triggers Hardened Mode (Aggressive)?
« Reply #6 on: August 25, 2015, 06:12:57 PM »
Thanks Rednose,
so it might be something about my installation.
It's Avast IS2015 10.3.2225 on Windows 10 64b (limited user, UAC max, CryptoPrevent), ASUS notebook.
Hardened Mode (Aggressive) ON
DeepScreen ON
Reputation services ON
Scan for PUPs ON
FSS ON
WebShield ON



« Last Edit: August 25, 2015, 06:19:50 PM by 1234ava »

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: What triggers Hardened Mode (Aggressive)?
« Reply #7 on: August 27, 2015, 04:02:19 PM »
I've noticed another Hardened Mode "anomaly" on my system.

This time, I did run a file,
DiscWizardSetup-1605861.it.exe
from the official Seagate site
hXXp://www.seagate.com/it/it/support/downloads/discwizard/

An Avast pop-up notified that Hardened Mode had prevented it from starting

BUT

it somehow "started" anyway, even though with errors (see screenshots below: the first error window says it could not access the path, the second one is a generic error).

After I run it again and allowed it in Hardened Mode, then it run regularly with no errors.


« Last Edit: August 27, 2015, 04:07:22 PM by 1234ava »

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: What triggers Hardened Mode (Aggressive)?
« Reply #8 on: August 31, 2015, 11:38:06 AM »
An Avast Hardened Mode pop-up let me know it prevented an .EXE file from starting.
The thing is, it's a file I had just downloaded but I did not try to run it.
I didn't set any browser settings to auto-execute anything, either.
I only noticed the issue with that file, not with other files.
The file comes from the developer's site, and Virus Total says it's clean.
I guess the file is safe but still unknown to Hardened Mode.
What I don't get, though, is why Avast "prevented it from starting", while I did not try to start it.
Happens both in Chrome and Firefox.


Happened again with another file, TraktRater_v2.2.0.exe
hXXps://github.com/damienhaynes/TraktRater/releases

I tried and downloaded it again. It didn't trigger the pop-up the second time or the third time...
but it happened again after 5 or 6 downloads!

So, I don't know if it actually depends on the files, or it just happens once in while.

I also tried an Avast Repair, to no avail.

Should I open a ticket with Support?
« Last Edit: August 31, 2015, 12:42:29 PM by 1234ava »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: What triggers Hardened Mode (Aggressive)?
« Reply #9 on: August 31, 2015, 11:54:38 AM »
Should I open a ticket with Support?
Yes, please do so.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: What triggers Hardened Mode (Aggressive)?
« Reply #10 on: September 06, 2015, 05:53:02 PM »
Should I open a ticket with Support?
Yes, please do so.

Avast Support said that some files in Avast IS installation might have become corrupted.
They advised that I completely uninstall it (with the uninstall tool) and install it again, which I've done.
Let's see if that fixes it.

Offline 1234ava

  • Full Member
  • ***
  • Posts: 161
Re: What triggers Hardened Mode (Aggressive)?
« Reply #11 on: September 07, 2015, 12:23:50 PM »
Should I open a ticket with Support?
Yes, please do so.

Avast Support said that some files in Avast IS installation might have become corrupted.
They advised that I completely uninstall it (with the uninstall tool) and install it again, which I've done.
Let's see if that fixes it.

Looks like it fixed it.  :)
So far, no more undue Hardened Mode warnings.

Offline avaster78

  • Jr. Member
  • **
  • Posts: 96
Re: What triggers Hardened Mode (Aggressive)?
« Reply #12 on: September 07, 2015, 06:33:40 PM »
I have had similar issues with  Aggressive Hardened Mode. When i was installing Windows10FirewallControl, HM warning popped up. And today it happened with Opera installer. I have the latest Avast Free and Windows 7. Dunno if HM should act like that, but lately it has been very sensitive. And those programs are known to be safe.
« Last Edit: September 07, 2015, 06:36:11 PM by avaster78 »
Windows 7 Home Premium SP1 64-bit. Avast Free Latest. Opera (Chromium). SpywareBlaster 5.5. Windows 10 Firewall Control Free 64-bit (together w/ Windows Firewall). HW: HP G5139sc - Athlon II X2 220 2.8 GHz - 4 GB (Dual-channel). VDSL2 Modem Router w/ Firewall. Internet 50Mbs.